Guest blog courtesy of LevelBlue and written by Katrina Thompson. The content of this post is solely the responsibility of the author. LevelBlue does not adopt or endorse any of the views, positions, or information provided by the author in this article. We wanted to know what was going on within our vast networks; modern tools have made it possible for us to know too much.Some data is good, so petabytes of data is better, right? In theory, yes, but we all know that, in practice, it really means a barrage of alerts, late nights at the office, and that feeling of guilt when you have to leave some alerts uninvestigated. SOCs today are drowning as they try to keep up with the new workload brought on by AI-induced threats, SaaS-based risks, proliferating forms of ransomware, the underground criminal as-a-service economy, and complex networks (private cloud, public cloud, hybrid cloud, multi-cloud, on-premises, and more). Oh, and more AI-induced threats.However, SOCs have one tool with which they can fight back. By wielding automation to their advantage, modern SOCs can cut many needless notifications before they end up as unfinished to-dos on their plate. And that will lead to more positive outcomes all around.As noted in Helpnet Security, “Today’s security tools generate an incredible volume of event data. This makes it difficult for security practitioners to distinguish between background noise and serious threats…[M]any systems are prone to false positives, which are triggered either by harmless activity or by overly sensitive anomaly thresholds. This can desensitize defenders who may end up missing important attack signals.”To increase the signal-to-noise ratio and winnow down this deluge of data, SOC automation processes are needed to streamline security operations. Those automated processes are only made more effective by adding the enhancing capabilities of artificial intelligence (AI) -- including machine learning (ML) and Large Language Models (LLMs) specifically.
The Plague of Alert Fatigue
One unsurprising headline reads, “Alert fatigue pushes security analysts to the limit.” And that isn’t even the most exciting news of the day. As noted by Grant Oviatt, head of security operations at Prophet Security, “Despite automation advancements, investigating alerts is still mostly a manual job, and the number of alerts has only gone up over the past five years. Some automated tools meant to lighten the load for analysts can actually add to it by generating even more alerts that need human attention.”Today, alert fatigue comes from a number of places:- Too many alerts | Thanks to all those tools: Firewalls, EDR, IPS, IDS, and more.
- Too many false positives | This leads to wasted time investigating flops.
- Not enough context | A lack of enriching information makes you blind to which alerts might actually be viable.
- Not enough personnel | Even throwing more people at the problem won’t help if you don’t have enough people. Given the amount of threats and alerts today, however, it’s likely you’d need to increase your SOC by a factor of 100.
