V2I10P42

User-Centric Machine Learning Framework for Cybersecurity Operations Center

Mrs. N. Shilpa¹*, K. Bhargav², P. Manoj Reddy³, M. Sairam⁴, P. Sai Kiran⁵

Abstract

Organizations deploy Security Information and Event Management (SIEM) systems to consolidate diverse security technologies and generate alerts for potential security incidents. Security Operations Center (SOC) analysts examine these alerts to validate their authenticity. The overwhelming volume of false positive alerts exceeds the analytical capacity of SOC teams, potentially allowing genuine threats to go undetected. This research presents a novel user-focused machine learning approach designed to minimize false positive rates while enhancing SOC analyst efficiency. Our framework integrates behavioral analytics with traditional security monitoring within operational SOC environments. We examine standard data inputs, analytical workflows, and preprocessing methodologies essential for developing robust machine learning solutions. This work addresses two distinct audiences: machine learning practitioners seeking to understand cybersecurity contexts, and cybersecurity professionals interested in implementing ML capabilities within their operations. The paper demonstrates practical implementation through a comprehensive case study, covering data acquisition, annotation processes, feature development, algorithm selection, and performance assessment using production SOC infrastructure.

Keywords:

SIEM; SOC; false positives; machine learning; behavioral analytics