Abstract
Awareness, in the sense of security, builds the backbone of operations understanding the current and future cyber activities. Situation awareness has become the focal point of securing systems due to dynamic nature of cyber domain. Technological advancements cause the volatility to transform into upcoming challenges. Understanding those is the key to keep cyber Situation Awareness (SA) progression. Earlier studies define required steps to administer cyber SA. These steps (perceive, comprehend, project, and resolve) are also adapted to cyber domain. Rapid technological changes redefine the content of those and thus, it creates demands improving automated tools, which play as systematic factor in nurturing SA. As a system factor, SIEM tools can be basis for comprehending cyber domain. In this work, we investigate recent studies contributed mainly to SIEM (Security Information and Event Management) tool’s enhancement to evaluate current state and help predict upcoming challenges for maintaining awareness. We use various criteria in our investigation such as; architecture improvement, affected SIEM process, utilized CTI (Cyber Threat Intelligence) artefact, implementation area, and type of produced result. In doing so, we aim to impart upward trends on CSA (Cyber Situation Awareness) to academia and industry professionals.
Published Version
Talk to us
Join us for a 30 min session where you can share your feedback and ask us any queries you have