MARATTO

article

Building a Proactive Cybersecurity Defense: Detection and Analysis Strategies

Abstract

With accelerating digital transformation, information system security is becoming a mandatory strategy. The surge in cyber threats, both in frequency and sophistication, jeopardizes the Confidentiality, Integrity, and Availability (CIA triad) of critical data. The rapid evolution of cyber threats necessitates advanced security mechanisms capable of proactive detection and rapid response. Traditional SOCs, primarily reactive and dependent on manual processes, struggle with high volumes of alerts and sophisticated attack vectors. This research paper presents a cost-effective, open-source SOC using Elastic Stack, The Hive, and Cortex for threat detection. The obtained results reduce alert fatigue, cut response times by 40 % and eliminate licensing costs while covering MITRE ATT&CK via Sigma rules. The average obtained is 60 % faster detection versus legacy SIEMs, proving enterprise security can be scalable and vendor-agnostic.

Research topics

  • Network Security and Intrusion Detection
  • Information and Cyber Security
  • Network Packet Processing and Optimization

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/sita67914.2025.11273604

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.