The ontology for SOC creation assistance and replication
Justin Novak et al.
What the paper says
A Security Operations Center (SOC) is an indispensable tool for any modern organization or enterprise to secure its digital data and information assets. Developing SOCs and SOC capabilities to meet organizational needs in today’s threat environment is an often laborious, time-consuming, and expensive task that (if not done correctly) may leave organizational goals unfulfilled. In this paper, we introduce the Ontology for SOC Creation Assistance and Replication (OSCAR), which organizations can use to aid in developing SOCs and in planning and evaluating SOC capabilities. We developed OSCAR using a purpose-built dataset created by extracting the knowledge of numerous SOC expert practitioners. OSCAR is organized into a knowledge hierarchy that includes people, process, and technology classes, but also emphasizes planning and functional considerations. OSCAR accomplishes two things. First, it fills a gap in existing cyber ontology literature by including classes for the initial development of SOCs in addition to those for security operations capabilities. Second, its domain-specific knowledge is derived from a unique dataset gathered directly from experts working in the field. Taken together, these unique traits make OSCAR an ideal tool for planning, building, and evaluating SOCs.
Evidence weight
Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40
| F · citation impact | 0.50 × 0.4 = 0.20 |
| M · momentum | 0.50 × 0.15 = 0.07 |
| V · venue signal | 0.50 × 0.05 = 0.03 |
| R · text relevance † | 0.50 × 0.4 = 0.20 |
† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.