International Journal of Computer Applications |
Foundation of Computer Science (FCS), NY, USA |
Volume 185 - Number 14 |
Year of Publication: 2023 |
Authors: Deussom Djomadji Eric Michel, Tonye Emmanuel, Bama Si Franck Arnold Franck, Binele Abana Alphonse |
10.5120/ijca2023922831 |
Deussom Djomadji Eric Michel, Tonye Emmanuel, Bama Si Franck Arnold Franck, Binele Abana Alphonse . Design and Implementation of a Chatbot for the Supervision of Security Events (SIEM). International Journal of Computer Applications. 185, 14 ( Jun 2023), 41-53. DOI=10.5120/ijca2023922831
Companies around the world are the first targets of cybercriminals, because the end product of their attacks is much more lucrative than that of targeted attacks against individuals. As a result, businesses have much greater and more stringent cyber security needs. Moreover, losses in cases of compromise can be evaluated in terms of tens of millions of CFA francs, which makes it a prime target for cybercriminals. Generally, in companies, all the intervention capacities are put into play through an Information System Security team in order to meet the maximum-security needs of its information system. This team is often responsible for the SOC (Security Operation Centre), i.e., the supervision of the security of the information system of a structure through tools of collection, correlation of events and remote intervention. The main mission of the SOC is to identify, analyse and ameliorate cyber security incidents. To assist this team in the continuous management of security and to improve the response time to various security incidents, we designed and implemented a conversational agent for security event monitoring using the ELK Stack SIEM tool. As a result, we obtained a conversational agent that is able to identify and analyse security incidents and events of the company's information system, centralize and have a global view of the security status of all monitored devices, create personalized and adequate rules that can detect flaws in the system, provide reports on security incidents and events through voice exchanges. This will allow the SOC to fulfil the first two terms of its main mission, i.e. the identification and analysis of incidents in order to be able to react more quickly and efficiently to them, thus fulfilling the third and last term of its main mission, remediation.