{"id":"https://openalex.org/W3092781945","doi":"https://doi.org/10.1145/3427228.3427233","title":"SAIBERSOC: Synthetic Attack Injection to Benchmark and Evaluate the Performance of Security Operation Centers","display_name":"SAIBERSOC: Synthetic Attack Injection to Benchmark and Evaluate the Performance of Security Operation Centers","publication_year":2020,"publication_date":"2020-12-07","ids":{"openalex":"https://openalex.org/W3092781945","doi":"https://doi.org/10.1145/3427228.3427233","mag":"3092781945"},"language":"en","primary_location":{"id":"doi:10.1145/3427228.3427233","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3427228.3427233","pdf_url":null,"source":{"id":"https://openalex.org/S4306417673","display_name":"Annual Computer Security Applications Conference","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Annual Computer Security Applications Conference","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2010.08453","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Martin Rosso","orcid":null},"institutions":[{"id":"https://openalex.org/I83019370","display_name":"Eindhoven University of Technology","ror":"https://ror.org/02c2kyt77","country_code":"NL","type":"education","lineage":["https://openalex.org/I83019370"]}],"countries":["NL"],"is_corresponding":true,"raw_author_name":"Martin Rosso","raw_affiliation_strings":["Eindhoven University of Technology, Netherlands"],"affiliations":[{"raw_affiliation_string":"Eindhoven University of Technology, Netherlands","institution_ids":["https://openalex.org/I83019370"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Michele Campobasso","orcid":null},"institutions":[{"id":"https://openalex.org/I83019370","display_name":"Eindhoven University of Technology","ror":"https://ror.org/02c2kyt77","country_code":"NL","type":"education","lineage":["https://openalex.org/I83019370"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Michele Campobasso","raw_affiliation_strings":["Eindhoven University of Technology"],"affiliations":[{"raw_affiliation_string":"Eindhoven University of Technology","institution_ids":["https://openalex.org/I83019370"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Ganduulga Gankhuyag","orcid":null},"institutions":[{"id":"https://openalex.org/I83019370","display_name":"Eindhoven University of Technology","ror":"https://ror.org/02c2kyt77","country_code":"NL","type":"education","lineage":["https://openalex.org/I83019370"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Ganduulga Gankhuyag","raw_affiliation_strings":["Eindhoven University of Technology"],"affiliations":[{"raw_affiliation_string":"Eindhoven University of Technology","institution_ids":["https://openalex.org/I83019370"]}]},{"author_position":"last","author":{"id":null,"display_name":"Luca Allodi","orcid":null},"institutions":[{"id":"https://openalex.org/I83019370","display_name":"Eindhoven University of Technology","ror":"https://ror.org/02c2kyt77","country_code":"NL","type":"education","lineage":["https://openalex.org/I83019370"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Luca Allodi","raw_affiliation_strings":["Eindhoven University of Technology, Netherlands"],"affiliations":[{"raw_affiliation_string":"Eindhoven University of Technology, Netherlands","institution_ids":["https://openalex.org/I83019370"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I83019370"],"apc_list":null,"apc_paid":null,"fwci":1.943,"has_fulltext":false,"cited_by_count":8,"citation_normalized_percentile":{"value":0.87282148,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"141","last_page":"153"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.37770000100135803,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.37770000100135803,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.3370000123977661,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10714","display_name":"Software-Defined Networks and 5G","score":0.1370999962091446,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.7723000049591064},{"id":"https://openalex.org/keywords/metric","display_name":"Metric (unit)","score":0.6996999979019165},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.38589999079704285},{"id":"https://openalex.org/keywords/performance-metric","display_name":"Performance metric","score":0.3531999886035919},{"id":"https://openalex.org/keywords/open-source","display_name":"Open source","score":0.2912999987602234},{"id":"https://openalex.org/keywords/measure","display_name":"Measure (data warehouse)","score":0.287200003862381}],"concepts":[{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.7723000049591064},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7638000249862671},{"id":"https://openalex.org/C176217482","wikidata":"https://www.wikidata.org/wiki/Q860554","display_name":"Metric (unit)","level":2,"score":0.6996999979019165},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.3961000144481659},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.38589999079704285},{"id":"https://openalex.org/C200601418","wikidata":"https://www.wikidata.org/wiki/Q2193887","display_name":"Reliability engineering","level":1,"score":0.3596999943256378},{"id":"https://openalex.org/C2780898871","wikidata":"https://www.wikidata.org/wiki/Q860554","display_name":"Performance metric","level":2,"score":0.3531999886035919},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.3427000045776367},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.30379998683929443},{"id":"https://openalex.org/C3018397939","wikidata":"https://www.wikidata.org/wiki/Q3644502","display_name":"Open source","level":3,"score":0.2912999987602234},{"id":"https://openalex.org/C2780009758","wikidata":"https://www.wikidata.org/wiki/Q6804172","display_name":"Measure (data warehouse)","level":2,"score":0.287200003862381},{"id":"https://openalex.org/C83163435","wikidata":"https://www.wikidata.org/wiki/Q3954104","display_name":"Security management","level":2,"score":0.2678999900817871},{"id":"https://openalex.org/C121822524","wikidata":"https://www.wikidata.org/wiki/Q5157582","display_name":"Computer security model","level":2,"score":0.2574999928474426},{"id":"https://openalex.org/C141571065","wikidata":"https://www.wikidata.org/wiki/Q1771949","display_name":"Performance measurement","level":2,"score":0.25}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3427228.3427233","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3427228.3427233","pdf_url":null,"source":{"id":"https://openalex.org/S4306417673","display_name":"Annual Computer Security Applications Conference","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Annual Computer Security Applications Conference","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2010.08453","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2010.08453","pdf_url":"https://arxiv.org/pdf/2010.08453","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2010.08453","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2010.08453","pdf_url":"https://arxiv.org/pdf/2010.08453","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G5994511833","display_name":null,"funder_award_id":"628.001.032","funder_id":"https://openalex.org/F4320321800","funder_display_name":"Nederlandse Organisatie voor Wetenschappelijk Onderzoek"},{"id":"https://openalex.org/G620320933","display_name":null,"funder_award_id":"ITEA191010","funder_id":"https://openalex.org/F4320314237","funder_display_name":"Rijksdienst voor Ondernemend Nederland"}],"funders":[{"id":"https://openalex.org/F4320314237","display_name":"Rijksdienst voor Ondernemend Nederland","ror":null},{"id":"https://openalex.org/F4320321800","display_name":"Nederlandse Organisatie voor Wetenschappelijk Onderzoek","ror":"https://ror.org/04jsz6e67"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":13,"referenced_works":["https://openalex.org/W1516506771","https://openalex.org/W2037640035","https://openalex.org/W2040576886","https://openalex.org/W2089020037","https://openalex.org/W2089241088","https://openalex.org/W2130596812","https://openalex.org/W2588452010","https://openalex.org/W2593932391","https://openalex.org/W2679033717","https://openalex.org/W2893240802","https://openalex.org/W2986291326","https://openalex.org/W3000845437","https://openalex.org/W4243161795"],"related_works":[],"abstract_inverted_index":{"In":[0],"this":[1],"paper":[2],"we":[3,76],"introduce":[4],"SAIBERSOC,":[5],"a":[6,43,95,104,107],"tool":[7,137],"and":[8,13,21,47,99,141],"methodology":[9,34,117],"enabling":[10],"security":[11,30],"researchers":[12],"operators":[14],"to":[15,41,45,56,102],"evaluate":[16,57,69],"the":[17,37,70,73,86,115,135],"performance":[18,125],"of":[19,61,72,88],"deployed":[20],"operational":[22,54],"Security":[23],"Operation":[24],"Centers":[25],"(SOCs)":[26],"(or":[27],"any":[28,58],"other":[29],"monitoring":[31],"infrastructure).":[32],"The":[33,91],"relies":[35,93],"on":[36,94],"MITRE":[38],"ATT&CK":[39],"Framework":[40],"define":[42],"procedure":[44],"generate":[46],"automatically":[48],"inject":[49],"synthetic":[50],"attacks":[51],"in":[52,120,123,130],"an":[53,78],"SOC":[55,89,97,124,131],"output":[59],"metric":[60],"interest":[62],"(e.g.,":[63],"detection":[64],"accuracy,":[65],"time-to-investigation,":[66],"etc.).":[67],"To":[68],"effectiveness":[71],"proposed":[74,116],"methodology,":[75],"devise":[77],"experiment":[79,92],"with":[80],"n":[81],"=":[82],"124":[83],"students":[84,101],"playing":[85],"role":[87],"analysts.":[90],"real":[96],"infrastructure":[98],"assigns":[100],"either":[103],"BADSOC":[105],"or":[106],"GOODSOC":[108],"experimental":[109],"condition.":[110],"Our":[111],"results":[112],"show":[113],"that":[114],"is":[118],"effective":[119],"identifying":[121],"variations":[122],"caused":[126],"by":[127],"(minimal)":[128],"changes":[129],"configuration.":[132],"We":[133],"release":[134],"SAIBERSOC":[136],"implementation":[138],"as":[139],"free":[140],"open":[142],"source":[143],"software.":[144]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":3},{"year":2020,"cited_by_count":1}],"updated_date":"2026-04-09T08:11:56.329763","created_date":"2020-10-22T00:00:00"}
