{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T16:03:59Z","timestamp":1784390639407,"version":"3.55.0"},"reference-count":150,"publisher":"Association for Computing Machinery (ACM)","issue":"9","license":[{"start":{"date-parts":[[2025,4,4]],"date-time":"2025-04-04T00:00:00Z","timestamp":1743724800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"CSIRO\u2019s Collaborative Intelligence Future Science Platform"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2025,9,30]]},"abstract":"<jats:p>A security operations centre (SOC) is a facility where teams of security professionals, supported by advanced technologies and processes, work together to monitor, detect, and respond to cybersecurity incidents. With advances in AI technology, most of the SOC functions are increasingly becoming AI-driven. Among these, real-time alert monitoring and triage is particularly important. Recent studies, by both industry and academia, have highlighted the problem of alert fatigue and burnout in SOC. Several solutions have been proposed in the literature and by the industry to address this problem. In this article, we review the existing literature and industry solutions on alert fatigue mitigation through the lenses of automation, augmentation, and human\u2013AI collaboration. Based on the review, we identify four major causes of alert fatigue in SOC. We also examine the shortcomings of existing solutions and propose several potential research directions leveraging AI. By providing a comprehensive analysis of the state-of-the-art approaches and their limitations, this study contributes to the existing literature in an important field of study. We anticipate that it will inspire new research directions for addressing alert fatigue not just in SOCs but across other Command and Control (C2) domains as well.<\/jats:p>","DOI":"10.1145\/3723158","type":"journal-article","created":{"date-parts":[[2025,3,12]],"date-time":"2025-03-12T11:30:31Z","timestamp":1741779031000},"page":"1-38","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":67,"title":["Alert Fatigue in Security Operations Centres: Research Challenges and Opportunities"],"prefix":"10.1145","volume":"57","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9090-0579","authenticated-orcid":false,"given":"Shahroz","family":"Tariq","sequence":"first","affiliation":[{"name":"Data61, CSIRO, Sydney, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6138-7742","authenticated-orcid":false,"given":"Mohan","family":"Baruwal Chhetri","sequence":"additional","affiliation":[{"name":"Data61, CSIRO, Melbourne Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3289-6599","authenticated-orcid":false,"given":"Surya","family":"Nepal","sequence":"additional","affiliation":[{"name":"Data61, CSIRO, Sydney, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3816-0176","authenticated-orcid":false,"given":"Cecile","family":"Paris","sequence":"additional","affiliation":[{"name":"Data61, CSIRO, Sydney, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,4,4]]},"reference":[{"key":"e_1_3_2_2_2","first-page":"1","volume-title":"International Conference on Forensics, Analytics, Big Data, Security (FABS\u201921)","volume":"1","author":"Ahmed Tariq","year":"2021","unstructured":"Tariq Ahmed, Aayush Shah, Morarjee Kolla, and Ramadevi Yellasiri. 2021. Reduction of alert fatigue using extended isolation forest. In International Conference on Forensics, Analytics, Big Data, Security (FABS\u201921), Vol. 1. IEEE, 1\u20135."},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2020.2996587"},{"key":"e_1_3_2_4_2","first-page":"10","volume-title":"31st USENIX Security Symposium (USENIX Security\u201922)","author":"Alahmadi Bushra A.","year":"2022","unstructured":"Bushra A. Alahmadi, Louise Axon, and Ivan Martinovic. 2022. 99% False positives: A qualitative study of SOC analysts\u2019 perspectives on security alarms. In 31st USENIX Security Symposium (USENIX Security\u201922). 10\u201312."},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3041837"},{"issue":"1","key":"e_1_3_2_6_2","first-page":"1","article-title":"Effects of workload, work complexity, and repeated alerts on alert fatigue in a clinical decision support system","volume":"17","author":"Ancker Jessica S.","year":"2017","unstructured":"Jessica S. Ancker, Alison Edwards, Sarah Nosal, Diane Hauser, Elizabeth Mauer, and Rainu Kaushal. 2017. Effects of workload, work complexity, and repeated alerts on alert fatigue in a clinical decision support system. BMC Med. Inform. Decis. Mak. 17, 1 (2017), 1\u20139.","journal-title":"BMC Med. Inform. Decis. Mak."},{"key":"e_1_3_2_7_2","article-title":"Destroy alert fatigue","year":"2024","unstructured":"Armor. 2024. Destroy alert fatigue. Retrieved from https:\/\/www.armor.com\/outcomes\/destroy-alert-fatigue\/","journal-title":"R"},{"key":"e_1_3_2_8_2","doi-asserted-by":"crossref","first-page":"154","DOI":"10.1016\/j.autcon.2017.03.003","article-title":"Monitoring fatigue in construction workers using physiological measurements","volume":"82","author":"Aryal Ashrant","year":"2017","unstructured":"Ashrant Aryal, Ali Ghahramani, and Burcin Becerik-Gerber. 2017. Monitoring fatigue in construction workers using physiological measurements. Autom. Construct. 82 (2017), 154\u2013165.","journal-title":"Autom. Construct."},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.14722\/usec.2018.23024"},{"issue":"3","key":"e_1_3_2_10_2","first-page":"1227","article-title":"Sonification to support the monitoring tasks of security operations centres","volume":"18","author":"Axon Louise","year":"2019","unstructured":"Louise Axon, Jassim Happa, Alastair Janse van Rensburg, Michael Goldsmith, and Sadie Creese. 2019. Sonification to support the monitoring tasks of security operations centres. IEEE Trans. Depend. Sec. Comput. 18, 3 (2019), 1227\u20131244.","journal-title":"IEEE Trans. Depend. Sec. Comput."},{"key":"e_1_3_2_11_2","doi-asserted-by":"crossref","first-page":"9","DOI":"10.1145\/3474718.3474723","volume-title":"Cyber Security Experimentation and Test Workshop","author":"Ban Tao","year":"2021","unstructured":"Tao Ban, Ndichu Samuel, Takeshi Takahashi, and Daisuke Inoue. 2021. Combat security alert fatigue with AI-assisted techniques. In Cyber Security Experimentation and Test Workshop. 9\u201316."},{"key":"e_1_3_2_12_2","article-title":"McAfee Labs Threats Report","author":"Beek Christiaan","year":"2017","unstructured":"Christiaan Beek, Diwakar Dinkar, Yashashree Gund, German Lancioni, Niamh Minihane, Francisca Moreno, Eric Peterson, Thomas Roccia, Craig Schmugar, Rick Simon et\u00a0al. 2017. McAfee Labs Threats Report. Technical Report. McAfee, Santa Clara, CA.","journal-title":"McAfee, Santa Clara, CA"},{"key":"e_1_3_2_13_2","unstructured":"Ray Bernard. 2008. Security operations center design. Retrieved from https:\/\/www.securityinfowatch.com\/home\/article\/10537078\/security-operations-center-design"},{"key":"e_1_3_2_14_2","article-title":"Security operation center concepts & implementation","author":"Bidou Renaud","year":"2005","unstructured":"Renaud Bidou. 2005. Security operation center concepts & implementation. Retrieved from http:\/\/www.iv2-technologies.com","journal-title":"R"},{"key":"e_1_3_2_15_2","article-title":"Why deduplication is important for security","author":"Blog AppSOC Security","year":"2024","unstructured":"AppSOC Security Blog. 2024. Why deduplication is important for security. Retrieved from https:\/\/securityboulevard.com\/2024\/06\/why-deduplication-is-important-for-security\/","journal-title":"R"},{"key":"e_1_3_2_16_2","article-title":"No alert left behind\u2014Get to 100% with GenAI","author":"Brown Brian B.","year":"2024","unstructured":"Brian B. Brown. 2024. No alert left behind\u2014Get to 100% with GenAI. Retrieved from https:\/\/www.trellix.com\/blogs\/xdr\/no-alert-left-behind-get-to-100-with-genai\/","journal-title":"R"},{"key":"e_1_3_2_17_2","first-page":"1","volume-title":"IEEE\/IFIP Network Operations and Management Symposium (NOMS\u201920)","author":"Burr Benjamin","year":"2020","unstructured":"Benjamin Burr, Shelly Wang, Geoff Salmon, and Hazem Soliman. 2020. On the detection of persistent attacks using alert graphs and event feature embeddings. In IEEE\/IFIP Network Operations and Management Symposium (NOMS\u201920). IEEE, 1\u20134."},{"key":"e_1_3_2_18_2","first-page":"1","volume-title":"IEEE Symposium on Visualization for Cyber Security (VizSec\u201916)","author":"Cappers Bram C. M.","year":"2016","unstructured":"Bram C. M. Cappers and Jarke J. van Wijk. 2016. Understanding the context of network traffic alerts. In IEEE Symposium on Visualization for Cyber Security (VizSec\u201916). IEEE, 1\u20138."},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3204171"},{"key":"e_1_3_2_20_2","article-title":"Qualys launches context XDR to prioritize threat detection and reduce alert fatigue","author":"Casey Tami","year":"2022","unstructured":"Tami Casey. 2022. Qualys launches context XDR to prioritize threat detection and reduce alert fatigue. Retrieved from https:\/\/www.qualys.com\/company\/newsroom\/news-releases\/usa\/qualys-launches-context-xdr-to-prioritize-threat-detection-and-reduce-alert\/","journal-title":"R"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/3511101"},{"issue":"3","key":"e_1_3_2_22_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3670009","article-title":"Towards human-AI teaming to mitigate alert fatigue in security operations centres","volume":"24","author":"Chhetri Mohan Baruwal","year":"2024","unstructured":"Mohan Baruwal Chhetri, Shahroz Tariq, Ronal Singh, Fatemeh Jalalvand, Cecile Paris, and Surya Nepal. 2024. Towards human-AI teaming to mitigate alert fatigue in security operations centres. ACM Trans. Internet Technol. 24, 3 (2024), 1\u201322.","journal-title":"ACM Trans. Internet Technol."},{"key":"e_1_3_2_23_2","doi-asserted-by":"crossref","first-page":"545","DOI":"10.1007\/978-981-13-2622-6_53","volume-title":"Computational Science and Technology","author":"Chuan Bernard Lee Jin","year":"2019","unstructured":"Bernard Lee Jin Chuan, Manmeet Mahinderjit Singh, and Azizul Rahman Mohd Shariff. 2019. APTGuard: Advanced persistent threat (APT) detections and predictions using Android smartphone. In Computational Science and Technology. Springer, 545\u2013555."},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/SMC42975.2020.9282831"},{"key":"e_1_3_2_25_2","article-title":"Cybersecurity Synergy: Navigating known and unknown threats with LogRhythm Axon and CimTrak","year":"2024","unstructured":"Cimcor. 2024. Cybersecurity Synergy: Navigating known and unknown threats with LogRhythm Axon and CimTrak. Retrieved from https:\/\/www.cimcor.com\/blog\/cybersecurity-synergy-logrhythm-axon-and-cimtrak","journal-title":"R"},{"key":"e_1_3_2_26_2","unstructured":"Abby Costin. 2022. How to resolve alert fatigue for security teams. Retrieved from https:\/\/blogs.vmware.com\/security\/2022\/06\/how-to-resolve-alert-fatigue-for-security-teams.html"},{"key":"e_1_3_2_27_2","volume-title":"SANS 2022 SOC Survey","author":"Crowley Chris","year":"2022","unstructured":"Chris Crowley and Barbara Filkins. 2022. SANS 2022 SOC Survey. White Paper. Escal Institute of Advanced Technologies (SANS Institute). Retrieved from www.sans.org\/white-papers\/sans-2022-soc-survey"},{"key":"e_1_3_2_28_2","article-title":"Managed detection and response","author":"Cyber Blackpoint","year":"2024","unstructured":"Blackpoint Cyber. 2024. Managed detection and response. Retrieved from https:\/\/blackpointcyber.com\/solutions\/managed-detection-and-response","journal-title":"R"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.3390\/app13042718"},{"issue":"7","key":"e_1_3_2_30_2","first-page":"3366","article-title":"A continual learning survey: Defying forgetting in classification tasks","volume":"44","author":"Lange Matthias De","year":"2021","unstructured":"Matthias De Lange, Rahaf Aljundi, Marc Masana, Sarah Parisot, Xu Jia, Ale\u0161 Leonardis, Gregory Slabaugh, and Tinne Tuytelaars. 2021. A continual learning survey: Defying forgetting in classification tasks. IEEE Trans. Pattern Anal. Mach. Intell. 44, 7 (2021), 3366\u20133385.","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"e_1_3_2_31_2","article-title":"Healthcare technology company optimizes Devo with binary defense\u2019s MDR & co-managed SIEM solution","author":"Defense Binary","year":"2024","unstructured":"Binary Defense. 2024. Healthcare technology company optimizes Devo with binary defense\u2019s MDR & co-managed SIEM solution. Retrieved from https:\/\/www.binarydefense.com\/resources\/case-studies\/healthcare-technology-company-optimizes-devo-with-binary-defenses-mdr-co-managed-siem-solution\/","journal-title":"R"},{"key":"e_1_3_2_32_2","volume-title":"Industrial Automation Technologies","author":"Dey Chanchal","year":"2020","unstructured":"Chanchal Dey and Sunit Kumar Sen. 2020. Industrial Automation Technologies. CRC Press."},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/3407023.3407039"},{"key":"e_1_3_2_34_2","article-title":"Too many security alerts, not enough time: Automation to the rescue","author":"Dominguez John","year":"2024","unstructured":"John Dominguez. 2024. Too many security alerts, not enough time: Automation to the rescue. Retrieved from https:\/\/www.splunk.com\/en_us\/blog\/security\/too-many-security-alerts-not-enough-time-automation-to-the-rescue.html","journal-title":"R"},{"key":"e_1_3_2_35_2","first-page":"237","volume-title":"International Conference on Applied Human Factors and Ergonomics","author":"Dutta Saurabh","year":"2017","unstructured":"Saurabh Dutta, Ger Joyce, and Jay Brewer. 2017. Utilizing chatbots to increase the efficacy of information security practitioners. In International Conference on Applied Human Factors and Ergonomics. Springer, 237\u2013243."},{"key":"e_1_3_2_36_2","volume-title":"11th USENIX Workshop on Cyber Security Experimentation and Test (CSET\u201918)","author":"Dykstra Josiah","year":"2018","unstructured":"Josiah Dykstra and Celeste Lyn Paul. 2018. Cyber Operations Stress Survey (COSS): Studying fatigue, frustration, and cognitive workload in cybersecurity operations. In 11th USENIX Workshop on Cyber Security Experimentation and Test (CSET\u201918)."},{"key":"e_1_3_2_37_2","first-page":"19","volume-title":"Randomized Controlled Trial for Copilot for Security","author":"Edelman Ben","year":"2024","unstructured":"Ben Edelman, James Bono, Sida Peng, Roberto Rodriguez, and Sandra Ho. 2024. Randomized Controlled Trial for Copilot for Security. Technical Report. Microsoft Security. 19 pages. Retrieved from www.microsoft.com\/en-au\/security\/business\/ai-machine-learning\/microsoft-copilot-security"},{"key":"e_1_3_2_38_2","first-page":"1","volume-title":"CHI Conference on Human Factors in Computing Systems","author":"Ehsan Upol","year":"2021","unstructured":"Upol Ehsan, Q. Vera Liao, Michael Muller, Mark O. Riedl, and Justin D. Weisz. 2021. Expanding explainability: Towards social transparency in ai systems. In CHI Conference on Human Factors in Computing Systems. 1\u201319."},{"issue":"3","key":"e_1_3_2_39_2","doi-asserted-by":"crossref","first-page":"243","DOI":"10.1016\/S0167-4048(00)88613-7","article-title":"Information security management: A hierarchical framework for various approaches","volume":"19","author":"Eloff Mariki M.","year":"2000","unstructured":"Mariki M. Eloff and Sebastiaan H. von Solms. 2000. Information security management: A hierarchical framework for various approaches. Comput. Secur. 19, 3 (2000), 243\u2013256.","journal-title":"Comput. Secur."},{"key":"e_1_3_2_40_2","first-page":"2595","volume-title":"IEEE International Conference on Big Data (Big Data\u201922)","author":"Eriksson H\u00e5kon Svee","year":"2022","unstructured":"H\u00e5kon Svee Eriksson and Gudmund Grov. 2022. Towards XAI in the SOC\u2014A user centric study of explainable alerts with SHAP and LIME. In IEEE International Conference on Big Data (Big Data\u201922). IEEE, 2595\u20132600."},{"key":"e_1_3_2_41_2","article-title":"Enhancing your security posture with the new eSentire threat intelligence offering","year":"2024","unstructured":"eSentire. 2024. Enhancing your security posture with the new eSentire threat intelligence offering. Retrieved from https:\/\/www.esentire.com\/blog\/enhancing-your-security-posture-with-the-new-esentire-threat-intelligence-offering","journal-title":"R"},{"key":"e_1_3_2_42_2","unstructured":"European Union. 2016. General Data Protection Regulation (GDPR). Retrieved from https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj"},{"key":"e_1_3_2_43_2","unstructured":"Rik Ferguson. 2023. SOCs face alert fatigue false Positives decreased visibility\u2014and employee burnout. Retrieved from https:\/\/www.scmagazine.com\/perspective\/socs-face-alert-fatigue-false-positives-decreased-visibility-and-employee-burnout"},{"key":"e_1_3_2_44_2","volume-title":"Symposium on Usable Privacy and Security (SOUPS\u201917)","author":"Filar Bobby","year":"2017","unstructured":"Bobby Filar, Richard Seymour, and Matthew Park. 2017. Ask me anything: A conversational interface to augment information security workers. In Symposium on Usable Privacy and Security (SOUPS\u201917)."},{"key":"e_1_3_2_45_2","unstructured":"Anna Fleck. 2022. Cybercrime expected to skyrocket in coming years\u2014Statista\u2019s cybersecurity outlook. Retrieved from https:\/\/www.statista.com\/chart\/28878\/expected-cost-of-cybercrime-until-2027"},{"key":"e_1_3_2_46_2","article-title":"ArcSight intelligence use cases","author":"Focus Micro","year":"2024","unstructured":"Micro Focus. 2024. ArcSight intelligence use cases. Retrieved from https:\/\/www.microfocus.com\/en-us\/use-case\/arcsight-intelligence","journal-title":"R"},{"key":"e_1_3_2_47_2","article-title":"Secure cyber defense case study","year":"2024","unstructured":"Fortinet. 2024. Secure cyber defense case study. Retrieved from https:\/\/www.fortinet.com\/content\/dam\/fortinet\/assets\/case-studies\/cs-secure-cyber.pdf","journal-title":"R"},{"key":"e_1_3_2_48_2","article-title":"That escalated quickly: An ML framework for alert prioritization","author":"Gelman Ben","year":"2023","unstructured":"Ben Gelman, Salma Taoufiq, Tam\u00e1s V\u00f6r\u00f6s, and Konstantin Berlin. 2023. That escalated quickly: An ML framework for alert prioritization. arXiv preprint arXiv:2302.06648 (2023).","journal-title":"arXiv preprint arXiv:2302.06648"},{"key":"e_1_3_2_49_2","volume-title":"Exploring C2 Capability and Effectiveness in Challenging Situations: Interorganizational Crisis Management, Military Operations and Cyber Defence","author":"Gran\u00e5sen Magdalena","year":"2019","unstructured":"Magdalena Gran\u00e5sen. 2019. Exploring C2 Capability and Effectiveness in Challenging Situations: Interorganizational Crisis Management, Military Operations and Cyber Defence. Vol. 1836. Link\u00f6ping University Electronic Press."},{"key":"e_1_3_2_50_2","unstructured":"GreyNoise. 2022. Panther Labs and GreyNoise partner to help security teams combat alert fatigue. Retrieved from https:\/\/www.greynoise.io\/press\/panther-labs-and-greynoise-partner-to-help-security-teams-combat-alert-fatigue"},{"key":"e_1_3_2_51_2","first-page":"5864","volume-title":"IEEE International Conference on Big Data (Big Data\u201919)","author":"Gupta Nitika","year":"2019","unstructured":"Nitika Gupta, Issa Traore, and Paulo Magella Faria de Quinan. 2019. Automated event prioritization for security operation center using deep learning. In IEEE International Conference on Big Data (Big Data\u201919). IEEE, 5864\u20135872."},{"issue":"4","key":"e_1_3_2_52_2","doi-asserted-by":"crossref","first-page":"376","DOI":"10.1109\/TCOM.1981.1095004","article-title":"Network management and congestion in the US telecommunications network","volume":"29","author":"Haenschke D.","year":"1981","unstructured":"D. Haenschke, D. Kettler, and Eric Oberer. 1981. Network management and congestion in the US telecommunications network. IEEE Trans. Commun. 29, 4 (1981), 376\u2013385.","journal-title":"IEEE Trans. Commun."},{"key":"e_1_3_2_53_2","first-page":"224","volume-title":"International Conference on Applied Human Factors and Ergonomics","author":"H\u00e1mornik Bal\u00e1zs P\u00e9ter","year":"2017","unstructured":"Bal\u00e1zs P\u00e9ter H\u00e1mornik and Csaba Krasznay. 2017. A team-level perspective of human factors in cyber security: Security operations centers. In International Conference on Applied Human Factors and Ergonomics. Springer, 224\u2013236."},{"key":"e_1_3_2_54_2","first-page":"1172","volume-title":"IEEE Symposium on Security and Privacy (SP\u201920)","author":"Hassan Wajih Ul","year":"2020","unstructured":"Wajih Ul Hassan, Adam Bates, and Daniel Marino. 2020. Tactical provenance analysis for endpoint detection and response systems. In IEEE Symposium on Security and Privacy (SP\u201920). IEEE, 1172\u20131189."},{"key":"e_1_3_2_55_2","volume-title":"Network and Distributed Systems Security Symposium (NDSS\u201919)","author":"Hassan Wajih Ul","year":"2019","unstructured":"Wajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen, Kangkook Jee, Zhichun Li, and Adam Bates. 2019. NoDoze: Combatting threat alert fatigue with automated provenance triage. In Network and Distributed Systems Security Symposium (NDSS\u201919)."},{"key":"e_1_3_2_56_2","first-page":"381","volume-title":"IEEE Symposium Series on Computational Intelligence (SSCI\u201922)","author":"Himmelhuber Anna","year":"2022","unstructured":"Anna Himmelhuber, Dominik Dold, Stephan Grimm, Sonia Zillner, and Thomas Runkler. 2022. Detection, explanation and filtering of cyber attacks combining symbolic and sub-symbolic methods. In IEEE Symposium Series on Computational Intelligence (SSCI\u201922). IEEE, 381\u2013388."},{"key":"e_1_3_2_57_2","first-page":"31","volume-title":"Voice of the SOC","author":"Hinchy Eoin","year":"2023","unstructured":"Eoin Hinchy. 2023. Voice of the SOC. Technical Report. Tines. 31 pages. Retrieved from https:\/\/www.tines.com\/reports\/voice-of-the-soc-2023"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102844"},{"key":"e_1_3_2_59_2","first-page":"1","volume-title":"15th International Conference on Availability, Reliability and Security","author":"Hus\u00e1k Martin","year":"2020","unstructured":"Martin Hus\u00e1k, Tom\u00e1\u0161 Jirs\u00edk, and Shanchieh Jay Yang. 2020. SoK: Contemporary issues and challenges to enable cyber situational awareness for network security. In 15th International Conference on Availability, Reliability and Security. 1\u201310."},{"key":"e_1_3_2_60_2","article-title":"From security alerts to actionable insights: How context can save you time and money","author":"Icusca Angel","year":"2019","unstructured":"Angel Icusca. 2019. From security alerts to actionable insights: How context can save you time and money. Retrieved from https:\/\/www.bitdefender.com\/en-us\/blog\/businessinsights\/security-alerts-actionable-insights-context-can-save-you-time-money","journal-title":"R"},{"key":"e_1_3_2_61_2","unstructured":"Intezer. 2023. Legato MSSP scaled SOC analysis with automation. Retrieved from https:\/\/intezer.com\/resources\/case-study\/legato-mssp-scaled-soc-analysis-automation\/"},{"key":"e_1_3_2_62_2","unstructured":"Intezer. 2024. DPD automates SOC tier 1 tasks with Intezer. Retrieved from https:\/\/intezer.com\/resources\/case-study\/dpd-automates-soc-tier-1-tasks-with-intezer\/"},{"key":"e_1_3_2_63_2","article-title":"Towards a criteria-based approach to selecting human\u2013AI interaction mode","author":"Irons Jessica","year":"2024","unstructured":"Jessica Irons, Patrick Cooper, Melanie McGrath, Shahroz Tariq, and Andreas Duenser. 2024. Towards a criteria-based approach to selecting human\u2013AI interaction mode. arXiv preprint arXiv:2411.07406 (2024).","journal-title":"arXiv preprint arXiv:2411.07406"},{"key":"e_1_3_2_64_2","article-title":"The evolution of security operations and strategies for building an effective SOC","volume":"5","author":"Kaliyaperumal Lakshmi Narayanan","year":"2021","unstructured":"Lakshmi Narayanan Kaliyaperumal. 2021. The evolution of security operations and strategies for building an effective SOC. ISACA J. 5 (2021), 1\u20137.","journal-title":"ISACA J."},{"key":"e_1_3_2_65_2","first-page":"102789","article-title":"Threat classification model for security information event management focusing on model efficiency","author":"Kim Jae-yeol","year":"2022","unstructured":"Jae-yeol Kim and Hyuk-Yoon Kwon. 2022. Threat classification model for security information event management focusing on model efficiency. Comput. Secur. 120 (2022), 102789.","journal-title":"Comput. Secur."},{"key":"e_1_3_2_66_2","volume-title":"11 Strategies of a World-Class Cybersecurity Operations Center","author":"Knerler Kathryn","year":"2022","unstructured":"Kathryn Knerler, Ingrid Parker, and Zimmerman Carson. 2022. 11 Strategies of a World-Class Cybersecurity Operations Center. MITRE."},{"key":"e_1_3_2_67_2","first-page":"1955","volume-title":"ACM SIGSAC Conference on Computer and Communications Security","author":"Kokulu Faris Bugra","year":"2019","unstructured":"Faris Bugra Kokulu, Ananta Soneji, Tiffany Bao, Yan Shoshitaishvili, Ziming Zhao, Adam Doup\u00e9, and Gail-Joon Ahn. 2019. Matched and mismatched SOCs: A qualitative study on security operations center issues. In ACM SIGSAC Conference on Computer and Communications Security. 1955\u20131970."},{"key":"e_1_3_2_68_2","doi-asserted-by":"crossref","first-page":"265","DOI":"10.1007\/978-3-642-39377-8_31","volume-title":"Information Assurance and Security Education and Training","author":"Kowalski Stewart","year":"2013","unstructured":"Stewart Kowalski, Katarina Pavlovska, and Mikael Goldstein. 2013. Two case studies in using chatbots for security training. In Information Assurance and Security Education and Training. Springer, 265\u2013272."},{"key":"e_1_3_2_69_2","first-page":"470","volume-title":"IEEE Conference on Technologies for Homeland Security (HST\u201912)","author":"Kowtha Sitaram","year":"2012","unstructured":"Sitaram Kowtha, Laura A. Nolan, and Rosemary A. Daley. 2012. Cyber security operations center characterization model and analysis. In IEEE Conference on Technologies for Homeland Security (HST\u201912). IEEE, 470\u2013475."},{"key":"e_1_3_2_70_2","article-title":"Reducing security alert fatigue using machine learning in Azure Sentinel","author":"Kumar Ram Shankar Siva","year":"2019","unstructured":"Ram Shankar Siva Kumar. 2019. Reducing security alert fatigue using machine learning in Azure Sentinel. Retrieved from https:\/\/azure.microsoft.com\/en-us\/blog\/reducing-security-alert-fatigue-using-machine-learning-in-azure-sentinel\/","journal-title":"R"},{"key":"e_1_3_2_71_2","article-title":"Human-AI collaboration in decision-making: Beyond learning to defer","author":"Leit\u00e3o Diogo","year":"2022","unstructured":"Diogo Leit\u00e3o, Pedro Saleiro, M\u00e1rio A. T. Figueiredo, and Pedro Bizarro. 2022. Human-AI collaboration in decision-making: Beyond learning to defer. arXiv preprint arXiv:2206.13202 (2022).","journal-title":"arXiv preprint arXiv:2206.13202"},{"key":"e_1_3_2_72_2","article-title":"CyGIL: A cyber gym for training autonomous agents over emulated network systems","author":"Li Li","year":"2021","unstructured":"Li Li, Raed Fayad, and Adrian Taylor. 2021. CyGIL: A cyber gym for training autonomous agents over emulated network systems. arXiv preprint arXiv:2109.03331 (2021).","journal-title":"arXiv preprint arXiv:2109.03331"},{"key":"e_1_3_2_73_2","first-page":"589","volume-title":"Computer Security\u2013ESORICS 2022: 27th European Symposium on Research in Computer Security, Copenhagen, Denmark, September 26\u201330, 2022, Proceedings, Part I","author":"Li Zhenyuan","year":"2022","unstructured":"Zhenyuan Li, Jun Zeng, Yan Chen, and Zhenkai Liang. 2022. AttacKG: Constructing technique knowledge graph from cyber threat intelligence reports. In Computer Security\u2013ESORICS 2022: 27th European Symposium on Research in Computer Security, Copenhagen, Denmark, September 26\u201330, 2022, Proceedings, Part I. Springer, 589\u2013609."},{"key":"e_1_3_2_74_2","first-page":"4295","volume-title":"IEEE International Conference on Big Data (Big Data\u201922)","author":"Lin Derek","year":"2022","unstructured":"Derek Lin. 2022. MATE: Summarizing alerts to interpretable outcomes with MITRE ATT&CK. In IEEE International Conference on Big Data (Big Data\u201922). IEEE, 4295\u20134302."},{"key":"e_1_3_2_75_2","volume-title":"A Data Triage Retrieval System for Cyber Security Operations Center","author":"Lin Tao","year":"2018","unstructured":"Tao Lin. 2018. A Data Triage Retrieval System for Cyber Security Operations Center. Master\u2019s Thesis. Pennsylvania State University."},{"key":"e_1_3_2_76_2","unstructured":"Otto Lindstr\u00f6m. 2018. Next generation security operations center. Metropolia University of Applied Sciences. Retrieved from https:\/\/www.theseus.fi\/bitstream\/handle\/10024\/157357\/Lindstrom_Otto.pdf?sequence=1"},{"key":"e_1_3_2_77_2","doi-asserted-by":"crossref","first-page":"106856","DOI":"10.1016\/j.infsof.2022.106856","article-title":"Context2Vector: Accelerating security event triage via context representation learning","volume":"146","author":"Liu Jia","year":"2022","unstructured":"Jia Liu, Runzi Zhang, Wenmao Liu, Yinghua Zhang, Dujuan Gu, Mingkai Tong, Xingkai Wang, Jianxin Xue, and Huanran Wang. 2022. Context2Vector: Accelerating security event triage via context representation learning. Inf. Softw. Technol. 146 (2022), 106856.","journal-title":"Inf. Softw. Technol."},{"key":"e_1_3_2_78_2","first-page":"1","volume-title":"1st International Conference on Informatics Engineering, Science and Technology.","author":"Majid M. A.","year":"2019","unstructured":"M. A. Majid and K. Ariffi. 2019. Success factors for cyber security operation center (SOC) establishment. In 1st International Conference on Informatics Engineering, Science and Technology.1\u201311."},{"key":"e_1_3_2_79_2","unstructured":"MarketsandMarkets. 2022. SOC as a service market worth $10.1 billion by 2027. Retrieved from www.marketsandmarkets.com\/PressReleases\/soc-as-a-service.asp"},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.joi.2018.09.002"},{"key":"e_1_3_2_81_2","unstructured":"Jim McDonough. 2023. Security operations center alert fatigue: How AI can help analysts. Retrieved from https:\/\/intezer.com\/blog\/incident-response\/security-operations-center-alert-fatigue-ai-analysts\/"},{"key":"e_1_3_2_82_2","article-title":"Collaborative human\u2013AI trust (CHAI-T): A process framework for active management of trust in human\u2013AI collaboration","author":"McGrath Melanie J.","year":"2024","unstructured":"Melanie J. McGrath, Andreas Duenser, Justine Lacey, and Cecile Paris. 2024. Collaborative human\u2013AI trust (CHAI-T): A process framework for active management of trust in human\u2013AI collaboration. arXiv preprint arXiv:2404.01615 (2024).","journal-title":"arXiv preprint arXiv:2404.01615"},{"issue":"2","key":"e_1_3_2_83_2","doi-asserted-by":"crossref","first-page":"379","DOI":"10.3390\/jcp2020020","article-title":"Improved detection and response via optimized alerts: Usability study","volume":"2","author":"McRee Griffith Russell","year":"2022","unstructured":"Griffith Russell McRee. 2022. Improved detection and response via optimized alerts: Usability study. J. Cybersec. Privac. 2, 2 (2022), 379\u2013401.","journal-title":"J. Cybersec. Privac."},{"key":"e_1_3_2_84_2","unstructured":"Trend Micro. 2021. A global study: Security operations on the backfoot. Retrieved from www.multivu.com\/players\/English\/8967351-trend-micro-cybersecurity-tool-sprawl-drives-plans-outsource-detection-response"},{"key":"e_1_3_2_85_2","unstructured":"MITRE Corporation. 2024. MITRE ATT&CK. Retrieved from https:\/\/attack.mitre.org\/"},{"key":"e_1_3_2_86_2","unstructured":"Montance. 2024. SOC class: Security operations center training and maturity model. Retrieved from https:\/\/montance.com\/soc-class"},{"key":"e_1_3_2_87_2","first-page":"33","volume-title":"Global Security Operations Center Study Results","author":"Consult Morning","year":"2023","unstructured":"Morning Consult. 2023. Global Security Operations Center Study Results. Technical Report. IBM. 33 pages. Retrieved from https:\/\/www.ibm.com\/downloads\/cas\/5AEDAOJN"},{"key":"e_1_3_2_88_2","first-page":"5323","volume-title":"AAAI Conference on Artificial Intelligence","volume":"36","author":"Mozannar Hussein","year":"2022","unstructured":"Hussein Mozannar, Arvind Satyanarayan, and David Sontag. 2022. Teaching humans when to defer to a classifier via exemplars. In AAAI Conference on Artificial Intelligence, Vol. 36. 5323\u20135331."},{"key":"e_1_3_2_89_2","first-page":"7076","volume-title":"International Conference on Machine Learning (ICML\u201920)","author":"Mozannar Hussein","year":"2020","unstructured":"Hussein Mozannar and David Sontag. 2020. Consistent estimators for learning to defer to an expert. In International Conference on Machine Learning (ICML\u201920). PMLR, 7076\u20137087."},{"key":"e_1_3_2_90_2","volume-title":"The Modern Security Operations Center","author":"Muniz J.","year":"2021","unstructured":"J. Muniz. 2021. The Modern Security Operations Center. Addison-Wesley. Retrieved from https:\/\/books.google.com.au\/books?id=RMDCwAEACAAJ"},{"key":"e_1_3_2_91_2","volume-title":"Security Operations Center: Building, Operating, and Maintaining your SOC","author":"Muniz Joseph","year":"2015","unstructured":"Joseph Muniz, Gary McIntyre, and Nadhem AlFardan. 2015. Security Operations Center: Building, Operating, and Maintaining your SOC. Cisco Press."},{"key":"e_1_3_2_92_2","volume-title":"International Conference on Intelligent and Innovative Computing Applications (ICONIC\u201918)","author":"Mutemwa Muyowa","year":"2018","unstructured":"Muyowa Mutemwa, Jabu Mtsweni, and Lukhanyo Zimba. 2018. Integrating a security operations centre with an organization\u2019s existing procedures, policies and information technology systems. In International Conference on Intelligent and Innovative Computing Applications (ICONIC\u201918). IEEE."},{"key":"e_1_3_2_93_2","first-page":"36","volume-title":"IEEE Symposium on Visualization for Cyber Security (VizSec\u201921)","author":"Nadeem Azqa","year":"2021","unstructured":"Azqa Nadeem, Sicco Verwer, and Shanchieh Jay Yang. 2021. SAGE: Intrusion alert-driven attack graph extractor. In IEEE Symposium on Visualization for Cyber Security (VizSec\u201921). IEEE, 36\u201341."},{"key":"e_1_3_2_94_2","unstructured":"National Cyber Security Centre. 2024. Building a security operations centre. Retrieved from https:\/\/www.ncsc.gov.uk\/collection\/building-a-security-operations-centre"},{"key":"e_1_3_2_95_2","unstructured":"National Institute of Standards and Technology. 2024. The NIST Cybersecurity Framework 2.0. Retrieved from https:\/\/www.nist.gov\/cyberframework"},{"key":"e_1_3_2_96_2","first-page":"2119","volume-title":"IEEE International Conference on Big Data (Big Data\u201921)","author":"Ndichu Samuel","year":"2021","unstructured":"Samuel Ndichu, Tao Ban, Takeshi Takahashi, and Daisuke Inoue. 2021. A machine learning approach to detection of critical alerts from imbalanced multi-appliance threat alert logs. In IEEE International Conference on Big Data (Big Data\u201921). IEEE, 2119\u20132127."},{"key":"e_1_3_2_97_2","first-page":"3007","volume-title":"IEEE International Conference on Big Data (Big Data\u201922)","author":"Ndichu Samuel","year":"2022","unstructured":"Samuel Ndichu, Tao Ban, Takeshi Takahashi, and Daisuke Inoue. 2022. Critical-threat-alert detection using online machine learning. In IEEE International Conference on Big Data (Big Data\u201922). IEEE, 3007\u20133014."},{"key":"e_1_3_2_98_2","article-title":"User & entity behavior analytics","year":"2024","unstructured":"Netsurion. 2024. User & entity behavior analytics. Retrieved from https:\/\/www.netsurion.com\/capabilities\/ueba","journal-title":"R"},{"key":"e_1_3_2_99_2","article-title":"Alerts","author":"Networks Barracuda","year":"2024","unstructured":"Barracuda Networks. 2024. Alerts. Retrieved from https:\/\/campus.barracuda.com\/product\/ContentShield\/doc\/171671579\/alerts\/","journal-title":"R"},{"key":"e_1_3_2_100_2","doi-asserted-by":"publisher","DOI":"10.1145\/3701716.3715469"},{"key":"e_1_3_2_101_2","first-page":"1","volume-title":"International Conference on Cyber Security and Protection of Digital Services (Cyber Security\u201919)","author":"Onwubiko Cyril","year":"2019","unstructured":"Cyril Onwubiko and Karim Ouazzane. 2019. Cyber onboarding is \u201cbroken.\u201d In International Conference on Cyber Security and Protection of Digital Services (Cyber Security\u201919). IEEE, 1\u201313."},{"key":"e_1_3_2_102_2","article-title":"Challenges towards building an effective cyber security operations centre","author":"Onwubiko Cyril","year":"2022","unstructured":"Cyril Onwubiko and Karim Ouazzane. 2022. Challenges towards building an effective cyber security operations centre. arXiv preprint arXiv:2202.03691 (2022).","journal-title":"arXiv preprint arXiv:2202.03691"},{"key":"e_1_3_2_103_2","article-title":"ChatGPT: A large language model trained by OpenAI","year":"2021","unstructured":"OpenAI. 2021. ChatGPT: A large language model trained by OpenAI. Retrieved from https:\/\/openai.com\/","journal-title":"R"},{"key":"e_1_3_2_104_2","first-page":"124","volume-title":"34th Annual Computer Security Applications Conference","author":"Oprea Alina","year":"2018","unstructured":"Alina Oprea, Zhou Li, Robin Norris, and Kevin Bowers. 2018. Made: Security analytics for enterprise threat detection. In 34th Annual Computer Security Applications Conference. 124\u2013136."},{"key":"e_1_3_2_105_2","unstructured":"OTAVA. 2025. Case study: OTAVA ends alert fatigue for technology solutions company. Retrieved from https:\/\/www.otava.com\/casestudy\/otava-ends-alert-fatigue-for-technology-solutions-company\/"},{"key":"e_1_3_2_106_2","unstructured":"OTORIO. 2025. Case study: Eliminating alert fatigue by adding OT risk context. Retrieved from https:\/\/www.otorio.com\/blog\/case-study-eliminating-alert-fatigue-adding-ot-risk-context\/"},{"key":"e_1_3_2_107_2","first-page":"177","volume-title":"The Conversation on Work","author":"Paris C\u00e9cile","year":"2024","unstructured":"C\u00e9cile Paris and Andrew Reeson. 2024. What\u2019s the secret to making sure AI does not steal your job? Work with it, not against it. In The Conversation on Work, Ian O. Williamson (Ed.). Johns Hopkins University Press, Baltimore, 177\u2013181."},{"key":"e_1_3_2_108_2","first-page":"340","volume-title":"International Conference on Advancements in Computing (ICAC\u201919)","author":"Perera Vihanga Heshan","year":"2019","unstructured":"Vihanga Heshan Perera, Amila Nuwan Senarathne, and Lakmal Rupasinghe. 2019. Intelligent SOC chatbot for security operation center. In International Conference on Advancements in Computing (ICAC\u201919). IEEE, 340\u2013345."},{"key":"e_1_3_2_109_2","unstructured":"PurpleSec. 2023. Cyber security statistics The ultimate list of stats data & trends for 2023. Retrieved from https:\/\/purplesec.us\/resources\/cyber-security-statistics"},{"key":"e_1_3_2_110_2","volume-title":"IEEE Symposium on Visualization for Cyber Security (VizSec\u201921)","author":"Rapp Robert-Carl","year":"2021","unstructured":"Robert-Carl Rapp, Christoph M\u00fcller, Franziska Becker, Paolo Palumbo, and Thomas Ertl. 2021. Interactive process tree analysis: Exploring the behaviour of processes with visual analytics for security operators. In IEEE Symposium on Visualization for Cyber Security (VizSec\u201921). 109\u2013124."},{"key":"e_1_3_2_111_2","doi-asserted-by":"publisher","DOI":"10.1145\/3472291"},{"key":"e_1_3_2_112_2","unstructured":"Mario Rojas. 2021. How Maltego helps SOC teams: Reduces alert fatigue and accelerates resolution time. Retrieved from https:\/\/www.maltego.com\/blog\/how-maltego-helps-soc-teams-reduces-alert-fatigue-and-accelerates-resolution-time\/"},{"key":"e_1_3_2_113_2","volume-title":"RSA Conference","volume":"2012","author":"Rothke Ben","year":"2012","unstructured":"Ben Rothke and CISSP CISM. 2012. Building a security operations center (SOC). In RSA Conference, Vol. 2012."},{"key":"e_1_3_2_114_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10796-021-10226-5"},{"key":"e_1_3_2_115_2","first-page":"598","volume-title":"IEEE European Symposium on Security and Privacy (EuroS&P\u201921)","author":"Satvat Kiavash","year":"2021","unstructured":"Kiavash Satvat, Rigel Gjomemo, and V. N. Venkatakrishnan. 2021. EXTRACTOR: Extracting attack behavior from threat reports. In IEEE European Symposium on Security and Privacy (EuroS&P\u201921). IEEE, 598\u2013615."},{"issue":"6","key":"e_1_3_2_116_2","doi-asserted-by":"crossref","first-page":"839","DOI":"10.1016\/j.jprocont.2013.03.010","article-title":"A combined analysis of plant connectivity and alarm logs to reduce the number of alerts in an automation system","volume":"23","author":"Schleburg Markus","year":"2013","unstructured":"Markus Schleburg, Lars Christiansen, Nina F. Thornhill, and Alexander Fay. 2013. A combined analysis of plant connectivity and alarm logs to reduce the number of alerts in an automation system. J. Process Contr. 23, 6 (2013), 839\u2013851.","journal-title":"J. Process Contr."},{"issue":"1","key":"e_1_3_2_117_2","doi-asserted-by":"crossref","first-page":"2327890","DOI":"10.1080\/08839514.2024.2327890","article-title":"Collaborative Intelligence: A scoping review of current applications","volume":"38","author":"Schleiger Emma","year":"2024","unstructured":"Emma Schleiger, Claire Mason, Claire Naughtin, Andrew Reeson, and Cecile Paris. 2024. Collaborative Intelligence: A scoping review of current applications. Appl. Artif. Intell. 38, 1 (2024), 2327890.","journal-title":"Appl. Artif. Intell."},{"key":"e_1_3_2_118_2","doi-asserted-by":"publisher","unstructured":"Aaron Schlenker Haifeng Xu Mina Guirguis Christopher Kiekintveld Arunesh Sinha Milind Tambe Solomon Sonya Darryl Balderas and Noah Dunstatter. 2017. Don\u2019t bury your head in warnings: A game-theoretic approach for intelligent allocation of cyber-security alerts. In Proceedings of the Twenty-Sixth International Joint Conference on Artificial Intelligence IJCAI-17. 381\u2013387. DOI:10.24963\/ijcai.2017\/54","DOI":"10.24963\/ijcai.2017\/54"},{"key":"e_1_3_2_119_2","first-page":"191","volume-title":"International Conference on Human-Computer Interaction","author":"Scholefield Sam","year":"2019","unstructured":"Sam Scholefield and Lynsay A. Shepherd. 2019. Gamification techniques for raising cyber security awareness. In International Conference on Human-Computer Interaction. Springer, 191\u2013203."},{"key":"e_1_3_2_120_2","unstructured":"Cado Security. 2024. SOC alert fatigue: How to manage overload in cybersecurity. Retrieved from https:\/\/www.cadosecurity.com\/wiki\/soc-alert-fatigue-how-to-manage-overload-in-cybersecurity"},{"key":"e_1_3_2_121_2","unstructured":"Microsoft Security. 2021. 6 strategies to reduce cybersecurity alert fatigue in your SOC. Retrieved from https:\/\/www.microsoft.com\/en-us\/security\/blog\/2021\/02\/17\/6-strategies-to-reduce-cybersecurity-alert-fatigue-in-your-soc\/"},{"key":"e_1_3_2_122_2","article-title":"Beating alert fatigue with Cortex XDR SmartScore technology","author":"Sela Niv","year":"2022","unstructured":"Niv Sela, Guy Mazaltrim, Gal Itzhak, and Yinnon Meshi. 2022. Beating alert fatigue with Cortex XDR SmartScore technology. Retrieved from https:\/\/www.paloaltonetworks.com\/blog\/security-operations\/beating-alert-fatigue-with-cortex-xdr-smartscore-technology\/","journal-title":"R"},{"key":"e_1_3_2_123_2","doi-asserted-by":"publisher","DOI":"10.1145\/3173457"},{"issue":"7","key":"e_1_3_2_124_2","doi-asserted-by":"crossref","first-page":"1857","DOI":"10.1109\/TIFS.2018.2886465","article-title":"A two-step approach to optimal selection of alerts for investigation in a CSOC","volume":"14","author":"Shah Ankit","year":"2018","unstructured":"Ankit Shah, Rajesh Ganesan, Sushil Jajodia, and Hasan Cam. 2018. A two-step approach to optimal selection of alerts for investigation in a CSOC. IEEE Trans. Inf. Forens. Secur. 14, 7 (2018), 1857\u20131870.","journal-title":"IEEE Trans. Inf. Forens. Secur."},{"key":"e_1_3_2_125_2","doi-asserted-by":"publisher","DOI":"10.1145\/3372498"},{"key":"e_1_3_2_126_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-021-00573-4"},{"issue":"1","key":"e_1_3_2_127_2","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1109\/TPDS.2019.2927977","article-title":"Adaptive alert management for balancing optimal performance among distributed CSOCs using reinforcement learning","volume":"31","author":"Shah Ankit","year":"2019","unstructured":"Ankit Shah, Rajesh Ganesan, Sushil Jajodia, Pierangela Samarati, and Hasan Cam. 2019. Adaptive alert management for balancing optimal performance among distributed CSOCs using reinforcement learning. IEEE Trans. Parallel Distrib. Syst. 31, 1 (2019), 16\u201333.","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"issue":"8","key":"e_1_3_2_128_2","doi-asserted-by":"crossref","first-page":"1313","DOI":"10.1109\/TVCG.2011.144","article-title":"A survey of visualization systems for network security","volume":"18","author":"Shiravi Hadi","year":"2011","unstructured":"Hadi Shiravi, Ali Shiravi, and Ali A. Ghorbani. 2011. A survey of visualization systems for network security. IEEE Trans. Visualiz. Comput. Graph. 18, 8 (2011), 1313\u20131329.","journal-title":"IEEE Trans. Visualiz. Comput. Graph."},{"issue":"3","key":"e_1_3_2_129_2","article-title":"Human-centered artificial intelligence: Three fresh ideas","volume":"12","author":"Shneiderman Ben","year":"2020","unstructured":"Ben Shneiderman. 2020. Human-centered artificial intelligence: Three fresh ideas. AIS Trans. Hum.-Comput. Interact. 12, 3 (2020).","journal-title":"AIS Trans. Hum.-Comput. Interact."},{"key":"e_1_3_2_130_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_131_2","article-title":"Companies have too many Security tools. Here\u2019s how we\u2019re solving that.","author":"Smith Ryan","year":"2019","unstructured":"Ryan Smith. 2019. Companies have too many Security tools. Here\u2019s how we\u2019re solving that. Retrieved from https:\/\/res.armor.com\/resources\/blog\/too-many-security-tools\/","journal-title":"R"},{"key":"e_1_3_2_132_2","unstructured":"SOC-CMM. 2024. SOC-CMM: Security operations center capability maturity model. Retrieved from https:\/\/www.soc-cmm.com\/"},{"key":"e_1_3_2_133_2","first-page":"1","volume-title":"IEEE Symposium on Visualization for Cyber Security (VizSec\u201918)","author":"Sopan Awalin","year":"2018","unstructured":"Awalin Sopan, Matthew Berninger, Murali Mulakaluri, and Raj Katakam. 2018. Building a machine learning model for the SOC, by the input from the SOC, and analyzing it for the SOC. In IEEE Symposium on Visualization for Cyber Security (VizSec\u201918). IEEE, 1\u20138."},{"key":"e_1_3_2_134_2","article-title":"Four key tips from incident response experts","year":"2024","unstructured":"Sophos. 2024. Four key tips from incident response experts. Retrieved from https:\/\/www.sophos.com\/en-us\/whitepaper\/four-key-tips-from-incident-response-experts.","journal-title":"R"},{"key":"e_1_3_2_135_2","first-page":"347","volume-title":"11th Symposium On Usable Privacy and Security (SOUPS\u201915)","author":"Sundaramurthy Sathya Chandran","year":"2015","unstructured":"Sathya Chandran Sundaramurthy, Alexandru G. Bardas, Jacob Case, Xinming Ou, Michael Wesch, John McHugh, and S. Raj Rajagopalan. 2015. A human capital model for mitigating security analyst burnout. In 11th Symposium On Usable Privacy and Security (SOUPS\u201915). 347\u2013359."},{"key":"e_1_3_2_136_2","article-title":"A2C: A modular multi-stage collaborative decision framework for human-AI teams","author":"Tariq Shahroz","year":"2024","unstructured":"Shahroz Tariq, Mohan Baruwal Chhetri, Surya Nepal, and Cecile Paris. 2024. A2C: A modular multi-stage collaborative decision framework for human-AI teams. arXiv preprint arXiv:2401.14432 (2024).","journal-title":"arXiv preprint arXiv:2401.14432"},{"key":"e_1_3_2_137_2","doi-asserted-by":"publisher","unstructured":"Shahroz Tariq Sangyup Lee Youjin Shin Myeong Shin Lee Okchul Jung Daewon Chung and Simon S. Woo. 2019. Detecting anomalies in space using multivariate convolutional LSTM with mixtures of probabilistic PCA. InInternational Conference on Knowledge Discovery & Data Mining (KDD\u201919). Association for Computing Machinery New York NY USA 2123\u20132133. DOI:10.1145\/3292500.3330776","DOI":"10.1145\/3292500.3330776"},{"key":"e_1_3_2_138_2","unstructured":"Torq. 2024. Check Point case study. Retrieved from https:\/\/torq.io\/resources\/check-point-case-study\/"},{"key":"e_1_3_2_139_2","unstructured":"Tripwire. 2024. Mitigating alert fatigue in SecOps teams. Retrieved from https:\/\/www.tripwire.com\/state-of-security\/mitigating-alert-fatigue-secops-teams"},{"key":"e_1_3_2_140_2","unstructured":"U.S. Department of Health and Human Services. 1996. Health Insurance Portability and Accountability Act (HIPAA). Retrieved from https:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/index.html"},{"key":"e_1_3_2_141_2","doi-asserted-by":"publisher","unstructured":"Thijs van Ede Hojjat Aghakhani Noah Spahn Riccardo Bortolameotti Marco Cova Andrea Continella Maarten van Steen Andreas Peter Christopher Kruegel and Giovanni Vigna. 2022. DEEPCASE: Semi-supervised contextual analysis of security events. In 2022 IEEE Symposium on Security and Privacy (SP). 522\u2013539. DOI:10.1109\/SP46214.2022.9833671","DOI":"10.1109\/SP46214.2022.9833671"},{"key":"e_1_3_2_142_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3045514"},{"key":"e_1_3_2_143_2","doi-asserted-by":"crossref","first-page":"763","DOI":"10.1145\/3514094.3534150","volume-title":"Proceedings of the AAAI\/ACM Conference on AI, Ethics, and Society","author":"Vodrahalli Kailas","year":"2022","unstructured":"Kailas Vodrahalli, Roxana Daneshjou, Tobias Gerstenberg, and James Zou. 2022. Do humans trust advice more if it comes from AI? An analysis of human-ai interactions. In Proceedings of the AAAI\/ACM Conference on AI, Ethics, and Society. 763\u2013777."},{"key":"e_1_3_2_144_2","unstructured":"May Wang. 2023. A new era of Ccybersecurity with AI: Predictions for 2024. Retrieved from https:\/\/www.paloaltonetworks.com.au\/cybersecurity-perspectives\/a-new-era-of-cybersecurity-with-ai"},{"key":"e_1_3_2_145_2","doi-asserted-by":"publisher","unstructured":"Xu Wang Sen Wang Xingxing Liang Dawei Zhao Jincai Huang Xin Xu Bin Dai and Qiguang Miao. 2024. Deep reinforcement learning: A survey. IEEE Transactions on Neural Networks and Learning Systems 35 4 (2024) 5064\u20135078. DOI:10.1109\/TNNLS.2022.3207346","DOI":"10.1109\/TNNLS.2022.3207346"},{"issue":"10","key":"e_1_3_2_146_2","doi-asserted-by":"crossref","first-page":"e0258781","DOI":"10.1371\/journal.pone.0258781","article-title":"Public perceptions of non-adherence to pandemic protection measures by self and others: A study of COVID-19 in the United Kingdom","volume":"16","author":"Williams Simon N.","year":"2021","unstructured":"Simon N. Williams, Christopher J. Armitage, Tova Tampe, and Kimberly A. Dienes. 2021. Public perceptions of non-adherence to pandemic protection measures by self and others: A study of COVID-19 in the United Kingdom. PloS One 16, 10 (2021), e0258781.","journal-title":"PloS One"},{"key":"e_1_3_2_147_2","doi-asserted-by":"publisher","DOI":"10.1057\/ejis.2011.51"},{"key":"e_1_3_2_148_2","doi-asserted-by":"crossref","first-page":"395","DOI":"10.1007\/978-981-16-9008-2_38","volume-title":"ISUW 2020","author":"Yeshwanth M. V.","year":"2022","unstructured":"M. V. Yeshwanth, Rajesh Kalluri, M. Siddharth Rao, R. K. Kumar, and B. S. Bindhumadhava. 2022. Adoption and assessment of machine learning algorithms in security operations centre for critical infrastructure. In ISUW 2020. Springer, 395\u2013407."},{"key":"e_1_3_2_149_2","article-title":"A mental-model centric landscape of human\u2013AI symbiosis","author":"Zahedi Zahra","year":"2022","unstructured":"Zahra Zahedi, Sarath Sreedharan, and Subbarao Kambhampati. 2022. A mental-model centric landscape of human\u2013AI symbiosis. arXiv preprint arXiv:2202.09447 (2022).","journal-title":"arXiv preprint arXiv:2202.09447"},{"key":"e_1_3_2_150_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.02.011"},{"issue":"1","key":"e_1_3_2_151_2","doi-asserted-by":"crossref","first-page":"603","DOI":"10.1109\/JSYST.2018.2828832","article-title":"Learning from experts\u2019 experience: Toward automated cyber security data triage","volume":"13","author":"Zhong Chen","year":"2018","unstructured":"Chen Zhong, John Yen, Peng Liu, and Robert F. Erbacher. 2018. Learning from experts\u2019 experience: Toward automated cyber security data triage. IEEE Syst. J. 13, 1 (2018), 603\u2013614.","journal-title":"IEEE Syst. J."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3723158","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3723158","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:56:42Z","timestamp":1750298202000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3723158"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,4]]},"references-count":150,"journal-issue":{"issue":"9","published-print":{"date-parts":[[2025,9,30]]}},"alternative-id":["10.1145\/3723158"],"URL":"https:\/\/doi.org\/10.1145\/3723158","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,4]]},"assertion":[{"value":"2023-05-04","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-03-04","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-04-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}