Automated Security Operation System Based on Anomaly Traffic Detection and Scenario Orchestration
Traditional security monitoring systems not only have poor efficiency,but also generate a large number of false alarms.Security personnel can easily ignore real and harmful information by manually processing a large amount of alarm information.To this end,a SOAR automated response operation system based on abnormal traffic detection is proposed to improve the efficiency of business operations and the work efficiency of security management personnel,and achieve the refinement and automation of security operations.At the same time,for unknown threats,using artificial intelligence models for full traffic analysis can form the ability to quickly discover,trace,and dispose of unknown threats,which can break through the technical bottleneck of traditional methods in unknown threat analysis.