Leveraging Microsoft sentinel and logic apps for automated cyber threat response
Vedran Dakić (),
Zlatan Morić (),
Ana Kapulica () and
Damir Regvart ()
Edelweiss Applied Science and Technology, 2024, vol. 8, issue 6, 4319-4348
Abstract:
An integrated approach to automated cyber threat response is explored in this paper, with Microsoft Sentinel's Security Information and Event Management (SIEM) capabilities being leveraged alongside Logic Apps' workflow automation within the Azure ecosystem. Efficient identification and automated mitigation of security incidents are enabled by a combination of AI-driven analytics and advanced threat-hunting capabilities, resulting in a substantial reduction of manual intervention and response times. The approach is demonstrated to contribute scientifically across three core areas: (1) a novel integration of Sentinel's SIEM with Logic Apps is proposed to streamline response workflows using automated playbooks; (2) the effectiveness of the system is assessed through multiple cyber threat scenarios, including automated account blocking and virtual machine isolation in response to identified threats; and (3) Sentinel's performance is evaluated relative to other SIEM solutions, such as Splunk and IBM QRadar, particularly in Azure-centric and hybrid environments. The potential of Microsoft Sentinel and Logic Apps to advance proactive cybersecurity defenses is underscored, while key limitations in scalability and cross-platform adaptability are also identified.
Keywords: Automatic response, Cyber threats; Cybersecurity, Logic apps, Microsoft sentinel, Security solutions. (search for similar items in EconPapers)
Date: 2024
References: Add references at CitEc
Citations:
Downloads: (external link)
https://learning-gate.com/index.php/2576-8484/article/view/2933/1104 (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:ajp:edwast:v:8:y:2024:i:6:p:4319-4348:id:2933
Access Statistics for this article
More articles in Edelweiss Applied Science and Technology from Learning Gate
Bibliographic data for series maintained by Melissa Fernandes ().