EconPapers    
Economics at your fingertips  
 

Modern Security Information and Event Management: Architecture, Analytics Pipelines, and Empirical Evaluation of SOC-Scale Threat Detection

Lakshmi Kiran Meesala

International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 2023, vol. 9, issue 4, 995-1012

Abstract: Security Information and Event Management (SIEM) platforms have undergone fundamental architectural transformation over three generations - from passive log aggregation and signature-based correlation to cloud-native, streaming analytics engines augmented with User and Entity Behavior Analytics (UEBA) and AI-driven threat scoring. Despite the emergence of Extended Detection and Response (XDR) and Security Orchestration, Automation and Response (SOAR) paradigms, SIEM retains indispensable centrality within enterprise Security Operations Centers (SOCs) as the normative substrate for compliance reporting, cross-domain event correlation, and forensic investigation. However, empirical data characterizing the detection performance, operational cost, and latency trade-offs of competing SIEM architectures across deployment models - on-premises, cloud-native, and hybrid - remains sparse in peer-reviewed literature. This paper formalizes a five-layer SIEM reference architecture, derives a twelve-dimensional capability taxonomy, and presents a controlled empirical evaluation of four production SIEM platforms (IBM QRadar, Splunk Enterprise Security, Microsoft Sentinel, and Elastic SIEM) across 48 SOC use cases. Results demonstrate that cloud-native SIEM achieves a 63.4% reduction in mean time-to-detect (MTTD) over on-premises deployments, while hybrid architectures reduce ingestion cost by 41.2% relative to full cloud deployments. UEBA integration reduces false positive rates by 57.3% across account compromise scenarios. These findings provide practitioners with evidence-based guidance for SIEM selection, architecture, and maturity planning.

Keywords: Security Information and Event Management (SIEM); SOC Architecture; UEBA; Threat Detection; Log Correlation; Cloud-Native Security; Mean Time-to-Detect (search for similar items in EconPapers)
Date: 2023
Note: Article URL: https://ijsrcseit.com/CSEIT23564538
References: Add references at CitEc
Citations:

Downloads: (external link)
https://ijsrcseit.com/CSEIT23564538 Article URL (text/html)
https://ijsrcseit.com/paper/CSEIT23564538.pdf Full text (application/pdf)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:jbh:ijsrcs:v9:y2023:i4:id:hcseit23564538

DOI: 10.32628/CSEIT23564538

Access Statistics for this article

More articles in International Journal of Scientific Research in Computer Science, Engineering and Information Technology from International Journal of Scientific Research in Computer Science, Engineering and Information Technology
Bibliographic data for series maintained by Pankaj Sharma (USA) ().

 
Page updated 2026-09-18
Handle: RePEc:jbh:ijsrcs:v9:y2023:i4:id:hcseit23564538