Modern Security Information and Event Management: Architecture, Analytics Pipelines, and Empirical Evaluation of SOC-Scale Threat Detection
Lakshmi Kiran Meesala
International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 2023, vol. 9, issue 4, 995-1012
Abstract:
Security Information and Event Management (SIEM) platforms have undergone fundamental architectural transformation over three generations - from passive log aggregation and signature-based correlation to cloud-native, streaming analytics engines augmented with User and Entity Behavior Analytics (UEBA) and AI-driven threat scoring. Despite the emergence of Extended Detection and Response (XDR) and Security Orchestration, Automation and Response (SOAR) paradigms, SIEM retains indispensable centrality within enterprise Security Operations Centers (SOCs) as the normative substrate for compliance reporting, cross-domain event correlation, and forensic investigation. However, empirical data characterizing the detection performance, operational cost, and latency trade-offs of competing SIEM architectures across deployment models - on-premises, cloud-native, and hybrid - remains sparse in peer-reviewed literature. This paper formalizes a five-layer SIEM reference architecture, derives a twelve-dimensional capability taxonomy, and presents a controlled empirical evaluation of four production SIEM platforms (IBM QRadar, Splunk Enterprise Security, Microsoft Sentinel, and Elastic SIEM) across 48 SOC use cases. Results demonstrate that cloud-native SIEM achieves a 63.4% reduction in mean time-to-detect (MTTD) over on-premises deployments, while hybrid architectures reduce ingestion cost by 41.2% relative to full cloud deployments. UEBA integration reduces false positive rates by 57.3% across account compromise scenarios. These findings provide practitioners with evidence-based guidance for SIEM selection, architecture, and maturity planning.
Keywords: Security Information and Event Management (SIEM); SOC Architecture; UEBA; Threat Detection; Log Correlation; Cloud-Native Security; Mean Time-to-Detect (search for similar items in EconPapers)
Date: 2023
Note: Article URL: https://ijsrcseit.com/CSEIT23564538
References: Add references at CitEc
Citations:
Downloads: (external link)
https://ijsrcseit.com/CSEIT23564538 Article URL (text/html)
https://ijsrcseit.com/paper/CSEIT23564538.pdf Full text (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:jbh:ijsrcs:v9:y2023:i4:id:hcseit23564538
DOI: 10.32628/CSEIT23564538
Access Statistics for this article
More articles in International Journal of Scientific Research in Computer Science, Engineering and Information Technology from International Journal of Scientific Research in Computer Science, Engineering and Information Technology
Bibliographic data for series maintained by Pankaj Sharma (USA) ().