AN APPROACH TO AUTOMATING INITIAL RESPONSE TO CYBER INCIDENTS IN SOC BASED ON THE INTEGRATION OF SIEM AND AUTOMATED PROCESSING MECHANISMS
DOI:
https://doi.org/10.31673/2409-7292.2026.037206Abstract
The paper proposes an approach to automating the initial response to cyber incidents in a SOC based on the
integration of a SIEM system with an automated processing module and external data sources. The proposed approach
involves the automated retrieval and structuring of incident information from IBM QRadar via the REST API, followed
by data enrichment using IP address verification results, asset characteristics, and vulnerability data obtained from Nessus
Vulnerability Management. Based on the resulting context, incident prioritization, ticket creation, analyst notification,
and updating of the relevant information in the SIEM system are performed. A distinctive feature of the proposed approach
is the automation of standardized initial incident processing procedures without requiring the deployment of a full-scale
SOAR platform, while maintaining SOC analyst control over critical response actions. Experimental evaluation using
typical cyber incident scenarios demonstrated a reduction in the time required for initial incident processing and a decrease
in the number of operations requiring direct analyst involvement. The results indicate the feasibility of using the proposed
approach as an additional automation layer between the SIEM system and SOC analysts. Future research will focus on
expanding the range of incident scenarios, integrating additional cyber threat intelligence sources, and improving
mechanisms for cyber incident prioritization.
Keywords: cyber incident, cybersecurity, SIEM, SOC, automation.
References
1. Nelson A., Rekhi S., Souppaya M., Scarfone K. Incident Response Recommendations and Considerations for
Cybersecurity Risk Management: A CSF 2.0 Community Profile: NIST SP 800-61 Rev. 3 [Електронний ресурс].
Gaithersburg: National Institute of Standards and Technology, 2025. URL: https://csrc.nist.gov/pubs/sp/800/61/r3/final.
2. Kent K., Souppaya M. Guide to Computer Security Log Management: NIST SP 800-92 [Електронний
ресурс]. Gaithersburg: National Institute of Standards and Technology, 2006. URL: https://csrc.nist.gov/pubs/sp/800/
92/final.
3. Kremer R., Wudali P. N., Momiyama S., Araki T., Furukawa J., Elovici Y., Shabtai A. IC-SECURE: Intelligent
System for Assisting Security Experts in Generating Playbooks for Automated Incident Response [Електронний ресурс].
arXiv, 2023. DOI: 10.48550/arXiv.2311.03825.
4. Bridges R. A., Rice A. E., Oesch T. S., Nichols J. A., Watson C. L., Spakes K. D., Norem S. A., Huettel M.
R., Jewell B. C., Weber B., Gannon C. M., Bizovi O. M., Hollifield S. C., Erwin S. H. Testing SOAR tools in use.
Computers & Security. 2023. Vol. 129. Article 103201. DOI: 10.1016/j.cose.2023.103201.
5. IBM. Ingesting QRadar offense alerts by creating an ingestion data source [Електронний ресурс]: IBM
Documentation. URL: https://www.ibm.com/docs/en/security-qradar/security-qradar-siem/saas?topic=suqof-ingestingqradar-offense-alerts-by-creating-ingestion-data-source.
6. IBM. QRadar SOAR Integration Guide [Електронний ресурс]: IBM Security QRadar SOAR Documentation.
URL: https://www.ibm.com/docs/en/sqsp/51.0.0?topic=platform-soar-documentation-communities.
7. Ali G., Shah S., Elaffendi M. Enhancing cybersecurity incident response: AI-driven optimization for
strengthened advanced persistent threat detection. Results in Engineering. 2025. Vol. 25. Article 104078. DOI:
10.1016/j.rineng.2025.104078.
8. Johnson C. S., Badger M. L., Waltermire D. A., Snyder J., Skorupka C. Guide to Cyber Threat Information
Sharing: NIST SP 800-150 [Електронний ресурс]. Gaithersburg: National Institute of Standards and Technology, 2016.
DOI: 10.6028/NIST.SP.800-150. URL: https://csrc.nist.gov/pubs/sp/800/150/final.