Idea
Graph-based alert contextualisation platform for SOCs to prioritize threats and enhance incident analysis with machine learning insights
Research Paper
Core Innovation
This paper introduces a graph-based alert grouping method that aggregates alerts into connected structures within time windows, capturing attack steps more effectively than isolated alerts. It applies Graph Matching Networks to link incoming alert groups with past incidents, providing richer context for analysts. This approach improves alert prioritisation and supports downstream machine learning applications.
Market Size (TAM)
$2–10B TAM for cybersecurity alert management platforms; $1–2B SAM from enterprise SOCs and managed security service providers. Driven by increasing cyber threats and demand for automated alert triage.
Potential Customers & Pain Points
- Security Operations Centres needing efficient alert triage
- Cybersecurity teams overwhelmed by alert volume
- Incident responders requiring contextual threat insights
Business Model
Subscription-based SaaS platform targeting SOCs and MSSPs with tiered pricing based on alert volume and features
Competitive Landscape
- Splunk
- IBM QRadar
- CrowdStrike
Implementation Challenges
- Integration with diverse alert sources
- Scalability to large alert volumes
- Analyst adoption and trust in automated grouping
Validation Strategy
- Pilot deployment with enterprise SOC for real alert data
- Evaluate alert grouping accuracy and analyst feedback
- Benchmark against existing alert triage tools
Research Paper Overview
A Graph-Based Approach to Alert Contextualisation in Security Operations Centres
Summary
This paper proposes a graph-based method to improve alert contextualisation in Security Operations Centres by grouping related alerts into graph structures within time windows. Nodes represent alerts and edges denote relationships, enabling higher-level analysis of attack steps. The approach uses Graph Matching Networks to correlate new alert groups with historical incidents, aiding analysts with deeper insights.