DefinePK

DefinePK hosts the largest index of Pakistani journals, research articles, news headlines, and videos. It also offers chapter-level book search.

Advancing Security Operations Centers: Modern Use Cases, MITRE ATT&CK Integration, and Coverage Optimization in 2025


Article Information

Title: Advancing Security Operations Centers: Modern Use Cases, MITRE ATT&CK Integration, and Coverage Optimization in 2025

Authors: Salman Ghani Virk, Jawaid Iqbal, Atif Ali, Ali Rashid Mahmud, Imran Rashid, Tariq Hanif

Journal: Journal of Computing & Biomedical Informatics

HEC Recognition History
Category From To
Y 2023-07-01 2024-09-30
Y 2022-07-01 2023-06-30

Publisher: Research Center of Computing & Biomedical Informatics

Country: Pakistan

Year: 2025

Volume: 9

Issue: 02

Language: en

Keywords: Security Operations Center (SOC)MITRE ATT&CKDetection CoverageAI-driven SOCAdversary EmulationCybersecurity ResilienceHybrid SOC Model

Categories

Abstract

The frequency of cybersecurity threats has risen considerably over the years. Furthermore, these attacks have become increasingly complex and costly. The total damage worldwide is estimated to go beyond USD 10.5 trillion per year by 2025 (Cybersecurity Ventures, 2025). Such an increasingly threatening environment requires organizations to take stronger security measures as a matter of great importance. SOCs are instrumental in organizations' security plans, as they provide ongoing checks of IT environments, facilitate the quick identification of breaches, and coordinate incident mitigation measures to prevent potential harm. This research paper employs the design science method to develop an image of detection coverage mapping and a visualization interface that helps correlate enterprise event logs with the MITRE ATT&CK tactics and techniques for identification. The study has been updated with various industry datasets, including IBM's 2025 Cost of Data Breach Report, Verizon's DBIR 2025, and ENISA's Threat Landscape 2024, which serve as the basis for the assessment. The study indicates that the implementation of AI-supported SOCs can significantly reduce the mean-time-to-detect (MTTD) by almost 40%, resulting in a notable performance increase for the threat detection system. Our research suggests that the first/primary way of managing SOCs (Security Operations) concerns by human analysts trained comprehensively and assisted by intelligent automation is the most acceptable. Additionally, the incessant adaptation of the MITRE ATT&CK framework as a benchmark and the launch of the targeted budget planning to advance detection and security quality were among the key points raised.


Paper summary is not available for this article yet.

Loading PDF...

Loading Statistics...