Аuthors
*, **, ***Moscow Polytechnic University, 38, Bolshaya Semenovskaya str., Moscow, 107023, Russia
*e-mail: pavel.piksel2012@mail.ru
**e-mail: aspev@yandex.ru
***e-mail: sspev@yandex.ru
Abstract
This article examines methods for developing new detection rules within an evolving Security Operations Center (SOC) to accelerate the response to security incidents in the infrastructure of an aviation industry enterprise. The scientific novelty of the work lies in the application of a novel method for converting detection rules from the Sigma format into a format supported by the OpenSearch Alerting plugin. The practical significance is the ability to maintain a unified detection rule format, which facilitates the rapid updating of the SOC with modern detection practices. A study of the OpenSearch Alerting plugin, which is responsible for supporting detection rules, was conducted. An analysis of the plugin's entity structure revealed extensive functionality but also a high barrier to entry for initial development. The key component of SOCs incident detection rules and their continuous development process was identified. Consequently, a table of potential data sources for developing new rules was compiled. A comparative analysis established the most effective data source: open repositories with rules in the Sigma format. Using a sample Sigma rule that included complex functional elements, a correspondence between the entities in the structure of the two rule formats—OpenSearch Alerting and Sigma—was established. Based on this established correspondence, a universal Jinja2 template was developed for the seamless conversion of Sigma rules into OpenSearch Alerting rules.
Keywords:
cybersecurity; software development life cycle; monitoring of secure development; SIEM systems; incident detection; event correlation, Opensearch detection rulesReferences
- Lesik E. S., Padalko S. N., Stankevich A. M. Cifrovaya model' organizacii: opredelenie, postroenie, ispol'zovanie. //Trudy MAI. – 2025. – №. 141.
- Kasatikov N. N., Brekhov O. M., Nikolaeva E. O. Integraciya tekhnologij iskusstvennogo intellekta i interneta veshchej dlya rasshirennogo monitoringa i optimizacii energeticheskih ob"ektov v umnyh gorodah //Trudy MAI. – 2023. – №. 131.
- SHablij A. D. Optimizaciya sostava komplektacij programmnogo obespecheniya. //Trudy MAI. – 2025. – №. 143.
- Sin' M. I dr. Razrabotka sistemy monitoringa silovyh agregatov bespilotnyh letatel'nyh apparatov v rezhime real'nogo vremeni. //Trudy MAI. – 2024. – №. 137.
- Smirnov D. V., Evsyutin O. O. Metodika sbora dannyh ob aktivnosti vredonosnogo programmnogo obespecheniya pod OS Windows na baze MITRE ATT&CK //Informatika i avtomatizaciya. – 2024. – T. 23. – №. 3. – S. 642-683.
- Gerchin I. A., Anackaya A. G. Cifrovizaciya i kiberbezopasnost': sovremennaya teoriya i praktika. – Sibirskij gosudarstvennyj avtomobil'no-dorozhnyj universitet (SibADI) Konferenciya: Cifrovizaciya i kiberbezopasnost': sovremennaya teoriya i praktika Omsk, 30–31 oktyabrya 2024 goda Organizatory: Sibirskij gosudarstvennyj avtomobil'no-dorozhnyj universitet (SibADI).
- Kosmacheva I. M. i dr. Sistema sobytijnogo monitoringa dlya avtomatizirovannogo obnaruzheniya incidentov //Vestnik Astrahanskogo gosudarstvennogo tekhnicheskogo universiteta. Seriya: Upravlenie, vychislitel'naya tekhnika i informatika. – 2023. – №. 3. – S. 76-86.
- Saulaiman M. N. E. et al. Cloud-Based Cybersecurity and Data Management System for Near Real-Time Monitoring and Alerting in Vehicle-SOC-a Proof of Concept //2025 IEEE 23rd World Symposium on Applied Machine Intelligence and Informatics (SAMI). – IEEE, 2025. – S. 000165-000170.
- Dolgachev M. V., Kostyunin V. A. Kompleksnyj analiz povedeniya sistemy windows dlya obnaruzheniya kiberugroz //Voprosy kiberbezopasnosti. – 2025. – №. 2 (66). – S. 71-77.
- Tolganbaev T. K. Domennye sluzhby active directory i yadro servera //Vestnik magistratury. – 2014. – №. 6-1 (33). – S. 27-29.
- Zefirov S. L., SHCHerbakova A. YU. Ocenka incidentov informacionnoj bezopasnosti //Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki. – 2014. – №. 2 (32). – S. 77-81.
- Onsamlee W. et al. The Cyber Threat Detection and Alert System Using MISP Threat Sharing Database.
Download

