From Detection to Prediction: AI-powered SIEM for Proactive Threat Hunting and Risk Mitigation

Main Article Content

Srinivas Reddy Pulyala

Abstract

The evolution of cybersecurity has witnessed a transformative shift from reactive defense measures to proactive threat-hunting and risk-mitigation strategies. In response to the rapidly evolving threat landscape, the integration of Artificial Intelligence (AI) into Security Information and Event Management (SIEM) tools has emerged as a crucial solution. Historically, SIEMs primarily aggregated security data but struggled to analyze the vast, complex datasets effectively. The integration of AI, especially Machine Learning (ML) and Deep Learning (DL), revolutionized these systems. AI algorithms enable SIEMs to extract meaningful insights from massive datasets, allowing for the identification of subtle anomalies and hidden threats that may not be detected by traditional detection methods. This transition marks a fundamental shift from simple data aggregation to intelligent analysis, empowering SIEMs to move beyond detection toward
proactive threat hunting. This paper highlights the role of AI in predicting threats, leveraging historical data to forecast potential risks, and continuously learning to adapt to evolving threat landscapes. It also explores the real-world use cases of AI-powered SIEMs in proactive threat hunting and risk mitigation.

Downloads

Download data is not yet available.

Metrics

Metrics Loading ...

Article Details

How to Cite
Pulyala, S. R. (2024). From Detection to Prediction: AI-powered SIEM for Proactive Threat Hunting and Risk Mitigation. Turkish Journal of Computer and Mathematics Education (TURCOMAT), 15(1), 34–43. https://doi.org/10.61841/turcomat.v15i1.14393
Section
Research Articles

References

Vinugayathri, “Why Signature-Based Detection Struggles to Keep Up with the New Attack Landscape?”

February 2022. Available online: https://cybersecuritynews.com/signature-based-detection/

Matt H., “SIEM Market Evolution And The Future of SIEM Tools,” October 2017. Available online:

https://www.rapid7.com/blog/post/2017/10/16/siem-market-evolution-and-the-future-of-siem-tools/

Wendy W., “What is SIEM and how does it work? The past, present, and future,” May 2021. Available online:

https://securityintelligence.com/posts/what-is-siem-how-does-siem-work/

Lauren B., “Top 5 Problems with Traditional SIEM,” April 2014. Available online:

https://cybersecurity.att.com/blogs/security-essentials/top-5-problems-with-traditional-siem-infographic

Nick C., “What is a cloud SIEM?” September 2020. Available online:

https://cybersecurity.att.com/blogs/security-essentials/cloud-based-siem

Ben C., “AI in SIEM: The Benefits for Enterprises of All Sizes” September 2019. Available online:

https://solutionsreview.com/security-information-event-management/ai-in-siem-the-benefits-for-enterprises-ofall-sizes/

Muhammad M. Y., Mohib U., Habib U., Basel K., “Weaponized AI for cyber attacks,” March 2021. Available

online: https://www.sciencedirect.com/science/article/abs/pii/S2214212620308620

Marc Ph., Stoecklin Jiyong J., Dhilung K., “DeepLocker: How AI Can Power a Stealthy New Breed of

Malware.” August 2018. Available online: https://securityintelligence.com/deeplocker-how-ai-can-power-astealthy-new-breed-of-malware/

Sarker, I.H. “Machine Learning: Algorithms, Real-World Applications and Research,” January 2021. Available

online: https://link.springer.com/article/10.1007/s42979-021-00592-x#citeas

Cyber Management, “What is Predictive AI & How is It Used in Cybersecurity?” July 2022. Available online:

https://www.cm-alliance.com/cybersecurity-blog/what-is-predictive-ai-how-is-it-used-in-cybersecurity

Exabeam, “AI SIEM: How SIEM with AI/ML is Revolutionizing the SOC.” Available online:

https://www.exabeam.com/explainers/siem/ai-siem-how-siem-with-ai-ml-is-revolutionizing-thesoc/#:~:text=Improved%20Efficiency%20of%20Incident%20Response&text=This%20process%20can%20be%2

time,and%20even%20execute%20that%20response.

Md Jobair Hossain Faruk∗, Hossain Shahriar†, Maria Valero†, Farhat Lamia Barsha‡, Shahriar Sobhan¶ Md

Abdullah Khan§, Michael Whitman¶, Alfredo Cuzzocrea∥, Dan Lo§, Akond Rahman‡ and Fan Wu, “AI plays a

pivotal role in identifying and analyzing malware,” 2022. Available online: https://arxiv.org/pdf/2206.12770.pdf

Manya A. S., Ali Z., “The role of User Entity Behavior Analytics to detect network attacks in real time,”

November 2018. Available online:

https://www.researchgate.net/publication/336259455_The_role_of_User_Entity_Behavior_Analytics_to_detect_

network_attacks_in_real_time