Author
Abstract
Security Information and Event Management (SIEM) platforms have undergone fundamental architectural transformation over three generations - from passive log aggregation and signature-based correlation to cloud-native, streaming analytics engines augmented with User and Entity Behavior Analytics (UEBA) and AI-driven threat scoring. Despite the emergence of Extended Detection and Response (XDR) and Security Orchestration, Automation and Response (SOAR) paradigms, SIEM retains indispensable centrality within enterprise Security Operations Centers (SOCs) as the normative substrate for compliance reporting, cross-domain event correlation, and forensic investigation. However, empirical data characterizing the detection performance, operational cost, and latency trade-offs of competing SIEM architectures across deployment models - on-premises, cloud-native, and hybrid - remains sparse in peer-reviewed literature. This paper formalizes a five-layer SIEM reference architecture, derives a twelve-dimensional capability taxonomy, and presents a controlled empirical evaluation of four production SIEM platforms (IBM QRadar, Splunk Enterprise Security, Microsoft Sentinel, and Elastic SIEM) across 48 SOC use cases. Results demonstrate that cloud-native SIEM achieves a 63.4% reduction in mean time-to-detect (MTTD) over on-premises deployments, while hybrid architectures reduce ingestion cost by 41.2% relative to full cloud deployments. UEBA integration reduces false positive rates by 57.3% across account compromise scenarios. These findings provide practitioners with evidence-based guidance for SIEM selection, architecture, and maturity planning.
Suggested Citation
Lakshmi Kiran Meesala, 2023.
"Modern Security Information and Event Management: Architecture, Analytics Pipelines, and Empirical Evaluation of SOC-Scale Threat Detection,"
International Journal of Scientific Research in Computer Science, Engineering and Information Technology, International Journal of Scientific Research in Computer Science, Engineering and Information Technology, vol. 9(4), pages 995-1012, July.
Handle:
RePEc:jbh:ijsrcs:v9:y2023:i4:id:hcseit23564538
DOI: 10.32628/CSEIT23564538
Note: Article URL: https://ijsrcseit.com/CSEIT23564538
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:jbh:ijsrcs:v9:y2023:i4:id:hcseit23564538. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Pankaj Sharma (USA) (email available below). General contact details of provider: https://ijsrcseit.com/home .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.