Mitigating Alert Fatigue in Real-Time Cyber Threat Detection; A Self-Contextualizing Log Intelligence Framework
Authors: Sundas Fatima Shafique, Syeda Eeman Fatima, Aoun Muhammad, Sana Tariq
Abstract
Alert fatigue problems can have serious consequences for security. In modern cybersecurity environments, passive security log generation and increased cyber threats are the cause of massive log data. In this log flood, excessive security alerts and high false positive rates are very common. It hides real attacks. That is why there is a need for an intelligent log analysis system along with real-time threat detection, especially through a self-contextualising log intelligence framework. The proposed framework is a hybrid approach of machine learning-based Self-Contextualizing (SC) system design that cleans security logs, then collects and structures them, so logs are easily understood, which improves threat analysis and alert management. The designed framework evaluates data using standard cybersecurity metrics, which include accuracy, precision, recall, F1-score, and false positive rate. The proposed framework aims to reduce alert fatigue, improve detection accuracy for threats, and enhance cybersecurity monitoring in real-time environments. The framework integrates Zeek for network monitoring, Filebeat for log collection, Elasticsearch for data storage and indexing, and NetworkX for graph-based contextualization.
