Research direction
SIEM platforms centralize security telemetry and detection, while SOAR platforms coordinate workflows and response. In practice, teams may still face data-integration complexity, noisy alerts, rigid playbooks, context switching and maintenance overhead.
Areas under review
- Log normalization and heterogeneous data sources.
- Rule dependence and detection maintenance.
- False-positive reduction and alert prioritization.
- Playbook usability and configuration requirements.
- Analyst trust, override and feedback.
- Integration of adaptive and explainable assistance.
Practical objective
The research is intended to identify improvements that can be translated into architecture decisions, prototypes and evaluation criteria.