Drift-Aware Explainable Online Learning for Real-Time SIEM Alert Prioritization in Financial Security Operations Centers

Authors

  • Srilatha Batchu
  • Manoj Kumar

Keywords:

SIEM log analysis, online learning, concept drift, explainable AI, SOC alert prioritization, cybersecurity analytics, financial security operations

Abstract

Security Information and Event Management (SIEM) platforms aggregate heterogeneous telemetry from authentication services, endpoints, firewalls, VPN gateways, cloud identity platforms, and privileged-access controls. In financial Security Operations Centers (SOCs), these streams are non-stationary: remote-access policies, cloud migrations, software updates, seasonal workloads, and adversarial behavior can alter log distributions and degrade static classifiers. This study develops and evaluates a drift-aware, explainable online-learning framework for real-time SIEM alert prioritization. A chronologically ordered six-month dataset contains 12,480,000 raw log events, 8,760,000 cleaned usable events, 124,500 alert-level records, and 2,430 analyst-validated suspicious incidents. The framework integrates online anomaly detection, concept-drift monitoring, separation of benign operational, malicious behavioral, and adversarial drift, SHAP-based explanation, and risk-based alert prioritization. The proposed model achieves precision of 0.88, recall of 0.84, F1-score of 0.86, ROC-AUC of 0.94, PR-AUC of 0.78, and a false-positive rate of 5.2%. During drift windows, performance declines by 5.7%, compared with 21.2% for static XGBoost and 22.7% for static Random Forest. The weighted F1-score for drift separation is 0.85. These findings indicate that controlled online adaptation, explanation-stability monitoring, and risk-aware ranking can improve detection robustness and analyst decision support under evolving financial-sector threat conditions.

References

A. L. Buczak and E. Guven, “A survey of data mining and machine learning methods for cyber security intrusion detection,” IEEE Communications Surveys & Tutorials, vol. 18, no. 2, pp. 1153–1176, 2016.

R. Sommer and V. Paxson, “Outside the closed world: On using machine learning for network intrusion detection,” in Proc. IEEE Symposium on Security and Privacy, pp. 305–316, 2010.

M. Ring, S. Wunderlich, D. Grüdl, D. Landes, and A. Hotho, “A survey of network-based intrusion detection data sets,” Computers & Security, vol. 86, pp. 147–167, 2019.

J. H. Abawajy, A. Kelarev, and M. Chowdhury, “Multistage approach for clustering and classification of intrusion detection data,” IEEE Transactions on Dependable and Secure Computing, vol. 11, no. 1, pp. 82–93, 2014.

K. Vinayakumar, M. Alazab, K. P. Soman, P. Poornachandran, A. Al-Nemrat, and S. Venkatraman, “Deep learning approach for intelligent intrusion detection system,” IEEE Access, vol. 7, pp. 41525–41550, 2019.

Downloads

How to Cite

Srilatha Batchu, & Manoj Kumar. (2026). Drift-Aware Explainable Online Learning for Real-Time SIEM Alert Prioritization in Financial Security Operations Centers. International Journal of Engineering Science & Humanities, 16(3), 402–419. Retrieved from https://www.ijesh.com/j/article/view/1115

Similar Articles

<< < 13 14 15 16 17 18 19 20 21 22 > >> 

You may also start an advanced similarity search for this article.