Cybersecurity Security Operations Center (SOC)Dashboard
DOI:
https://doi.org/10.62643/Abstract
Security Operations Centers must correlate alerts, vulnerabilities, asset health, and incident activity produced by many disconnected tools. This paper presents a Cybersecurity Security Operations Center Dashboard that consolidates these functions into a role-aware web platform. The documented implementation uses a React.js singlepage interface, an Nginx edge layer, a Node.js and Express.js REST API, JWT authentication, role-based access control, MongoDB persistence, and containerized cloud deployment. Operational modules cover dashboard key performance indicators, alert triage, signature and behavior-based threat detection, MITRE ATT&CK mapping, vulnerability and patch tracking, incident response, reporting, user administration, and settings. Prometheus and Grafana provide infrastructure monitoring, while the ELK Stack and CloudWatch support centralized logging and operational visibility. The architecture accepts telemetry from firewalls, intrusion detection systems, endpoint tools, cloud logs, and vulnerability scanners, normalizes the records, and exposes structured workflows from alert creation through investigation, containment, recovery, and closure. Representative dashboard and API outputs confirm the intended integration of security score summaries, severitybased alert counts, active incidents, server-health indicators, geolocated attack events, and auditable incident timelines. The result is a modular and scalable foundation for centralized security monitoring, faster analyst decision support, and compliance-oriented reporting.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.













