首页> 外文会议>International Conference on Wireless Communications, Signal Processing and Networking >Profiling SIEM tools and correlation engines for security analytics
【24h】

Profiling SIEM tools and correlation engines for security analytics

机译:分析SIEM工具和相关引擎以进行安全性分析

获取原文

摘要

Nowadays, IT organizations generate colossal amounts of data. Handling these chunks of data itself is critical in the IT world. Hence centralizing the log management system improves security thereby enhances data protection in an organization. Such enterprises require a high profiling tool that helps in managing the information and events data to improve the level of security. Security Information and Event Management (SIEM) is a procedure for security analysis that prominence an overview of security in an organization. SIEM tools collect, analyze, normalize and correlates all files and analyze data coming from the various device and give a centralized view of logs. This paper articulates an abstraction of SIEM tools and event correlation engines, furnishing a description of their technical comparative study, focusing on most popular SIEM tools and open source rule-based correlation engines and profiles them.
机译:如今,IT组织生成大量数据。在IT领域,处理这些数据本身至关重要。因此,集中化日志管理系统可提高安全性,从而增强组织中的数据保护。这样的企业需要一个高配置文件工具,该工具可以帮助管理信息和事件数据以提高安全级别。安全信息和事件管理(SIEM)是用于安全分析的过程,可以突出组织中的安全概述。 SIEM工具收集,分析,规范化和关联所有文件,并分析来自各种设备的数据,并提供集中的日志视图。本文阐明了SIEM工具和事件相关引擎的抽象,提供了它们的技术比较研究的描述,重点介绍了最流行的SIEM工具和基于开源规则的相关引擎,并对它们进行了介绍。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号