【24h】

Adjustable Fusion to Support Cyber Security Operators

机译:可调融合以支持网络安全运营商

获取原文

摘要

Cyber security operators use Security Information and Event Management systems to process and summarize the huge amount of heterogeneous logs and alerts. However, these systems do not give to the operator a concise view of the attack status or context, a mandatory feature to understand and remediate properly a threat. Moreover, the number of alerts to analyze for a single information system is high, and thus requires to be split into several levels of responsibility distributed among several operators. This layered security monitoring implies a decision problem as well as an automation problem tackled in this paper with the support of an attack graph-based feature. An attack graph is a risk assessment model that accurately describes, in a concise way, the threats on an information system. In this article, we describe how an attack graph can be used for pattern searching and fusion algorithms, in order to add context to the alerts. We also present recommendations for designing future interactive application based on adjustable fusion and a risk assessment model, for cyber security monitoring.
机译:网络安全运营商使用安全信息和事件管理系统来处理和总结大量的异构日志和警报。然而,这些系统不会向操作员提供简明的攻击状态或上下文,是一个强制性的特征来理解和纠正威胁。此外,为单个信息系统分析的警报数量很高,因此需要分成多个运算符之间分配的几个责任。该分层安全监测暗示了一个决策问题以及在本文中解决了基于攻击图的特征的自动化问题。攻击图是一种风险评估模型,以简明的方式准确地描述信息系统的威胁。在本文中,我们描述了如何用于模式搜索和融合算法的攻击图,以便向警报添加上下文。我们还提出了基于可调融合和风险评估模型设计未来互动应用的建议,用于网络安全监控。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号