首页> 外文会议>European Intelligence and Security Informatics Conference >A Framework and Prototype for A Socio-Technical Security Information and Event Management System (ST-SIEM)
【24h】

A Framework and Prototype for A Socio-Technical Security Information and Event Management System (ST-SIEM)

机译:社会技术安全信息和事件管理系统(ST-SIEM)的框架和原型

获取原文

摘要

In this short paper we present a socio-technical framework for integrating a security risk escalation maturity model into a security information and event management system. The objective of the framework is to develop the foundations for the next generation socio-technical security information and event management systems (ST-SIEMs) enabling socio-technical security operations centers (ST-SOCs). The primary benefit of the socio-technical framework is twofold: supporting organizations in overcoming the identified limitations in their security risk escalation maturity, and supporting SOCs in overcoming the limitations of their SIEMs. The risk escalation maturity level is quantified using metrics. These metrics are then used by SIEMs for cross correlating security events before they are disseminated to respective organizations. Typical SIEMs in use today calculate security events using generic risk factors not necessarily relevant for every organization. The proposed framework can enable security administrators to effectively and efficiently manage security warnings and to establish necessary countermeasures.
机译:在这篇简短的论文中,我们提出了一个社会技术框架,用于将安全风险升级成熟度模型集成到安全信息和事件管理系统中。该框架的目标是为下一代社会技术安全信息和事件管理系统(ST-SIEM)奠定基础,从而使社会技术安全运营中心(ST-SOC)成为可能。社会技术框架的主要好处是双重的:支持组织克服已确定的安全风险升级成熟度的局限性,并支持SOC克服SIEM的局限性。风险升级成熟度级别使用指标进行量化。然后,SIEM将这些度量标准用于相互关联的安全事件,然后再将其分发给各个组织。当今使用的典型SIEM使用不一定与每个组织都相关的通用风险因素来计算安全事件。所提出的框架可以使安全管理员能够有效地管理安全警告并建立必要的对策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号