首页> 外文会议>IEEE International Conference on Networks >SIEM with LSA technique for Threat identification
【24h】

SIEM with LSA technique for Threat identification

机译:SIEM具有LSA技术的威胁​​识别

获取原文
获取外文期刊封面目录资料

摘要

Security in the heterogeneous and complex network is very challenged for administrators. They need to handle with a lot of devices, and perform the task of protection and prevention plan for securing the network from the threats. The Security Information and Event Management (SIEM) is one of the most common tools that helps administrators to deal with current situation. It helps to manage and identify the threats. Moreover, it will initiate a proper an action to protect the network against the right threats and also generate a report for the administrators. However, the amount of threats is increasing rapidly, and the variation of threats is also another issue for identifying. The Latent Semantic Analysis (LSA) was proposed in this paper to help alleviate these problems. It would improve the performance by reducing the unnecessary noise in a huge data generated from devices. It is also used to detect a similar threat pattern relying on similarity between threats and events/logs. The experiments showed that LSA approach can help eliminating not significant data used in the threat identifying process without degradation of the accuracy.
机译:异构和复杂网络中的安全性对于管理员来说非常挑战。他们需要处理很多设备,并执行保护和预防计划的任务,以保护网络从威胁中保护网络。安全信息和事件管理(SIEM)是最常见的工具之一,帮助管理员处理当前情况。它有助于管理和识别威胁。此外,它将启动适当的动作来保护网络免受正确的威胁,并且还为管理员提供报告。但是,威胁的数量正在迅速增加,威胁的变异也是识别的另一个问题。本文提出了潜在语义分析(LSA),以帮助减轻这些问题。它将通过减少从设备生成的巨大数据中的不必要的噪声来提高性能。它还用于检测依赖于威胁和事件/日志之间相似性的类似威胁模式。实验表明,LSA方法可以帮助消除威胁识别过程中使用的不显着数据,而不会降低准确性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号