首页> 外文会议>International Conference on Applied Computing and Information Technology >A Study on the Methods for Establishing Security Information Event Management
【24h】

A Study on the Methods for Establishing Security Information Event Management

机译:建立安全信息和事件管理的方法研究

获取原文

摘要

There has recently been emerging a global threat caused by the attack through multi-hacking technologies against the national infrastructure, industrial control system and enterprises, what's called cyber-hacking and cyber-attack on the cyber space like cyber war, for the sake of the nation and organization. Besides, APT (Advanced Persistent Threat) attack utilizing complex types of attack in order to attack a certain target brings about a tremendous chaos on a national and social level. Under such a situation, a necessity for ESM (Enterprise Security Management) is emphasized to establish multi-network enterprise security systems for a defense against an attack from outside and an efficient management. However, ESM analyzed and collected data, with the main focus on information security system-based security event and network sensor-based harmful traffic event without carrying out a function to analyze a general system and application log-based event. As far as an effective security detection is concerned, strategies for a systemic preparation and execution to actively solve the security issue are necessary by utilizing enormous big data occurring throughout the enterprise IT infrastructure sectors. In this regard, this study is to present a security log analysis system utilizing SIEM (Security Information & Event Management) system to cope with an advanced attack that the existing ESM can hardly detect. SIEM is going to analyze an association between data and security event occurring in major IT infrastructure facility network, system, applied services and a great deal of information security systems, and then to present the methods for identifying, in advance, potential security threat.
机译:最近,通过对国家基础设施,工业控制系统和企业的多黑客技术,攻击攻击造成的全球威胁,为网络战争等网络空间所谓的网络 - 黑客和网络攻击国家和组织。此外,APT(高级持续威胁)攻击利用复杂类型的攻击,以攻击某个目标在国家和社会层面带来巨大的混乱。在这种情况下,强调了ESM(企业安全管理)的必要性,以建立多网络企业安全系统,以防范外部的攻击和有效的管理。但是,ESM分析和收集数据,主要关注信息安全系统的安全事件和基于网络传感器的有害流量事件,而无需分析基于常规系统和应用程序日志的事件。就有效的安全检测而言,通过利用整个企业IT基础架构部门发生巨大的大数据来实现系统性准备和执行以积极解决安全问题的策略。在这方面,本研究是呈现利用SIEM(安全信息和事件管理)系统的安全日志分析系统,以应对现有ESM无法检测到的高级攻击。暹粒将分析主要IT基础架构设施网络,系统,应用服务和大量信息安全系统中的数据和安全事件之间的关联,然后提前提前识别潜在安全威胁的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号