首页> 外文会议>International conference on availability, reliability and security >Fighting Botnets with Cyber-Security Analytics: Dealing with Heterogeneous Cyber-Security Information in New Generation SIEMs
【24h】

Fighting Botnets with Cyber-Security Analytics: Dealing with Heterogeneous Cyber-Security Information in New Generation SIEMs

机译:用网络安全分析战斗机滴管:在新一代SIEM中处理异质网络安全信息

获取原文

摘要

One of the cyber-threats with the highest impact nowadays, in terms of number of compromised systems and the impact they can have on the Internet at large, is commonly known as the botnet. In the ACDC (Advanced Cyber Defence Centre) project, partners from 14 European countries, including public administrations, private sector organizations and academia, are trying to achieve a sustainable victory over botnets. This paper presents how a new generation SIEM is being used in the ACDC project to leverage its scalability and enhanced analytic capabilities and produce advance cyber-intelligence from the heterogeneous and massive streams of data continuously produced in the cyber-security context, in combination with traditional security events and system logs. The paper describes a case study where this approach is being tested. In the case study, the SIEM has been adapted to cope, not only with traditional security events and system logs, but also with pre-analyzed information about cyber-threats and incidents reported by the tools of some of the ACDC partner organizations. The case study also tests the adoption of the standard XML-based format called STIX, developed by the Mitre Corporation in the USA, and its suitability as a common specification for exchanging cybersecurity information between a subset of ACDC tools, the Atos SL SIEM and the ACDC's centralized data clearing house (CCH).
机译:一个时下,在入侵系统的数量,他们可以在大都有在互联网上的影响而言,就是俗称的僵尸网络影响最大的网络威胁的。在ACDC(高级网络防御中心)项目,来自14个欧洲国家,包括公共管理部门,私营机构和学术界的合作伙伴正在努力实现在僵尸网络可持续发展的胜利。本文呈现怎样的新一代SIEM在ACDC项目中使用,以充分利用其可扩展性和增强的分析能力和生产提前CYBER-智能从网络安全方面不断产生数据的异构性和巨大的数据流,并结合传统安全事件日志和系统日志。本文介绍了一个案例研究,在这种方法正在测试中。在案例研究中,SIEM已经适应了应对,不仅与传统的安全事件日志和系统日志,也与有关的一些ACDC伙伴组织的报告工具,网络威胁和事件的预分析的信息。该案例研究还测试通过所谓STIX的基于XML的标准格式,由Mitre公司在美国开发的,其作为的ACDC工具的子集之间交换网络安全信息时,源讯SL SIEM和共同的规范适用性ACDC的集中式数据交换所(CCH)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号