首页> 外文期刊>Cluster computing >A high-level domain-specific language for SIEM (design, development and formal verification)
【24h】

A high-level domain-specific language for SIEM (design, development and formal verification)

机译:暹粒的高级域名语言(设计,开发和正式验证)

获取原文
获取原文并翻译 | 示例
       

摘要

Organizations deploy security information and event management (SIEM) systems for centralized management of security events. The real-time security monitoring capability of the SIEM depends on the correlation process where events data are matched against the security rules. Most SIEM systems use general purpose languages to define security rules. Creating new rules in general purpose languages require excellent programming skills in the proprietary language and intimate knowledge of events. This paper introduces a high-level domain-specific language (HDSL) which simplifies rule creation for the SIEM system. We formally specify the HDSL with extended Backus-Naur form grammar in another tool for language recognition according to the model driven engineering approach. In our implementation framework, the rules defined in the HDSL are converted in the standard event processing language. For evaluation purpose, the converted security rules are tested on the service real-time data security analytics. The results indicate that the rules are converted accurately and generate alarms when specific attacks are detected. For checking correctness of the HDSL, formal verification is carried out using satisfiability modulo theory and Z3 solver. The results are evaluated under diverse attack scenarios, which reveal that HDSL is functioning correctly. The HDSL enhances the SIEM correlation capabilities by providing a tranquil approach for writing the correlation rules.
机译:组织部署用于集中管理安全事件的安全信息和事件管理(SIEM)系统。 Siem的实时安全监控能力取决于事件数据与安全规则匹配的相关过程。大多数SIEM系统使用通用语言来定义安全规则。以通用语言创建新规则需要专有语言的优异编程技巧和对事件的亲密知识。本文介绍了一种高级域特定语言(HDSL),简化了SIEM系统的规则创建。根据模型驱动的工程方法,我们正式指定具有扩展背部的HDSL与延长的背部核心形式语法。在我们的实现框架中,HDSL中定义的规则在标准事件处理语言中转换。对于评估目的,转换后的安全规则在服务实时数据安全分析上进行测试。结果表明,当检测到特定攻击时,准确地转换规则并生成警报。为了检查HDSL的正确性,使用可满足模数和Z3求解器进行正式验证。结果在不同的攻击情景下进行评估,揭示了HDSL正常运行。 HDSL通过提供宁静的方法来增强Siem相关性能,用于编写相关规则。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号