首页> 外文会议>International Early Research Career Enhancement School on Biologically Inspired Cognitive Architectures and Cybersecurity >Analysis of SIEM Systems and Their Usage in Security Operations and Security Intelligence Centers
【24h】

Analysis of SIEM Systems and Their Usage in Security Operations and Security Intelligence Centers

机译:暹粒系统分析及其在安全运营和安全智能中心的用途

获取原文

摘要

To achieve business objectives, to stay competitive and to operate legally modern organizations of all types (e.g. commercial enterprises, government agencies, not-for profit organizations), different size and sphere of activity need to match a lot of internal and external requirements. They are called compliance regulations and mean conforming to a rule, such as a specification, procedure, policy, standard, law, etc. These organizations need to ensure valuable assets, uninterrupted business operation (processes), reliable data and differentiated quality of service (QoS) to various groups of users. They need to protect their clients and employees not only inside but also outside organization itself in connection with which two new terms were introduced - teleworking or telecommuting. According to Gartner by 2020, 30% of global enterprises will have been directly compromised by an independent group of cybercriminals or cyber-activists. And in 60% of network breaches, hackers compromise the network within minutes, says Verizon in the 2015 Data Breach Investigations Report. An integrated system to manage organizations' intranet security is required as never before. The data collected and analyzed within this system should be evaluated online from a viewpoint of any information security (IS) incident to find its source, consider its type, weight its consequences, visualize its vector, associate all target systems, prioritize countermeasures and offer mitigation solutions with weighted impact relevance. The brief analysis of a concept and evolution of Security Information and Event Management (SIEM) systems and their usage in Security Operations Centers and Security Intelligence Centers for intranet's IS management are presented.
机译:为了实现业务目标,保持竞争力和经营所有类型的法律现代组织(例如,商业企业,政府机构,非营利组织),不同规模和活动领域需要匹配大量内部和外部要求。它们被称为合规规定,符合规则,如规范,程序,政策,标准,法律等。这些组织需要确保有价值的资产,不间断的业务运营(流程),可靠的数据和差异化的服务质量( QoS)到各种用户组。他们需要保护客户和员工不仅在内部,而且在组织本身也有关哪些新的术语被推出 - 远程工作或远程办公。根据2020年的Gartner的说法,30%的全球企业将由一组独立的网络犯罪分子或网络活动分子直接损害。在2015年数据违约调查报告的verizon表示,在60%的网络违规行为中,黑客在几分钟内妥协了网络。需要一个用于管理组织的Intranet安全性的集成系统,从未如前所述。在该系统内收集和分析的数据应该在线在线评估,从任何信息安全(IS)事件找到其来源,考虑其类型,重量其后果,可视化其向量,使所有目标系统相关联,优先考虑对策并提供缓解加权影响相关的解决方案。提出了对安全信息和事件管理(SIEM)系统的概念和演变的概述和演变,并介绍了Intranet的安全运营中心和安全智能中心是管理。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号