Memorias de investigación
Ponencias en congresos:
A Scalable SIEM Correlation Engine and Its Application to the Olympic Games IT Infrastructure
Año:2013

Áreas de investigación
  • Ciencias de la computación y tecnología informática

Datos
Descripción
The security event correlation scalability has become a major concern for security analysts and IT administrators when considering complex IT infrastructures that need to handle gargantuan amounts of events or wide correlation window spans. The current correlation capabilities of Security Information and Event Management (SIEM), based on a single node in centralized servers, have proved to be insufficient to process large event streams. This paper introduces a step forward in the current state of the art to address the aforementioned problems. The proposed model takes into account the two main aspects of this ?eld: distributed correlation and query parallelization. We present a case study of a multiple-step attack on the Olympic Games IT infrastructure to illustrate the applicability of our approach.
Internacional
Si
Nombre congreso
Eighth International Conference on Availability, Reliability and Security (ARES), 2013
Tipo de participación
960
Lugar del congreso
Revisores
Si
ISBN o ISSN
978-0-7695-5008-4
DOI
10.1109/ARES.2013.82
Fecha inicio congreso
02/09/2013
Fecha fin congreso
06/09/2013
Desde la página
625
Hasta la página
629
Título de las actas
2013 International Conference on Availability, Reliability and Security

Esta actividad pertenece a memorias de investigación

Participantes

Grupos de investigación, Departamentos, Centros e Institutos de I+D+i relacionados
  • Creador: Grupo de Investigación: Laboratorio de sistemas distribuidos (LSD)