Abstract:
Security Information and Event Management (SIEM) is the state-of-the-practice in handling heterogeneous data sources for security analysis. This paper presents challenges...Show MoreMetadata
Abstract:
Security Information and Event Management (SIEM) is the state-of-the-practice in handling heterogeneous data sources for security analysis. This paper presents challenges and directions in SIEM in the context of a real-life mission critical system by a top leading company in the Air Traffic Control domain. The system emits massive volumes of highly-unstructured text logs. We present the challenges in addressing such logs, ongoing work on the integration of an open source SIEM, and directions in modeling system behavioral baselines for inferring compromise indicators. Our explorative analysis paves the way for data discovery approaches aiming to complement the current SIEM practice.
Published in: 2018 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW)
Date of Conference: 15-18 October 2018
Date Added to IEEE Xplore: 18 November 2018
ISBN Information: