VaultBox: Enhancing the Security and Effectiveness of Security Analytics

被引:0
|
作者
Trivedi, Devharsh [1 ]
Triandopoulos, Nikos [1 ]
机构
[1] Stevens Inst Technol, Hoboken, NJ 07030 USA
来源
关键词
Security analytics; Rateless encoding; Secure logging; SIEM security; LT codes; Secure coding;
D O I
10.1007/978-3-031-45933-7_24
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security tools like Firewalls, IDS, IPS, SIEM, EDR, and NDR effectively detect and block threats. However, these tools depend on the system, application, and event logs. Logs are the key ingredient for various purposes, including troubleshooting performance issues, satisfying compliance mandates, and monitoring and improving security. In addition, logs from multiple machines are collected and fed to the Security Information and Event Management (SIEM) system for further security analysis. Therefore, a SIEM system's efficiency and effectiveness depend heavily on the quality and quantity of logs provided. Unfortunately, logs are often targeted brutally and tampered with after a successful intrusion to cover the attack's traces. Thus it becomes critical to protect the confidentiality, integrity, availability, and authenticity of logs at rest or transit. This paper proposes a novel scheme to prevent logs from tampering, detect any tampering, and recuperate logs if lost or corrupt. Our scheme is forward-secure, replicated, randomized, and rate-less, aiming to help securely store and transmit logs to SIEM.
引用
收藏
页码:401 / 422
页数:22
相关论文
共 50 条
  • [1] Advanced Security Analytics
    Khatravath, Sreevidya
    Laha, Sumanta
    PROCEEDINGS OF THE 2016 2ND INTERNATIONAL CONFERENCE ON APPLIED AND THEORETICAL COMPUTING AND COMMUNICATION TECHNOLOGY (ICATCCT), 2016, : 461 - 464
  • [2] Security Analytics and Measurements
    Cybenko, George
    Landwehr, Carl E.
    IEEE SECURITY & PRIVACY, 2012, 10 (03) : 5 - 8
  • [3] Enhancing Drone Video Analytics Security Management using an AERPAW Testbed
    Morel, Alicia Esquivel
    Murry, Zack
    Kostage, Kevin
    Qu, Chengyi
    Calyam, Prasad
    IEEE INFOCOM 2024-IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS, INFOCOM WKSHPS 2024, 2024,
  • [4] Enhancing Track Safety and Asset Security of Subways by Video Data Analytics
    Scholz, Sven
    Schuette, Joerg
    INTERNATIONAL CONFERENCE ON TRANSPORTATION AND DEVELOPMENT 2022: APPLICATION OF EMERGING TECHNOLOGIES, 2022, : 14 - 22
  • [5] Security Analytics: Adapting Data Science for Security Challenges
    Verma, Rakesh
    IWSPA '18: PROCEEDINGS OF THE FOURTH ACM INTERNATIONAL WORKSHOP ON SECURITY AND PRIVACY ANALYTICS, 2018, : 40 - 41
  • [6] Security Analytics: Big Data Analytics for Cybersecurity
    Mahmood, Tariq
    Afzal, Uzma
    2013 2ND NATIONAL CONFERENCE ON INFORMATION ASSURANCE (NCIA), 2013, : 129 - 134
  • [7] Enhancing Network-edge Connectivity and Computation Security in Drone Video Analytics
    Esquivel Morel, Alicia
    Kavzak Ufuktepe, Deniz
    Ignatowicz, Robert
    Riddle, Alexander
    Qu, Chengyi
    Calyam, Prasad
    Palaniappan, Kannappan
    2020 IEEE APPLIED IMAGERY PATTERN RECOGNITION WORKSHOP (AIPR): TRUSTED COMPUTING, PRIVACY, AND SECURING MULTIMEDIA, 2020,
  • [8] Visual Analytics for Network Security
    Shurkhovetskyy, Georgiy
    Bahey, Ahmed
    Ghoniem, Mohammad
    2012 IEEE CONFERENCE ON VISUAL ANALYTICS SCIENCE AND TECHNOLOGY (VAST), 2012, : 301 - 302
  • [9] Security and Privacy in Social Analytics
    Wen, Zhen
    PROCEEDINGS OF THE 1ST INTERNATIONAL WORKSHOP ON SOCIAL INFLUENCE ANALYSIS (SOCINF 2015), 2015, 1398
  • [10] Big Data Analytics for Security
    Cardenas, Alvaro A.
    Manadhata, Pratyusa K.
    Rajan, Sreeranga P.
    IEEE SECURITY & PRIVACY, 2013, 11 (06) : 74 - 76