A Framework and Prototype for A Socio-Technical Security Information and Event Management System (ST-SIEM)

被引:0
|
作者
AlSabbagh, Bilal [1 ]
Kowalski, Stewart [2 ]
机构
[1] Stockholm Univ, Dept Comp & Syst Sci, Stockholm, Sweden
[2] Norwegian Univ Sci & Technol, Norwegian Informat Secur Lab, Gjovik, Norway
关键词
SIEM; Socio-Technical SIEM; SOC; Risk Escalation;
D O I
10.1109/EISIC.2016.51
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In this short paper we present a socio-technical framework for integrating a security risk escalation maturity model into a security information and event management system. The objective of the framework is to develop the foundations for the next generation socio-technical security information and event management systems (ST-SIEMs) enabling socio-technical security operations centers (ST-SOCs). The primary benefit of the socio-technical framework is twofold: supporting organizations in overcoming the identified limitations in their security risk escalation maturity, and supporting SOCs in overcoming the limitations of their SIEMs. The risk escalation maturity level is quantified using metrics. These metrics are then used by SIEMs for cross correlating security events before they are disseminated to respective organizations. Typical SIEMs in use today calculate security events using generic risk factors not necessarily relevant for every organization. The proposed framework can enable security administrators to effectively and efficiently manage security warnings and to establish necessary countermeasures.
引用
收藏
页码:192 / 195
页数:4
相关论文
共 50 条
  • [1] An Information Security Management for Socio-Technical Analysis of System Security
    Huynen, Jean-Louis
    Lenzini, Gabriele
    [J]. INFORMATION SYSTEMS SECURITY AND PRIVACY, 2018, 867 : 222 - 251
  • [2] A Socio-Technical Approach to Information Security
    Mujinga, Mathias
    Eloff, Mariki M.
    Kroeze, Jan H.
    [J]. AMCIS 2017 PROCEEDINGS, 2017,
  • [3] SPEAR SIEM: A Security Information and Event Management system for the Smart Grid
    Radoglou-Grammatikis, Panagiotis
    Sarigiannidis, Panagiotis
    Iturbe, Eider
    Rios, Erkuden
    Martinez, Saturnino
    Sarigiannidis, Antonios
    Eftathopoulos, Georgios
    Spyridis, Yannis
    Sesis, Achilleas
    Vakakis, Nikolaos
    Tzovaras, Dimitrios
    Kafetzakis, Emmanouil
    Giannoulakis, Ioannis
    Tzifas, Michalis
    Giannakoulias, Alkiviadis
    Angelopoulos, Michail
    Ramos, Francisco
    [J]. COMPUTER NETWORKS, 2021, 193
  • [4] Challenges and Directions in Security Information and Event Management (SIEM)
    Cinque, Marcello
    Cotroneo, Domenico
    Pecchia, Antonio
    [J]. 2018 29TH IEEE INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING WORKSHOPS (ISSREW), 2018, : 95 - 99
  • [5] Modelling the Enemies of an IT Security System - A Socio-Technical System Security Model
    Kowalski, Stewart
    Mwakalinga, Jeffy
    [J]. IMCIC'11: THE 2ND INTERNATIONAL MULTI-CONFERENCE ON COMPLEXITY, INFORMATICS AND CYBERNETICS, VOL I, 2011, : 251 - 256
  • [6] Socio-Technical System Design Framework for People with Disability
    Liu, Peng
    Lu, Tun
    Gu, Ning
    [J]. COMPUTER SUPPORTED COOPERATIVE WORK AND SOCIAL COMPUTING, CHINESECSCW 2018, 2019, 917 : 272 - 284
  • [7] Towards a political framework for socio-technical system design
    Koehler, Andrew
    Taylor, Karen
    [J]. 2007 IEEE INTERNATIONAL SYMPOSIUM ON TECHNOLOGY AND SOCIETY, 2007, : 132 - +
  • [8] A socio-technical framework for quality assessment of computer information systems
    Palvia, Shailendra C.
    Sharma, Ravi S.
    Conrath, David W.
    [J]. Industrial Management and Data Systems, 2001, 101 (5-6): : 237 - 251
  • [9] A socio-technical framework for quality assessment of computer information systems
    Palvia, SC
    Sharma, RS
    Conrath, DW
    [J]. INDUSTRIAL MANAGEMENT & DATA SYSTEMS, 2001, 101 (5-6) : 237 - 251
  • [10] From Situation Awareness to Action: An Information Security Management Toolkit for Socio-technical Security Retrospective and Prospective Analysis
    Huynen, Jean-Louis
    Lenzini, Gabriele
    [J]. ICISSP: PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2017, : 213 - 224