A Framework and Prototype for A Socio-Technical Security Information and Event Management System (ST-SIEM)

被引:0
|
作者
AlSabbagh, Bilal [1 ]
Kowalski, Stewart [2 ]
机构
[1] Stockholm Univ, Dept Comp & Syst Sci, Stockholm, Sweden
[2] Norwegian Univ Sci & Technol, Norwegian Informat Secur Lab, Gjovik, Norway
关键词
SIEM; Socio-Technical SIEM; SOC; Risk Escalation;
D O I
10.1109/EISIC.2016.51
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In this short paper we present a socio-technical framework for integrating a security risk escalation maturity model into a security information and event management system. The objective of the framework is to develop the foundations for the next generation socio-technical security information and event management systems (ST-SIEMs) enabling socio-technical security operations centers (ST-SOCs). The primary benefit of the socio-technical framework is twofold: supporting organizations in overcoming the identified limitations in their security risk escalation maturity, and supporting SOCs in overcoming the limitations of their SIEMs. The risk escalation maturity level is quantified using metrics. These metrics are then used by SIEMs for cross correlating security events before they are disseminated to respective organizations. Typical SIEMs in use today calculate security events using generic risk factors not necessarily relevant for every organization. The proposed framework can enable security administrators to effectively and efficiently manage security warnings and to establish necessary countermeasures.
引用
收藏
页码:192 / 195
页数:4
相关论文
共 50 条
  • [32] Unpacking landscape pressures on socio-technical regimes: Insights on the urban waste management system
    Morone, Piergiuseppe
    Lopolito, Antonio
    Anguilano, Daniela
    Sica, Edgardo
    Tartiu, Valentina E.
    [J]. ENVIRONMENTAL INNOVATION AND SOCIETAL TRANSITIONS, 2016, 20 : 62 - 74
  • [33] Digitally transforming the organization through knowledge management: a socio-technical system (STS) perspective
    Thomas, Asha
    [J]. EUROPEAN JOURNAL OF INNOVATION MANAGEMENT, 2024, 27 (09) : 437 - 460
  • [34] A socio-technical system framework for risk-informed performance-based building regulation
    Meacham, Brian J.
    van Straalen, IJsbrand J.
    [J]. BUILDING RESEARCH AND INFORMATION, 2018, 46 (04): : 444 - 462
  • [35] XML Schema-Based Minification for Communication of Security Information and Event Management (SIEM) Systems in Cloud Environments
    Moussa, Bishoy
    Mostafa, Mahmoud
    El-Khouly, Mahmoud
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2014, 5 (09) : 74 - 82
  • [36] Socio-technical design principles for a multi-stakeholder agriculture extension information system in Ethiopia
    Atinaf, Muluneh
    Anteneh, Salehu
    Kifle, Mesfin
    [J]. INFORMATION TECHNOLOGY FOR DEVELOPMENT, 2024, 30 (03) : 493 - 521
  • [37] Multimodal Information System for a durable mobility: socio-technical networks, usage scenarios and project governance
    Draetta, Laura
    Fernandez, Valerie
    Relieu, Marc
    [J]. BUSINESS TRANSFORMATION THROUGH INNOVATION AND KNOWLEDGE MANAGEMENT: AN ACADEMIC PERSPECTIVE, VOLS 3 AND 4, 2010, : 1506 - +
  • [38] A Socio-Technical Framework for Lean Project Management Implementation towards Sustainable Value in the Digital Transformation Context
    Lima, Bianca Felizardo
    Neto, Julio Vieira
    Santos, Renan Silva
    Caiado, Rodrigo Goyannes Gusmao
    [J]. SUSTAINABILITY, 2023, 15 (03)
  • [39] Developing immunity to flight security risk: Prospective benefits from considering aviation security as a socio-technical eco-system
    McFarlane P.
    Hills M.
    [J]. Journal of Transportation Security, 2013, 6 (3) : 221 - 234
  • [40] An integrated system for information security management with the unified framework
    Yang, Tsung-Han
    Ku, Cheng-Yuan
    Liu, Man-Nung
    [J]. JOURNAL OF RISK RESEARCH, 2016, 19 (01) : 21 - 41