A Framework and Prototype for A Socio-Technical Security Information and Event Management System (ST-SIEM)

被引:0
|
作者
AlSabbagh, Bilal [1 ]
Kowalski, Stewart [2 ]
机构
[1] Stockholm Univ, Dept Comp & Syst Sci, Stockholm, Sweden
[2] Norwegian Univ Sci & Technol, Norwegian Informat Secur Lab, Gjovik, Norway
关键词
SIEM; Socio-Technical SIEM; SOC; Risk Escalation;
D O I
10.1109/EISIC.2016.51
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In this short paper we present a socio-technical framework for integrating a security risk escalation maturity model into a security information and event management system. The objective of the framework is to develop the foundations for the next generation socio-technical security information and event management systems (ST-SIEMs) enabling socio-technical security operations centers (ST-SOCs). The primary benefit of the socio-technical framework is twofold: supporting organizations in overcoming the identified limitations in their security risk escalation maturity, and supporting SOCs in overcoming the limitations of their SIEMs. The risk escalation maturity level is quantified using metrics. These metrics are then used by SIEMs for cross correlating security events before they are disseminated to respective organizations. Typical SIEMs in use today calculate security events using generic risk factors not necessarily relevant for every organization. The proposed framework can enable security administrators to effectively and efficiently manage security warnings and to establish necessary countermeasures.
引用
收藏
页码:192 / 195
页数:4
相关论文
共 50 条