A framework for mastering heterogeneity in multi-layer security information and event correlation

被引:8
|
作者
Coppolino, Luigi [1 ]
D'Antonio, Salvatore [1 ]
Formicola, Valerio [1 ]
Romano, Luigi [1 ]
机构
[1] Univ Naples Parthenope, Dept Engn, Naples, Italy
关键词
Security Information and Event Management; Security Probe; Mobile payment; Data collection; Data correlation;
D O I
10.1016/j.sysarc.2015.11.010
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security Information and Event Management (SIEM) is a consolidated technology that relies on the correlation of massive amounts of security-relevant information in order to detect ongoing attacks and intrusions. This correlation process is usually fed with logs generated by network devices and equipment, thus proving to be ineffective against attacks that affect multiple domains (e.g. physical, logical) or different architectural levels (e.g. network, operating system, application) of a service infrastructure. To bridge the gap, we propose a flexible framework for event collection and correlation, namely the Generic Event Translator, which is able to process heterogeneous data and spot evidence of security issues by using complex event pattern detectors that correlate information from multiple architectural layers and domains of the monitored infrastructure. The framework has been integrated into the open-source SIEM OSSIM, and validated in two challenging case studies, namely a dam infrastructure control system and a mobile phone based payment service. (C) 2015 Elsevier B.V. All rights reserved.
引用
收藏
页码:78 / 88
页数:11
相关论文
共 50 条
  • [1] Multi-Layer Security Framework for IoT Devices
    Vochescu, Alexandru
    Culic, Ioana
    Radovici, Alexandru
    [J]. 2020 19TH ROEDUNET CONFERENCE: NETWORKING IN EDUCATION AND RESEARCH (ROEDUNET), 2020,
  • [2] Multi-Layer IoT Security Framework for Ambient Intelligence Environments
    Bica, Ion
    Chifor, Bogdan-Cosmin
    Arseni, Stefan-Ciprian
    Matei, Ioana
    [J]. SENSORS, 2019, 19 (18)
  • [3] Research of Supportive Capability and Security of Multi-layer Template with Modern Framework
    Wang Youzhen
    [J]. MECHATRONICS ENGINEERING, COMPUTING AND INFORMATION TECHNOLOGY, 2014, 556-562 : 747 - 750
  • [4] The multi-layer RSIP framework
    Luo, JN
    Shieh, SP
    [J]. NINTH IEEE INTERNATIONAL CONFERENCE ON NETWORKS, PROCEEDINGS, 2001, : 166 - 171
  • [5] The CORBA-based unified event management framework in multi-layer networks
    Hong, WK
    Hong, CS
    [J]. COMPUTER COMMUNICATIONS, 2002, 25 (03) : 254 - 264
  • [6] MULTI-LAYER NETWORK SECURITY ARCHITECTURE
    Chan, Vincent W. S.
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2020, 58 (12) : 4 - 4
  • [7] A multi-layer framework for semantic modeling
    Silva, Sergio Evangelista
    Reis, Luciana Paula
    Fernandes, June Marques
    Sester Pereira, Alana Deusilan
    [J]. JOURNAL OF DOCUMENTATION, 2020, 76 (02) : 502 - 530
  • [8] A Distributed Spatio-Temporal Event Correlation Protocol for Multi-Layer Virtual Networks
    Steinert, R.
    Gestrelius, S.
    Gillblad, D.
    [J]. 2011 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE (GLOBECOM 2011), 2011,
  • [9] A Data Driven Multi-Layer Framework of Pervasive Information Computing System for eHealthcare
    Tiwari, Vivek
    Tiwari, Basant
    [J]. INTERNATIONAL JOURNAL OF E-HEALTH AND MEDICAL COMMUNICATIONS, 2019, 10 (04) : 66 - 85
  • [10] The Multi-layer Information Bottleneck Problem
    Yang, Qianqian
    Piantanidat, Pablo
    Gunduz, Deniz
    [J]. 2017 IEEE INFORMATION THEORY WORKSHOP (ITW), 2017, : 404 - 408