A Hierarchical Architectural Model for Network Security Exploring Situational Awareness

被引:0
|
作者
Almeida, Ricardo Borges [1 ]
Covalski, Victor [1 ]
Machado, Roger [1 ]
Leal da Rosa, Diorgenes Yuri [1 ]
Yamin, Adenauer Correa [1 ]
Donato, Lucas Medeiros [2 ]
Pernas, Ana Marilza [1 ]
机构
[1] Univ Fed Pelotas, Pelotas, Brazil
[2] De Montfort Univ, Leicester, Leics, England
关键词
Network Security; Situational Awareness; Architectural Model;
D O I
10.1145/3297280.3297417
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Often network security technologies used by organizations for securing their computational systems are deficient in providing holistic view of the environment. Based on this, our paper presents an architectural model based on a Situational Awareness approach for securing computational systems in distributed environments. The architecture is called EXEHDA-ISSA and is inspired by SIEM systems. It is composed of three modular software components called Collector, SmartLogger, and Manager. These components are interconnected following a multi-level hierarchical model and provide features such as event collection, hybrid event processing and a hybrid approach to contextual data storage. For the purpose of evaluating this proposal, four case studies were developed to validate the holistic view of security events as well as the model's characteristics such as flexibility, autonomy, scalability and the support to heterogeneity. Finally, the strengths and limitations of our approach are discussed, then followed by future works.
引用
收藏
页码:1365 / 1372
页数:8
相关论文
共 50 条
  • [1] Network security situational awareness model based on threat intelligence
    Zhang, Hongbin
    Yin, Yan
    Zhao, Dongmei
    Liu, Bin
    [J]. Tongxin Xuebao/Journal on Communications, 2021, 42 (06): : 182 - 194
  • [2] Survey of Network Security Situational Awareness
    Yao, Jiayu
    Fan, Xiani
    Cao, Ning
    [J]. CYBERSPACE SAFETY AND SECURITY, PT I, 2020, 11982 : 34 - 44
  • [3] A Network Security Situational Awareness Model Based on Information Fusion
    Abasi
    [J]. ADVANCES IN MECHATRONICS, AUTOMATION AND APPLIED INFORMATION TECHNOLOGIES, PTS 1 AND 2, 2014, 846-847 : 1632 - 1635
  • [4] Situational Awareness Technology in Network Security
    Ye, Zheng-wang
    [J]. 2014 2ND INTERNATIONAL CONFERENCE ON SOCIAL SCIENCE AND HEALTH (ICSSH 2014), PT 4, 2014, 58 : 247 - 251
  • [5] An Extraction Method Of Situational Factors For Network Security Situational Awareness
    Wang, Huiqiang
    Liang, Ying
    Ye, Haizhi
    [J]. ICICSE: 2008 INTERNATIONAL CONFERENCE ON INTERNET COMPUTING IN SCIENCE AND ENGINEERING, PROCEEDINGS, 2008, : 317 - 320
  • [6] Application Analysis of Network Security Situational Awareness Model for Asset Information Protection
    Ren, Yuemei
    Feng, Xianju
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (05) : 790 - 799
  • [7] Exploration of a network security situational awareness model based on multisource data fusion
    Li, Xingguo
    Zhong, Yu
    [J]. NEURAL COMPUTING & APPLICATIONS, 2023, 35 (36): : 25083 - 25095
  • [8] Exploration of a network security situational awareness model based on multisource data fusion
    Xingguo Li
    Yu Zhong
    [J]. Neural Computing and Applications, 2023, 35 : 25083 - 25095
  • [9] Functional Requirements of Situational Awareness in Computer Network Security
    Onwubiko, Cyril
    [J]. ISI: 2009 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS, 2009, : 209 - 213
  • [10] A Study of Network Security Situational Awareness in Internet of Things
    Li, Jingyi
    Yi, Xiaoyin
    Wei, Shi
    [J]. 2020 16TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE, IWCMC, 2020, : 1624 - 1629