The Operational Role of Security Information and Event Management Systems

被引:86
|
作者
Bhatt, Sandeep [1 ]
Manadhata, Pratyusa K. [1 ]
Zomlot, Loai [1 ]
机构
[1] Hewlett Packard Labs, Palo Alto, CA 94304 USA
关键词
INTRUSION DETECTION; ALERT CORRELATION;
D O I
10.1109/MSP.2014.103
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
An integral part of enterprise computer security incident response teams, a security operations center (SOC) monitors security incidents in real time. Security incident and event management systems play a critical role in SOCs-collecting, normalizing, storing, and correlating events to identify malicious activities-but face operational challenges.
引用
收藏
页码:35 / 41
页数:7
相关论文
共 50 条