DocumentCode :
1361098
Title :
Improving the Automation of Security Information Management: A Collaborative Approach
Author :
Aguirre, Idoia ; Alonso, Sergio
Volume :
10
Issue :
1
fYear :
2012
Firstpage :
55
Lastpage :
59
Abstract :
Many preventive security measures purport to protect networks from cyber intrusions. These adopted measures can generate a large amount of information that should be stored and analyzed to enable responses to detected attacks. Security information and event managers (SIEMs) are indispensable for collecting all of a system´s security-related information in a central repository. This can then provide trend analysis and lead analysts to adopt appropriate actions. A collaborative work approach lets SIEMs of different trusted domains share alarms and their countermeasures. By sharing alarms and adopted measures in domains with similar profiles, the authors hope to enhance a global view of the security and facilitate decision making for security-domain administrators.
Keywords :
decision making; groupware; security of data; central repository; collaborative work approach; cyber intrusions; decision making; network protection; preventive security measures; security information and event managers; security information management automation; security-domain administrators; Automation; Collaboration; Computer security; Information management; Network security; Security; Servers; Traffic control; SIEM; computer-supported cooperative work; data sharing; decision support; security; security information and event managers;
fLanguage :
English
Journal_Title :
Security & Privacy, IEEE
Publisher :
ieee
ISSN :
1540-7993
Type :
jour
DOI :
10.1109/MSP.2011.153
Filename :
6060795
Link To Document :
بازگشت