DocumentCode :
2361083
Title :
A Study of ESMTC(Enterprise Security Management System Based on Threshold Classification)
Author :
Choi, Kyong-Ho ; Park, Won Hyung ; Kim, Kuinam J.
Author_Institution :
Center for Ind. Security, Kyonggi Univ., Suwon, South Korea
fYear :
2012
fDate :
23-25 May 2012
Firstpage :
1
Lastpage :
6
Abstract :
Most of organizations operate an Enterprise Security Management system (ESM) for managing and analyzing security events. However, it is difficult to instantly analyze and respond for each event by a security manager because the amount of security events collected, stored, analyzed, and displayed by the Enterprise Security Management system is significantly increased according to time and expansions in systems and networks. In addition, as the trends of threats have been changed as a type of Advanced Persistent Threat (APT) that attacks specific individuals and organizations for a long term period, an integrated analysis is required for all security events. Thus, in this study, an Enterprise Security Management system based on Threshold Classification (ESMTC) is proposed to detect and intercept cyber threats occurred for a long term period. It shows an advantage that it does not failure to notice even a single attack through structuralizing and listing detailed attack detection packets and performs related analyses to other attacks.
Keywords :
business data processing; corporate modelling; security of data; APT; ESMTC; advanced persistent threat; cyber threats; detection packets; enterprise security management system based on threshold classification; security events; Computer crime; Educational institutions; Industries; Monitoring; Operating systems; Organizations;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Science and Applications (ICISA), 2012 International Conference on
Conference_Location :
Suwon
Print_ISBN :
978-1-4673-1402-2
Type :
conf
DOI :
10.1109/ICISA.2012.6220971
Filename :
6220971
Link To Document :
بازگشت