DocumentCode
2406364
Title
Log management comprehensive architecture in Security Operation Center (SOC)
Author
Madani, Afsaneh ; Rezayi, Saed ; Gharaee, Hossein
Author_Institution
Network Security Group, Iran Telecommun. Res. Center (ITRC), Tehran, Iran
fYear
2011
fDate
19-21 Oct. 2011
Firstpage
284
Lastpage
289
Abstract
With the widespread use of information, variety of security logs have increased greatly, which due need for security log management. Organizations requirements have imposed to collect, store, and analyze tremendous volumes of log data across entire infrastructure for extended durations and at increasingly granular levels. It is the process of generating, transmitting, storing, analyzing, and disposing security log data from network to databases. Due to the wide variety of logs, storing comprises different methods. Recorded events in collection module are processed, normalized and classified. Logs are stored in storage module in order to use in forensic, reviewing, auditing and providing further necessities of correlation module. Routine log correlation analysis is beneficial for identifying security incidents, policy violations, fraudulent activities, troubleshooting and operational network problems. So log management is an important and efficient activity in network monitoring. Finding an effective log management functional architecture for network events analysis is the main goal of this paper. In this paper, we aim to suggest log management architecture with more common functions that are used by vendors. By studying logging architectures the main functions are administration of log collection, normalizing, categorization, queuing prioritizing and storing logged events/alarms by sensors. Log functions are different but the suitable architecture must justify the functions to send a normative, synchronized and prioritized log in an efficient way. The mentioned functions are gathered from SIEM products characteristics. Suggested architecture includes functions and activities in log collection server and storage server.
Keywords
security of data; SOC; correlation module; fraudulent activities; log management comprehensive architecture; operational network problems; policy violations; security incidents; security log data; security log management; security operation center; storage module; Computer architecture; Correlation; Monitoring; Security; Servers; Software; System-on-a-chip; SOC; event fiields; log management; normalizing; storage;
fLanguage
English
Publisher
ieee
Conference_Titel
Computational Aspects of Social Networks (CASoN), 2011 International Conference on
Conference_Location
Salamanca
Print_ISBN
978-1-4577-1132-9
Type
conf
DOI
10.1109/CASON.2011.6085959
Filename
6085959
Link To Document