DocumentCode
263942
Title
SIEM implementation for global and distributed environments
Author
Anastasov, Igor ; Davcev, Danco
Author_Institution
Fac. of Comput. Sci. & Eng. (FCSE), Univ. “Ss. Cyril & Methodius”, Skopje, Macedonia
fYear
2014
fDate
17-19 Jan. 2014
Firstpage
1
Lastpage
6
Abstract
Today´s computer networks produce a huge amount of security log data. Handling this data is impossible without using Security Information and Event Management Systems (SIEM) to centralize the log management and increase the level of information security and data protection in the organization. SIEM collect and aggregate log data from various devices and applications through software called agents or connectors, filter uninteresting data and normalize to a proprietary format, analyses through correlation using contextual information and alert administrators in case of attack. SIEM provide proactive threat detection and real-time analysis of system activity. Handling these issues will be very hard without relying on consolidated, big data-powered SIEM. However, even having the most expensive SIEM solution, the organization should not expect the product to work great out of the box. The best SIEM solution does not guarantee success. The organization should focus on building various use cases to make their SIEM solution a success. In this paper, we propose a new model and architecture for SIEM implementation that is using multiple hierarchical SIEM Managers. The model is called “Hierarchical Managers Model”. We demonstrated how this model and architecture could be created and enabled in the leading SIEM system - ArcSight ESM [7]. We also provide examples of possible use cases that we have created and tested in our testing environment. These are meant to provide a good base starting point and should not be considered comprehensive for all situations. The use cases shown in this paper are created using the security event correlation framework from Hewlett-Packard - ArcSight ESM [7].
Keywords
security of data; software agents; ArcSight ESM; SIEM; computer network; data protection; distributed environment; event management system; global environment; hierarchical managers model; log management; proactive threat detection; security event correlation; security information; security log data; Connectors; Databases; Electronic mail; Monitoring; Organizations; Security; Servers; ArcSight ESM [7]; Internet of Things; SIEM; computer security; event management; information security; log management; rules; use cases;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Applications and Information Systems (WCCAIS), 2014 World Congress on
Conference_Location
Hammamet
Print_ISBN
978-1-4799-3350-1
Type
conf
DOI
10.1109/WCCAIS.2014.6916651
Filename
6916651
Link To Document