• DocumentCode
    1700951
  • Title

    SIEM with LSA technique for Threat identification

  • Author

    Dairinram, Pavarit ; Wongsawang, Damras ; Pengsart, Pagaporn

  • Author_Institution
    Fac. of Inf. & Commun. Technol., Mahidol Univ., Bangkok, Thailand
  • fYear
    2013
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Security in the heterogeneous and complex network is very challenged for administrators. They need to handle with a lot of devices, and perform the task of protection and prevention plan for securing the network from the threats. The Security Information and Event Management (SIEM) is one of the most common tools that helps administrators to deal with current situation. It helps to manage and identify the threats. Moreover, it will initiate a proper an action to protect the network against the right threats and also generate a report for the administrators. However, the amount of threats is increasing rapidly, and the variation of threats is also another issue for identifying. The Latent Semantic Analysis (LSA) was proposed in this paper to help alleviate these problems. It would improve the performance by reducing the unnecessary noise in a huge data generated from devices. It is also used to detect a similar threat pattern relying on similarity between threats and events/logs. The experiments showed that LSA approach can help eliminating not significant data used in the threat identifying process without degradation of the accuracy.
  • Keywords
    security of data; statistical analysis; LSA technique; SIEM; heterogeneous complex network; latent semantic analysis; prevention plan; protection plan; security information and event management; threat identification; treat management; Artificial intelligence; Equations; IP networks; Mathematical model; Security; Semantics; Vectors; Latent Semantic Ankysis; Network Security; Security Information and Event Management; Threat identification;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Networks (ICON), 2013 19th IEEE International Conference on
  • Conference_Location
    Singapore
  • Print_ISBN
    978-1-4799-2083-9
  • Type

    conf

  • DOI
    10.1109/ICON.2013.6781951
  • Filename
    6781951