Events correlation in the SIEM-systems based on unmonotonous output
DOI:
https://doi.org/10.18372/2410-7840.19.11438Keywords:
The SIEM-system, correlation, signatura, products, unmonotonous conclusion, rules of silencesAbstract
Going near creation of cross-correlation mechanisms is considered in the SIEM-systems. As logical basis of such mechanisms the use non-monotonic rules of silences is offered in combination with the conclusion of resolution type. This approach extends possibilities of classic cross-correlation mechanisms of the SIEM-systems due to possibility of the simultaneous use of both rules of products and rules of silences which allow to describe typical situations. It enables to process exceptions without their preliminary authentication and create more flexible mechanisms of correlation.References
Hanemann, A., Marcu, P. Algorithm design and application of service-oriented event correlation. [Электронный ресурс] URL: http://www.re-searchgate.net/publication/221033552_Algrithm_design_and_application_of_service-oriented_event_correlation (дата обращения 25.05.2014).
Muller, A. Event Correlation Engine. [Электронный ресурс] URL: ftp://ftp.tik.ee.ethz.ch/pub/stu-dents/2009-FS/MA-2009-01.pdf (дата обращения 25.05.2014).
Шелестова, О. Корреляция SIEM – это просто. Сигнатурные методы. [Электронный ресурс] URL: http://www.securitylab.ru/analytics/431459.php (дата обращения 30.03.2014).
Олеся Шелестова. Корреляция SIEM. Сигна-турные методы //исследовательский центр Positive Research [Электронный ресурс] 2012. URL: http://www.securitylab.ru/analytics/431459.php.
Борисов В. И., Шабуров А. С. О Применении сигнатурных методов анализа информации в SIEM-системах/ Безопасность в информационной сфере № 3(17) / 2015 C. 23-27.
Федорченко А.В., Левшун Д.С., Чечулин А.А., Котенко И.В. Анализ методов корреляции событий безопасности в SIEM-системах. Часть 1. // Труды СПИИРАН. 2016. Вып. 47. C. 5-27.
Стандарт ISO/IEC TR 18044:2004 "Information technology - Security techniques - Information secu-rity incident management".
Тей А., Грибомон П., Луи Ж., Лог Ж. Логический подход к искусственному интеллекту. - М.: Мир, 1990. - 429 с.
Самохвалов Ю.Я. Метод проблемно-ориентированного доказательства в нечеткой логике // Кибернетика и системный анализ. - 1995. - № 5. - С. 58-68.
Downloads
Published
How to Cite
Issue
Section
License
The scientific journal adheres to the principles of Open Access and provides free, immediate, and permanent access to all published materials without financial, technical, or legal barriers for readers.
All articles are published in Open Access under the Creative Commons Attribution 4.0 International (CC BY 4.0) license.
Copyright
Authors who publish their works in the journal:
-
retain the copyright to their publications;
-
grant the journal the right of first publication of the article;
-
agree to the distribution of their materials under the CC BY 4.0 license;
-
have the right to reuse, archive, and distribute their works (including in institutional and subject repositories), provided that proper reference is made to the original publication in the journal.




