Skip to main content

2019 | OriginalPaper | Buchkapitel

A Novel and Comprehensive Evaluation Methodology for SIEM

verfasst von : Mahdieh Safarzadeh, Hossein Gharaee, Amir Hossein Panahi

Erschienen in: Information Security Practice and Experience

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Many SIEM products have been produced. However, there is no comprehensive methodology to evaluate them. We present a novel and comprehensive three-dimensional methodology to evaluate SIEM products. We consider a SIEM product as a set of dimensions, namely capability, architectural component, and common feature, then subdivide each dimension-according to its definition-into sub-dimensions. Afterward, we develop multiple criteria for evaluating each sub-dimension. The dimensions can have a different impact and importance on SIEM product, to determine the magnitude of the impact and importance of each dimension we use a factor called the impact factor. We also consider some impact factors for the impact and importance of each sub-dimension and each criterion. Since there are different methods, algorithms, and standards for developing the criteria, so we provide maturity levels for each criterion. The results of the evaluations show that this methodology can evaluate the criteria coverage, completeness and correctness of criteria, and determine the superiority of criteria in the SIEM products as well.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
4.
Zurück zum Zitat Mark, N., Kelly, M.K.: Critical Capabilities for Security Information and Event, May 2013. Accessed 7 June 2019 Mark, N., Kelly, M.K.: Critical Capabilities for Security Information and Event, May 2013. Accessed 7 June 2019
7.
Zurück zum Zitat Igor, k., Elena, D.: Countermeasure selection in SIEM systems based on the integrated complex of security metrics. In: 23rd Euromicro International Conference on Parallel, Distributed, and Network-Based Processing, pp. 567–574. IEEE, Turku(2015) Igor, k., Elena, D.: Countermeasure selection in SIEM systems based on the integrated complex of security metrics. In: 23rd Euromicro International Conference on Parallel, Distributed, and Network-Based Processing, pp. 567–574. IEEE, Turku(2015)
8.
Zurück zum Zitat Kavita, A., Hemant, M.: A study on critical capabilities for security information and event management. Int. J. Sci. Res. (IJSR) 4(7), 1893–1896 (2015) Kavita, A., Hemant, M.: A study on critical capabilities for security information and event management. Int. J. Sci. Res. (IJSR) 4(7), 1893–1896 (2015)
9.
Zurück zum Zitat Leszczyna, R., Wróbel, M.R.: Evaluation of open source SIEM for situation awareness platform in the smart grid environment. In: World Conference on Factory Communication Systems (WFCS), pp. 1–4. IEEE, Palma de Mallorca (2015) Leszczyna, R., Wróbel, M.R.: Evaluation of open source SIEM for situation awareness platform in the smart grid environment. In: World Conference on Factory Communication Systems (WFCS), pp. 1–4. IEEE, Palma de Mallorca (2015)
10.
Zurück zum Zitat Sandeep, B., Pratyusa, K.M., Loai, Z.: The operational role of security information and event management systems. IEEE Secur. Priv. 12(5), 35–41 (2014)CrossRef Sandeep, B., Pratyusa, K.M., Loai, Z.: The operational role of security information and event management systems. IEEE Secur. Priv. 12(5), 35–41 (2014)CrossRef
11.
Zurück zum Zitat Cesario, D.S., Alessia, G., Ilaria, M., Marco, V.: A novel security information and event management system for enhancing cyber security in a hydroelectric dam. Int. J. Crit. Infrastruct. Protect. 13(5), 39–51 (2016) Cesario, D.S., Alessia, G., Ilaria, M., Marco, V.: A novel security information and event management system for enhancing cyber security in a hydroelectric dam. Int. J. Crit. Infrastruct. Protect. 13(5), 39–51 (2016)
12.
Zurück zum Zitat Filip, H., Josef, H., Sona, N., Stanislav, Z., Ondrej, M.: The deployment of security information and event management in cloud infrastructure. In: 25th International Conference Radioelektronika (RADIOELEKTRONIKA), pp. 399–404. IEEE, Pardubice (2015) Filip, H., Josef, H., Sona, N., Stanislav, Z., Ondrej, M.: The deployment of security information and event management in cloud infrastructure. In: 25th International Conference Radioelektronika (RADIOELEKTRONIKA), pp. 399–404. IEEE, Pardubice (2015)
13.
Zurück zum Zitat David, R.M., Shon, H., Allen, H., Stephen, V., Chris, B.: Security Information and Event Management (SIEM) Implementation, 1st edn. McGraw-Hill Education, New York (2011) David, R.M., Shon, H., Allen, H., Stephen, V., Chris, B.: Security Information and Event Management (SIEM) Implementation, 1st edn. McGraw-Hill Education, New York (2011)
14.
Zurück zum Zitat David, N.: Designing and Building A Security Operations Center, 1st edn. Syngress, Massachusetts (2015) David, N.: Designing and Building A Security Operations Center, 1st edn. Syngress, Massachusetts (2015)
15.
Zurück zum Zitat Joseph, M., Gary, M., Nadhem, A.: Security Operations Center: Building, Operating, and Maintaining your SOC. Cisco Press, Indiana (2016) Joseph, M., Gary, M., Nadhem, A.: Security Operations Center: Building, Operating, and Maintaining your SOC. Cisco Press, Indiana (2016)
Metadaten
Titel
A Novel and Comprehensive Evaluation Methodology for SIEM
verfasst von
Mahdieh Safarzadeh
Hossein Gharaee
Amir Hossein Panahi
Copyright-Jahr
2019
DOI
https://doi.org/10.1007/978-3-030-34339-2_28