• DocumentCode
    1361098
  • Title

    Improving the Automation of Security Information Management: A Collaborative Approach

  • Author

    Aguirre, Idoia ; Alonso, Sergio

  • Volume
    10
  • Issue
    1
  • fYear
    2012
  • Firstpage
    55
  • Lastpage
    59
  • Abstract
    Many preventive security measures purport to protect networks from cyber intrusions. These adopted measures can generate a large amount of information that should be stored and analyzed to enable responses to detected attacks. Security information and event managers (SIEMs) are indispensable for collecting all of a system´s security-related information in a central repository. This can then provide trend analysis and lead analysts to adopt appropriate actions. A collaborative work approach lets SIEMs of different trusted domains share alarms and their countermeasures. By sharing alarms and adopted measures in domains with similar profiles, the authors hope to enhance a global view of the security and facilitate decision making for security-domain administrators.
  • Keywords
    decision making; groupware; security of data; central repository; collaborative work approach; cyber intrusions; decision making; network protection; preventive security measures; security information and event managers; security information management automation; security-domain administrators; Automation; Collaboration; Computer security; Information management; Network security; Security; Servers; Traffic control; SIEM; computer-supported cooperative work; data sharing; decision support; security; security information and event managers;
  • fLanguage
    English
  • Journal_Title
    Security & Privacy, IEEE
  • Publisher
    ieee
  • ISSN
    1540-7993
  • Type

    jour

  • DOI
    10.1109/MSP.2011.153
  • Filename
    6060795