DocumentCode
1361098
Title
Improving the Automation of Security Information Management: A Collaborative Approach
Author
Aguirre, Idoia ; Alonso, Sergio
Volume
10
Issue
1
fYear
2012
Firstpage
55
Lastpage
59
Abstract
Many preventive security measures purport to protect networks from cyber intrusions. These adopted measures can generate a large amount of information that should be stored and analyzed to enable responses to detected attacks. Security information and event managers (SIEMs) are indispensable for collecting all of a system´s security-related information in a central repository. This can then provide trend analysis and lead analysts to adopt appropriate actions. A collaborative work approach lets SIEMs of different trusted domains share alarms and their countermeasures. By sharing alarms and adopted measures in domains with similar profiles, the authors hope to enhance a global view of the security and facilitate decision making for security-domain administrators.
Keywords
decision making; groupware; security of data; central repository; collaborative work approach; cyber intrusions; decision making; network protection; preventive security measures; security information and event managers; security information management automation; security-domain administrators; Automation; Collaboration; Computer security; Information management; Network security; Security; Servers; Traffic control; SIEM; computer-supported cooperative work; data sharing; decision support; security; security information and event managers;
fLanguage
English
Journal_Title
Security & Privacy, IEEE
Publisher
ieee
ISSN
1540-7993
Type
jour
DOI
10.1109/MSP.2011.153
Filename
6060795
Link To Document