• DocumentCode
    2361083
  • Title

    A Study of ESMTC(Enterprise Security Management System Based on Threshold Classification)

  • Author

    Choi, Kyong-Ho ; Park, Won Hyung ; Kim, Kuinam J.

  • Author_Institution
    Center for Ind. Security, Kyonggi Univ., Suwon, South Korea
  • fYear
    2012
  • fDate
    23-25 May 2012
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Most of organizations operate an Enterprise Security Management system (ESM) for managing and analyzing security events. However, it is difficult to instantly analyze and respond for each event by a security manager because the amount of security events collected, stored, analyzed, and displayed by the Enterprise Security Management system is significantly increased according to time and expansions in systems and networks. In addition, as the trends of threats have been changed as a type of Advanced Persistent Threat (APT) that attacks specific individuals and organizations for a long term period, an integrated analysis is required for all security events. Thus, in this study, an Enterprise Security Management system based on Threshold Classification (ESMTC) is proposed to detect and intercept cyber threats occurred for a long term period. It shows an advantage that it does not failure to notice even a single attack through structuralizing and listing detailed attack detection packets and performs related analyses to other attacks.
  • Keywords
    business data processing; corporate modelling; security of data; APT; ESMTC; advanced persistent threat; cyber threats; detection packets; enterprise security management system based on threshold classification; security events; Computer crime; Educational institutions; Industries; Monitoring; Operating systems; Organizations;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Science and Applications (ICISA), 2012 International Conference on
  • Conference_Location
    Suwon
  • Print_ISBN
    978-1-4673-1402-2
  • Type

    conf

  • DOI
    10.1109/ICISA.2012.6220971
  • Filename
    6220971