Using Extensible Metadata Definitions to Create a Vendor-Independent SIEM System
نویسندگان
چکیده
The threat of cyber-attacks grows up, as one can see by several negative security news and reports [8]. Today there are many security components (e.g. anti-virus-system, firewall, and IDS) available to protect enterprise networks; unfortunately, they work independently from each other – isolated. But many attacks can only be recognized if logs and events of different security components are combined and correlated with each other. Existing specifications of the Trusted Computing Group (TCG) already provide a standardized protocol for metadata collection and exchange named IF-MAP. This protocol is very useful for network security applications and for the correlation of different metadata in one common database. That circumstance again is very suitable for Security Information and Event Management (SIEM) systems. In this paper we present a SIEM architecture developed during a research project called SIMU. Additionally, we introduce a new kind of metadata that can be helpful for domains that are not covered by the existing TCG specifications. Therefore, a metadata model with unique data types has been designed for higher flexibility. For the realization two different extensions are discussed in this paper: a new feature model or an additional service identifier.
منابع مشابه
Towards an Integrated Model for Data, Metadata, and Operations
Abstract: Information integration requires manipulating data and metadata in ways that in general go beyond a single existing transformation formalism. As a result, a complete source-to-target mapping can only be expressed by combining different techniques like query languages, wrappers, scripting, etc., which are often speci c to a single integration platform or vendor. Such a mapping is not p...
متن کاملAuthor-generated Metadata Usability A USABILITY STUDY OF A TOOL FOR CONTRIBUTOR-SUPPLIED METDATA CREATION: THE USE OF METADATA ELEMENT DEFINITIONS AND EXAMPLES IN ONLINE HELP By
This paper describes a usability study of Botanical Pride, a contributor-supplied metadata creation tool which allows botany enthusiasts to create metadata for images of botanical specimens. Two versions of the interface were tested: a Definitions Only version that included definitions of metadata elements and a Definitions+Examples version that included definitions of metadata elements and one...
متن کاملMoving Library Metadata Toward Linked Data: Opportunities Provided by the eXtensible Catalog
To ensure that they can participate in the Semantic Web, libraries need to prepare their legacy metadata for use as linked data. eXtensible Catalog (XC) software facilitates converting legacy library data into linked data using a platform that enables risk-free experimentation and that can be used to address problems with legacy metadata using batch services. The eXtensible Catalog also provide...
متن کاملUsing Profiles for IMDI Metadata Creation
In this paper a system to support the creation of extended IMDI metadata records is presented. It is based on bundling definitions of the in the IMDI system user definable key-name/value pairs in a profile. The possibility of using inheritance of profiles in a corpus structure is explored. Profiles Can be created and used by the IMDI Editor, a tool specially designed to create IMDI metadata rec...
متن کاملAdvanced PLC programming methods
The main goal of this thesis is to use Model-Driven Design approach and Object-Oriented Programming features to create a software tool for programming PLC control system. The primary function of the instrument of development is the automated generating of proper PLC code according to IEC 61131-3 from templates which represent models of real components of automated plant and let us use some of t...
متن کامل