Using Extensible Metadata Definitions to Create a Vendor-Independent SIEM System

نویسندگان

  • Kai-Oliver Detken
  • Dirk Scheuermann
  • Bastian Hellmann
چکیده

The threat of cyber-attacks grows up, as one can see by several negative security news and reports [8]. Today there are many security components (e.g. anti-virus-system, firewall, and IDS) available to protect enterprise networks; unfortunately, they work independently from each other – isolated. But many attacks can only be recognized if logs and events of different security components are combined and correlated with each other. Existing specifications of the Trusted Computing Group (TCG) already provide a standardized protocol for metadata collection and exchange named IF-MAP. This protocol is very useful for network security applications and for the correlation of different metadata in one common database. That circumstance again is very suitable for Security Information and Event Management (SIEM) systems. In this paper we present a SIEM architecture developed during a research project called SIMU. Additionally, we introduce a new kind of metadata that can be helpful for domains that are not covered by the existing TCG specifications. Therefore, a metadata model with unique data types has been designed for higher flexibility. For the realization two different extensions are discussed in this paper: a new feature model or an additional service identifier.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Towards an Integrated Model for Data, Metadata, and Operations

Abstract: Information integration requires manipulating data and metadata in ways that in general go beyond a single existing transformation formalism. As a result, a complete source-to-target mapping can only be expressed by combining different techniques like query languages, wrappers, scripting, etc., which are often speci c to a single integration platform or vendor. Such a mapping is not p...

متن کامل

Author-generated Metadata Usability A USABILITY STUDY OF A TOOL FOR CONTRIBUTOR-SUPPLIED METDATA CREATION: THE USE OF METADATA ELEMENT DEFINITIONS AND EXAMPLES IN ONLINE HELP By

This paper describes a usability study of Botanical Pride, a contributor-supplied metadata creation tool which allows botany enthusiasts to create metadata for images of botanical specimens. Two versions of the interface were tested: a Definitions Only version that included definitions of metadata elements and a Definitions+Examples version that included definitions of metadata elements and one...

متن کامل

Moving Library Metadata Toward Linked Data: Opportunities Provided by the eXtensible Catalog

To ensure that they can participate in the Semantic Web, libraries need to prepare their legacy metadata for use as linked data. eXtensible Catalog (XC) software facilitates converting legacy library data into linked data using a platform that enables risk-free experimentation and that can be used to address problems with legacy metadata using batch services. The eXtensible Catalog also provide...

متن کامل

Using Profiles for IMDI Metadata Creation

In this paper a system to support the creation of extended IMDI metadata records is presented. It is based on bundling definitions of the in the IMDI system user definable key-name/value pairs in a profile. The possibility of using inheritance of profiles in a corpus structure is explored. Profiles Can be created and used by the IMDI Editor, a tool specially designed to create IMDI metadata rec...

متن کامل

Advanced PLC programming methods

The main goal of this thesis is to use Model-Driven Design approach and Object-Oriented Programming features to create a software tool for programming PLC control system. The primary function of the instrument of development is the automated generating of proper PLC code according to IEC 61131-3 from templates which represent models of real components of automated plant and let us use some of t...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2015