ePrints.FRI - University of Ljubljana, Faculty of Computer and Information Science

Detection of critical events in complex information systems

Aljoša Počič (2017) Detection of critical events in complex information systems. EngD thesis.

[img]
Preview
PDF
Download (4Mb)

    Abstract

    Safety in the information environment depends not just on the technologies used, but also on the policies and rules in place. New security protections have developed as a response to new threats and attacks. In order to make use of the data obtained from different security protections and introduce policies into everyday activities within the information system, we used a SIEM system. SIEM system assumes the essential role regarding security of the information system. All records, events and network traffic are stored in one place and in a normalized form, which allows analysis of their correlation. This is how we gain a central position, allowing us to monitor the security situation in the information system, and also to conduct analyses and security reports. The thesis discusses the key sources of information for SIEM systems and the possibilities for data collection from the network traffic. The development of SIEM systems over time and the expectations of next generation SIEM systems available today are also described. The following part focuses on the sample customer and on the model environment. The types of devices in the customer’s environment and the integration of devices in the SIEM system used are listed and described as well. The last part of the thesis shows the use of the solution and three typical areas of analyses performed in the SIEM system. The analysis of advanced attacks also shows the use of free online tools that help us to confirm or reject the threats identified by the security solutions in the information environment.

    Item Type: Thesis (EngD thesis)
    Keywords: SIEM, protection of information infrastructure, logs, events, correlations, security
    Number of Pages: 72
    Language of Content: Slovenian
    Mentor / Comentors:
    Name and SurnameIDFunction
    prof. dr. Miha Mraz249Mentor
    Link to COBISS: http://www.cobiss.si/scripts/cobiss?command=search&base=51012&select=(ID=1537607107)
    Institution: University of Ljubljana
    Department: Faculty of Computer and Information Science
    Item ID: 3977
    Date Deposited: 26 Sep 2017 13:57
    Last Modified: 19 Oct 2017 14:22
    URI: http://eprints.fri.uni-lj.si/id/eprint/3977

    Actions (login required)

    View Item