UCLog+ : A Security Data Management System for Correlating Alerts, Incidents, and Raw Data From Remote Logs

Computer Science – Cryptography and Security

Scientific paper

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

10 pages, 9 Tables, 16 Figures

Scientific paper

Source data for computer network security analysis takes different forms (alerts, incidents, logs) and each source may be voluminous. Due to the challenge this presents for data management, this has often lead to security stovepipe operations which focus primarily on a small number of data sources for analysis with little or no automated correlation between data sources (although correlation may be done manually). We seek to address this systemic problem. In previous work we developed a unified correlated logging system (UCLog) that automatically processes alerts from different devices. We take this work one step further by presenting the architecture and applications of UCLog+ which adds the new capability to correlate between alerts and incidents and raw data located on remote logs. UCLog+ can be used for forensic analysis including queries and report generation but more importantly it can be used for near-real-time situational awareness of attack patterns in progress. The system, implemented with open source tools, can also be a repository for secure information sharing by different organizations.

No associations

LandOfFree

Say what you really think

Search LandOfFree.com for scientists and scientific papers. Rate them and share your experience with other people.

Rating

UCLog+ : A Security Data Management System for Correlating Alerts, Incidents, and Raw Data From Remote Logs does not yet have a rating. At this time, there are no reviews or comments for this scientific paper.

If you have personal experience with UCLog+ : A Security Data Management System for Correlating Alerts, Incidents, and Raw Data From Remote Logs, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and UCLog+ : A Security Data Management System for Correlating Alerts, Incidents, and Raw Data From Remote Logs will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFWR-SCP-O-665158

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.