About | Contact Us | Register | Login
ProceedingsSeriesJournalsSearchEAI
Security and Privacy in Communication Networks. 17th EAI International Conference, SecureComm 2021, Virtual Event, September 6–9, 2021, Proceedings, Part I

Research Article

SIEMA: Bringing Advanced Analytics to Legacy Security Information and Event Management

Download(Requires a free EAI acccount)
534 downloads
Cite
BibTeX Plain Text
  • @INPROCEEDINGS{10.1007/978-3-030-90019-9_2,
        author={Pejman Najafi and Feng Cheng and Christoph Meinel},
        title={SIEMA: Bringing Advanced Analytics to Legacy Security Information and Event Management},
        proceedings={Security and Privacy in Communication Networks. 17th EAI International Conference, SecureComm 2021, Virtual Event, September 6--9, 2021, Proceedings, Part I},
        proceedings_a={SECURECOMM},
        year={2021},
        month={11},
        keywords={Reference architecture Next-gen SIEM Advanced analytic Big data Cybersecurity},
        doi={10.1007/978-3-030-90019-9_2}
    }
    
  • Pejman Najafi
    Feng Cheng
    Christoph Meinel
    Year: 2021
    SIEMA: Bringing Advanced Analytics to Legacy Security Information and Event Management
    SECURECOMM
    Springer
    DOI: 10.1007/978-3-030-90019-9_2
Pejman Najafi1, Feng Cheng1, Christoph Meinel1
  • 1: University of Potsdam

Abstract

Within today’s organizations, a Security Information and Event Management (SIEM) system is the centralized repository expected to aggregate all security-relevant data. While the primary purpose of SIEM solutions has been regulatory compliance, more and more organizations recognize the value of these systems for threat detection due to their holistic view of the entire enterprise. Today’s mature Security Operation Centers dedicate several teams to threat hunting, pattern/correlation rule creation, and alert monitoring. However, traditional SIEM systems lack the capability for advanced analytics as they were designed for different purposes using technologies that are now more than a decade old. In this paper, we discuss the requirements for a next-generation SIEM system that emphasizes analytical capabilities to allow advanced data science and engineering. Next, we propose a reference architecture that can be used to design such systems. We describe our experience in implementing a next-gen SIEM with advanced analytical capabilities, both in academia and industry. Lastly, we illustrate the importance of advanced analytics within today’s SIEM with a simple yet complex use case of beaconing detection.

Keywords
Reference architecture Next-gen SIEM Advanced analytic Big data Cybersecurity
Published
2021-11-09
Appears in
SpringerLink
http://dx.doi.org/10.1007/978-3-030-90019-9_2
Copyright © 2021–2025 ICST
EBSCOProQuestDBLPDOAJPortico
EAI Logo

About EAI

  • Who We Are
  • Leadership
  • Research Areas
  • Partners
  • Media Center

Community

  • Membership
  • Conference
  • Recognition
  • Sponsor Us

Publish with EAI

  • Publishing
  • Journals
  • Proceedings
  • Books
  • EUDL