DATA-DRIVEN FIELD MAPPING OF SECURITY LOGS FOR INTEGRATED MONITORING

被引:0
|
作者
Choi, Seungoh [1 ]
Kim, Yesol [1 ]
Yun, Jeong-Han [1 ]
Min, Byung-Gil [1 ]
Kim, Hyoung-Chun [1 ]
机构
[1] Affiliated Inst ETRI, Daejeon, South Korea
来源
关键词
Security; event logs; integrated system monitoring;
D O I
10.1007/978-3-030-34647-8_13
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As industrial control system vulnerabilities and attacks increase, security controls must be applied to operational technologies. The growing demand for security threat monitoring and analysis techniques that integrate information from security logs has resulted in enterprise security management systems giving way to security information and event management systems. Nevertheless, it is vital to implement some form of pre-processing to collect, integrate and analyze security events efficiently. Operators still have to manually check entire security logs or write scripts or parsers that draw on domain knowledge, tasks that are time-consuming and error-prone. To address these challenges, this chapter focuses on the data-driven mapping of security logs to support the integrated monitoring of operational technology systems. The characteristics of security logs from security appliances used in critical infrastructure assets are analyzed to create a tool that maps different security logs to field categories to support integrated system monitoring. The tool reduces the effort needed by operators to manually process security logs even when the logged data generated by security appliances has new or modified formats.
引用
收藏
页码:253 / 268
页数:16
相关论文
共 50 条
  • [1] Security and Privacy for Smart Meters: A Data-Driven Mapping Study
    Antoniadis, Ioannis I.
    Chatzidimitriou, Kyriakos C.
    Symeonidis, Andreas L.
    PROCEEDINGS OF 2019 IEEE PES INNOVATIVE SMART GRID TECHNOLOGIES EUROPE (ISGT-EUROPE), 2019,
  • [2] Data-Driven Transient Stability Boundary Generation for Online Security Monitoring
    Yan, Rong
    Geng, Guangchao
    Jiang, Quanyuan
    IEEE TRANSACTIONS ON POWER SYSTEMS, 2021, 36 (04) : 3042 - 3052
  • [3] Integrated Data-Driven Power System Transient Stability Monitoring and Enhancement
    Zhu, Lipeng
    Wen, Weijia
    Li, Jiayong
    Hu, Yuhan
    IEEE TRANSACTIONS ON POWER SYSTEMS, 2024, 39 (01) : 1797 - 1809
  • [4] An integrated approach for tactical monitoring and data-driven spread forecasting of wildfires
    Valero, Mario M.
    Rios, Oriol
    Mata, Christian
    Pastor, Elsa
    Planas, Eulalia
    FIRE SAFETY JOURNAL, 2017, 91 : 835 - 844
  • [5] Data-driven public health security
    Li, Cuiping
    Wu, Linhuan
    Shu, Chang
    Bao, Yiming
    Ma, Juncai
    Song, Shuhui
    CHINESE SCIENCE BULLETIN-CHINESE, 2024, 69 (09): : 1156 - 1163
  • [6] A data-driven approach for embedded security
    Saputra, H
    Ozturk, O
    Vijaykrishnan, N
    Kandemir, M
    Brooks, R
    IEEE COMPUTER SOCIETY ANNUAL SYMPOSIUM ON VLSI, PROCEEDINGS: NEW FRONTIERS IN VLSI DESIGN, 2005, : 104 - 109
  • [7] Data-driven multimedia forensics and security
    Rocha, Anderson
    Li, Shujun
    Kuo, C. -C. Jay
    Piva, Alessandro
    Huang, Jiwu
    JOURNAL OF VISUAL COMMUNICATION AND IMAGE REPRESENTATION, 2018, 55 : 447 - 448
  • [8] A Data-Driven Approach to Security Science
    Iyer, Ravishankar K.
    7TH ACM SYMPOSIUM ON INFORMATION, COMPUTER AND COMMUNICATIONS SECURITY (ASIACCS 2012), 2012,
  • [9] UNCOVER: Data-Driven Design Support through Continuous Monitoring of Security Incidents
    Stammler, Matthias
    Lorenz, Julian
    Sax, Eric
    Becker, Juergen
    Haman, Matthias
    Bidinger, Patrick
    Dewald, Andreas
    Georgouti, Paraskevi
    Camarinopoulos, Alexios
    Becker, Guenter
    Finsterbusch, Klaus
    Kirschner, Maximilian
    Adolph, Laurenz
    Hohl, Carl Philipp
    Rill, Maria
    Vonderau, Daniel
    Betancourt, Victor Pazmino
    2024 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION, DATE, 2024,
  • [10] Inference Attack and Privacy Security of Data-driven Industrial Process Monitoring Systems
    Zhang, Xinmin
    Zhang, Xuerui
    Song, Zhihuan
    Ren, Qinyuan
    Wei, Chihang
    2023 IEEE 12TH DATA DRIVEN CONTROL AND LEARNING SYSTEMS CONFERENCE, DDCLS, 2023, : 1312 - 1319