DATA-DRIVEN FIELD MAPPING OF SECURITY LOGS FOR INTEGRATED MONITORING

被引:0
|
作者
Choi, Seungoh [1 ]
Kim, Yesol [1 ]
Yun, Jeong-Han [1 ]
Min, Byung-Gil [1 ]
Kim, Hyoung-Chun [1 ]
机构
[1] Affiliated Inst ETRI, Daejeon, South Korea
来源
关键词
Security; event logs; integrated system monitoring;
D O I
10.1007/978-3-030-34647-8_13
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As industrial control system vulnerabilities and attacks increase, security controls must be applied to operational technologies. The growing demand for security threat monitoring and analysis techniques that integrate information from security logs has resulted in enterprise security management systems giving way to security information and event management systems. Nevertheless, it is vital to implement some form of pre-processing to collect, integrate and analyze security events efficiently. Operators still have to manually check entire security logs or write scripts or parsers that draw on domain knowledge, tasks that are time-consuming and error-prone. To address these challenges, this chapter focuses on the data-driven mapping of security logs to support the integrated monitoring of operational technology systems. The characteristics of security logs from security appliances used in critical infrastructure assets are analyzed to create a tool that maps different security logs to field categories to support integrated system monitoring. The tool reduces the effort needed by operators to manually process security logs even when the logged data generated by security appliances has new or modified formats.
引用
收藏
页码:253 / 268
页数:16
相关论文
共 50 条
  • [21] Data-driven assessment of eQTL mapping methods
    Michaelson, Jacob J.
    Alberts, Rudi
    Schughart, Klaus
    Beyer, Andreas
    BMC GENOMICS, 2010, 11
  • [22] Data-driven assessment of eQTL mapping methods
    Jacob J Michaelson
    Rudi Alberts
    Klaus Schughart
    Andreas Beyer
    BMC Genomics, 11
  • [23] Data-driven matched field processing for Lamb wave structural health monitoring
    Harley, Joel B.
    Moura, Jose M. F.
    JOURNAL OF THE ACOUSTICAL SOCIETY OF AMERICA, 2014, 135 (03): : 1231 - 1244
  • [24] Data-Driven Reversible Jump for QTL Mapping
    Zuanetti, Daiane Aparecida
    Milan, Luis Aparecido
    GENETICS, 2016, 202 (01) : 25 - +
  • [25] A data-driven monitoring scheme for multivariate multimodal data
    Wang, Zhiqiong
    Gong, Renping
    Song, Lisha
    He, Shuguang
    Gao, Yuan
    COMPUTERS & INDUSTRIAL ENGINEERING, 2024, 192
  • [26] Online Flooding Supervision in Packed Towers: An Integrated Data-Driven Statistical Monitoring Method
    Liu, Yi
    Liang, Yu
    Gao, Zengliang
    Yao, Yuan
    CHEMICAL ENGINEERING & TECHNOLOGY, 2018, 41 (03) : 436 - 446
  • [27] Integrated Data-Driven Process Monitoring and Explicit Fault-Tolerant Multiparametric Control
    Onel, Melis
    Burnak, Bans
    Pistikopoulos, Efstratios N.
    INDUSTRIAL & ENGINEERING CHEMISTRY RESEARCH, 2020, 59 (06) : 2291 - 2306
  • [28] Towards an Integrated Cyberinfrastructure for Scalable Data-driven Monitoring, Dynamic Prediction and Resilience of Wildfires
    Altintas, Ilkay
    Block, Jessica
    de Callafon, Raymond
    Crawl, Daniel
    Cowart, Charles
    Gupta, Amarnath
    Nguyen, Mai
    Braun, Hans-Werner
    Schulze, Jurgen
    Gollner, Michael
    Trouve, Arnaud
    Smarr, Larry
    INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE, ICCS 2015 COMPUTATIONAL SCIENCE AT THE GATES OF NATURE, 2015, 51 : 1633 - 1642
  • [29] Adaptive integrated security control of ICPS based on data-driven and mechanism analysis fusion method
    Li, Wei
    Chen, Jing-Jing
    Li, Ya-Jie
    Kongzhi yu Juece/Control and Decision, 2024, 39 (09): : 3079 - 3089
  • [30] Data-driven change towards integrated care
    Bourgeois, Jolyce
    De Ridder, Lotje
    Van den Bogaert, Saskia
    Van der Brempt, Isabelle
    De Ridder, Ri
    INTERNATIONAL JOURNAL OF INTEGRATED CARE, 2018, 18