Architecture of Anomaly Detection Module for the Security Operations Center

被引:7
|
作者
Bienias, Piotr [1 ]
Kolaczek, Grzegorz [1 ]
Warzynski, Arkadiusz [1 ]
机构
[1] Wroclaw Univ Sci & Technol, Fac Comp Sci & Management, 27 Wybrzeze Wyspianskiego St, PL-50370 Wroclaw, Poland
关键词
anomaly detection; Security Operation Center; intrusion detection;
D O I
10.1109/WETICE.2019.00035
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The paper presents the preliminary results of the research undertaken within RegSOC project. The goal of the project is initiate a prototype instance of the model Regional Center for Cybersecurity (RegSOC) and to facilitate to the public entities. The outcomes of this project will allow to raise levels of security protection and to present procedures, which can reduce the probability of unwanted events and methods of lowering their consequences. The project aims at developing a comprehensive cybersecurity monitoring platform which will be the software and organizational solution (management models and organizational procedures). The software part of the platform will constitute several modules specialized in various types of security level evaluation. The paper focuses on the module integrated with the RegSOC platform which will support security-related events detection by detecting anomalies. The architecture of the anomaly detection module has been introduced and the functional and non-functional requirements related to this module have been discussed. Also, the role and the way of integrating the module with the general RegSOC architecture has been demonstrated.
引用
收藏
页码:126 / 131
页数:6
相关论文
共 50 条
  • [31] Hybrid Security Architecture for Data Center Networks
    Lam, Ho-Yu
    Zhao, Song
    Xi, Kang
    Chao, H. Jonathan
    2012 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2012,
  • [32] Cyber Security Operations Center Characterization Model and Analysis
    Kowtha, Sitaram
    Nolan, Laura A.
    Daley, Rosemary A.
    2012 IEEE INTERNATIONAL CONFERENCE ON TECHNOLOGIES FOR HOMELAND SECURITY, 2012, : 470 - 475
  • [33] Analysis of the Functionalities of a Shared ICS Security Operations Center
    Dimitrov, Willian
    Syarova, Svetlana
    2019 BIG DATA, KNOWLEDGE AND CONTROL SYSTEMS ENGINEERING (BDKCSE), 2019,
  • [34] An Architecture for Monitoring and Anomaly Detection for Space Systems
    Cortes, Edwin A.
    Rabelo, Luis
    SAE INTERNATIONAL JOURNAL OF AEROSPACE, 2013, 6 (01): : 81 - 86
  • [35] Security Operations Center: A Systematic Study and Open Challenges
    Vielberth, Manfred
    Boehm, Fabian
    Fichtinger, Ines
    Pernul, Guenther
    IEEE ACCESS, 2020, 8 : 227756 - 227779
  • [36] A Power Anomaly Detection Architecture Based on DNN
    Geng, Wei
    Liu, Dongyu
    Cao, Xiu
    PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND APPLICATION ENGINEERING (CSAE2019), 2019,
  • [37] API Traffic Anomaly Detection in Microservice Architecture
    Sowmya, M.
    Rai, Ankith J.
    Spoorthi, V
    Irfan, M. D.
    Honnavalli, Prasad B.
    Nagasundari, S.
    2023 IEEE/ACM 23RD INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND INTERNET COMPUTING WORKSHOPS, CCGRIDW, 2023, : 206 - 213
  • [38] LEGRI Science Operation Center. Architecture and Operations
    Pere Blay
    Julia Suso
    Almudena Robert
    Jose Luis Requena
    Jorge Alamo
    Victor Reglero
    Chris J. Eyles
    Astrophysics and Space Science, 2001, 276 : 311 - 323
  • [39] LEGRI Science Operation Center. Architecture and operations
    Blay, P
    Suso, J
    Robert, A
    Requena, JL
    Alamo, J
    Reglero, V
    Eyles, CJ
    ASTROPHYSICS AND SPACE SCIENCE, 2001, 276 (01) : 311 - 323
  • [40] A data analytics framework for anomaly detection in flight operations
    Coelho e Silva, Lucas
    Rocha Murca, Mayara Conde
    JOURNAL OF AIR TRANSPORT MANAGEMENT, 2023, 110