Application of security information and event management system for protection in enterprise information infrastructure

DOI 10.18127/j19997493-201804-12


A.V. Proletarsky – Dr.Sc.(Eng.), Professor, Department «Computer systems and networks», Dean of Faculty, Bauman Moscow State Technical University
A.A. Mitkovsky – Post-graduate Student, Department «Computer systems and networks», Bauman Moscow State Technical University
A.D. Ponomarev – Post-graduate Student, Department «Computer systems and networks», Bauman Moscow State Technical University

To date, there has been an active growth in the amount of data that must be processed to determine the real state of protection of the information infrastructure. To solve this problem, a SIEM-system was developed that allows for the collection, storage and analysis of information in real time from various sources of events to take specific actions to prevent to information security threats. The aim of this work was to study the approach to collecting heterogeneous information, analyzing it, and identifying security incidents based on the principles of data correlation in SIEM systems. In this paper the main tasks of SIEM-systems is described, a model for representing normalized data for aggregation and event filtering is proposed. A technique for detecting bruteforce attacks based on the correlation mechanisms of the MaxPatrol SIEM system has been developed. The conclusion is made that the proposed approach to the implementation of SIEM-systems based on the rule-based reasoning (RBR) allows solving the problems of detecting security incidents with strict observance of the conditions for making decisions.

