Investigation of Cyber Situation Awareness via SIEM tools: a constructive review

U. Ünal, Ceyda Nur Kahya, Yaprak Kurtlutepe, H. Dağ
{"title":"Investigation of Cyber Situation Awareness via SIEM tools: a constructive review","authors":"U. Ünal, Ceyda Nur Kahya, Yaprak Kurtlutepe, H. Dağ","doi":"10.1109/UBMK52708.2021.9558964","DOIUrl":null,"url":null,"abstract":"Awareness, in the sense of security, builds the backbone of operations understanding the current and future cyber activities. Situation awareness has become the focal point of securing systems due to dynamic nature of cyber domain. Technological advancements cause the volatility to transform into upcoming challenges. Understanding those is the key to keep cyber Situation Awareness (SA) progression. Earlier studies define required steps to administer cyber SA. These steps (perceive, comprehend, project, and resolve) are also adapted to cyber domain. Rapid technological changes redefine the content of those and thus, it creates demands improving automated tools, which play as systematic factor in nurturing SA. As a system factor, SIEM tools can be basis for comprehending cyber domain. In this work, we investigate recent studies contributed mainly to SIEM (Security Information and Event Management) tool’s enhancement to evaluate current state and help predict upcoming challenges for maintaining awareness. We use various criteria in our investigation such as; architecture improvement, affected SIEM process, utilized CTI (Cyber Threat Intelligence) artefact, implementation area, and type of produced result. In doing so, we aim to impart upward trends on CSA (Cyber Situation Awareness) to academia and industry professionals.","PeriodicalId":106516,"journal":{"name":"2021 6th International Conference on Computer Science and Engineering (UBMK)","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2021-09-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 6th International Conference on Computer Science and Engineering (UBMK)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/UBMK52708.2021.9558964","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

Awareness, in the sense of security, builds the backbone of operations understanding the current and future cyber activities. Situation awareness has become the focal point of securing systems due to dynamic nature of cyber domain. Technological advancements cause the volatility to transform into upcoming challenges. Understanding those is the key to keep cyber Situation Awareness (SA) progression. Earlier studies define required steps to administer cyber SA. These steps (perceive, comprehend, project, and resolve) are also adapted to cyber domain. Rapid technological changes redefine the content of those and thus, it creates demands improving automated tools, which play as systematic factor in nurturing SA. As a system factor, SIEM tools can be basis for comprehending cyber domain. In this work, we investigate recent studies contributed mainly to SIEM (Security Information and Event Management) tool’s enhancement to evaluate current state and help predict upcoming challenges for maintaining awareness. We use various criteria in our investigation such as; architecture improvement, affected SIEM process, utilized CTI (Cyber Threat Intelligence) artefact, implementation area, and type of produced result. In doing so, we aim to impart upward trends on CSA (Cyber Situation Awareness) to academia and industry professionals.
基于SIEM工具的网络态势感知研究:建设性回顾
在安全意识方面,建立了了解当前和未来网络活动的运营支柱。由于网络域的动态性,态势感知已成为系统安全的重点。技术进步导致波动性转化为即将到来的挑战。了解这些是保持网络态势感知(SA)进展的关键。早期的研究定义了管理网络安全所需的步骤。这些步骤(感知、理解、计划和解决)也适用于网络领域。快速的技术变化重新定义了这些内容,因此,它创造了改进自动化工具的需求,这些工具在培养SA中扮演着系统因素。作为一个系统因素,SIEM工具可以作为理解网络域的基础。在这项工作中,我们调查了最近的研究,主要贡献了SIEM(安全信息和事件管理)工具的增强,以评估当前状态并帮助预测即将到来的挑战,以保持意识。我们在调查中使用各种标准,例如;架构改进、影响SIEM过程、利用CTI(网络威胁情报)工件、实现区域和产生结果的类型。为此,我们的目标是向学术界和业界专业人士介绍网络态势感知的上升趋势。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信