본문 바로가기
  • Home

An Effective Security Monitoring Scheme Based on Correlation Analysis of Multiple Security Events

  • Journal of Knowledge Information Technology and Systems
  • Abbr : JKITS
  • 2012, 7(2), pp.49-58
  • Publisher : Korea Knowledge Information Technology Society
  • Research Area : Interdisciplinary Studies > Interdisciplinary Research
  • Published : April 30, 2012

이행곤 1 최상수 1 Jungsuk Song 1 Cho, Gi Hwan 2

1한국과학기술정보연구원
2전북대학교

Accredited

ABSTRACT

In order to cope with recent cyber attacks more effectively, it is needed to focus on only the significant security events from a large number of the original security events triggered by the security products such as IDS, TMS, etc. In this paper, we propose an effective security monitoring scheme which is able to collect and classify the security events provided by diverse types of the security products that are already deployed on the backbone network. In addition, the proposed scheme can contribute to the reduction of the security events that the security operators have to inspect. We expect that the proposed scheme can be used for reference model of the security centers to carry out incident response.

Citation status

* References for papers published after 2023 are currently being built.