2011
DOI: 10.1007/978-3-642-24270-0_15
|View full text |Cite
|
Sign up to set email alerts
|

Integration of a System for Critical Infrastructure Protection with the OSSIM SIEM Platform: A dam case study

Abstract: In recent years the monitoring and control devices in charge of supervising the critical processes of Critical Infrastructures have been victims of cyber attacks. To face such threat, organizations providing critical services are increasingly focusing on protecting their network infrastructures. Security Information and Event Management (SIEM) frameworks support network protection by performing centralized correlation of network asset reports. In this work we propose an extension of a commercial SIEM framework… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
6
0

Year Published

2012
2012
2020
2020

Publication Types

Select...
6
2

Relationship

2
6

Authors

Journals

citations
Cited by 17 publications
(6 citation statements)
references
References 5 publications
0
6
0
Order By: Relevance
“…The Response Module receives the output of the ARIES Analysis Engine and generates security events based on the AlienVault Open Source SIEM (OSSIM) [ 49 , 50 ] format. Moreover, based on the information originating from the three detection layers of ARIES, it activates appropriate firewall rules to mitigate timely the potential intrusions.…”
Section: Aries Architecturementioning
confidence: 99%
“…The Response Module receives the output of the ARIES Analysis Engine and generates security events based on the AlienVault Open Source SIEM (OSSIM) [ 49 , 50 ] format. Moreover, based on the information originating from the three detection layers of ARIES, it activates appropriate firewall rules to mitigate timely the potential intrusions.…”
Section: Aries Architecturementioning
confidence: 99%
“…SIEM System. The KONFIDO SIEM will extend some existing SIEM solutions [3,4], and customize them based on the specific requirements of a federated environment compliant to the OpenNCP model. The KONFIDO SIEM will be able to analyse information and events collected using a holistic approach at the different levels of the monitored system to discover possible ongoing attacks, or anomalous situations.…”
Section: Puf-based Random Number Generatormentioning
confidence: 99%
“…Both types of collectors execute format translation tasks, but do not perform content analysis and advanced data manipulation such as aggregation, filtering, correlation, anonymization and content-based encryption. Coppolino, et al [7] have demonstrated that the OSSIM SIEM system can be used to protect critical infrastructures in a non-intrusive manner (i.e., without modifying SIEM framework components). They also show how to process physical layer data on the OSSIM server.…”
Section: Related Workmentioning
confidence: 99%