A Dangerousness-Based Investigation Model for Security Event Management - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2008

A Dangerousness-Based Investigation Model for Security Event Management

Radu State
  • Fonction : Auteur
  • PersonId : 830456
Luc Paffumi
  • Fonction : Auteur

Résumé

The current landscape of security management solutions for large scale networks is limited by the lack of supporting approaches capable to deal with the huge number of alarms and events that are generated on current networks. In this paper we propose a security management architecture, capable to reconstruct causal dependencies from captured network and service alarms. The key idea is based on mapping events in semantic spaces, where a novel algorithm can determine such dependencies. We have implemented a prototype and tested it on a operational network within an outsourced security management suite protecting multiple networks.
Fichier non déposé

Dates et versions

hal-00405369 , version 1 (20-07-2009)

Identifiants

  • HAL Id : hal-00405369 , version 1

Citer

Veronique Legrand, Radu State, Luc Paffumi. A Dangerousness-Based Investigation Model for Security Event Management. The Third International Conference on Internet Monitoring and Protection, Jun 2008, Bucharest, Romania. pp.109 - 118. ⟨hal-00405369⟩
243 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More