Master'sOpen Access

Writing security information and event management (SIEM)/log correlation rules

2021
0 views
0 downloads
Advisor: Doç. Dr. Şengül Doğan

Abstract (EN)

Intrusion detection systems aim to detect attacks against computer systems and networks or information systems in general. Today, one of the most critical problems in terms of information security is to detect cyber attacks. Since computers connected to internet networks create an environment that is susceptible to exploitation, they prepare the environment for various confidential information to be exposed and damaged. Due to these reasons, information security must detect cyber attacks that may be carried out against the importants datas of the institutions and take precautions against such attacks. Although many institutions are aware of this issue, they establish their own Cyber Security Operations Centers. Institutions with this mindset have SIEM products, and through the written correlation rules; attack activities, suspicious activities, and anomalies can be detected beforehand. In this study, the formats of the logs (trace records) taken from various security devices, operating systems, network systems, and web application servers are investigated. By combining the received logs in a SIEM product, sample correlation rules are written to detect anomalies. These rules can detect intrusions in web applications or abnormalities in the operating system category. Keywords: Log, Correlation rules, SIEM

Author

Dilek Gökçeoğlu

How to Cite

Dilek Gökçeoğlu (Master Thesis). Writing security information and event management (SIEM)/log correlation rules, 2021, Fırat University.

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Fırat University