Yüksek LisansAçık Erişim

Writing security information and event management (SIEM)/log correlation rules

2021
0 görüntülenme
0 i̇ndirme
Danışman: Doç. Dr. Şengül Doğan

Özet (EN)

Intrusion detection systems aim to detect attacks against computer systems and networks or information systems in general. Today, one of the most critical problems in terms of information security is to detect cyber attacks. Since computers connected to internet networks create an environment that is susceptible to exploitation, they prepare the environment for various confidential information to be exposed and damaged. Due to these reasons, information security must detect cyber attacks that may be carried out against the importants datas of the institutions and take precautions against such attacks. Although many institutions are aware of this issue, they establish their own Cyber Security Operations Centers. Institutions with this mindset have SIEM products, and through the written correlation rules; attack activities, suspicious activities, and anomalies can be detected beforehand. In this study, the formats of the logs (trace records) taken from various security devices, operating systems, network systems, and web application servers are investigated. By combining the received logs in a SIEM product, sample correlation rules are written to detect anomalies. These rules can detect intrusions in web applications or abnormalities in the operating system category. Keywords: Log, Correlation rules, SIEM

Yazar

Dilek Gökçeoğlu

Bu Yayına Nasıl Atıf Yapılır

Dilek Gökçeoğlu (Master Thesis). Writing security information and event management (SIEM)/log correlation rules, 2021, Fırat University.

Lisans

Tüm Hakları Saklıdır

Bu eser belirtilen lisans koşulları altında paylaşılmaktadır.

Fırat University tezlerinden daha fazlası