Efficient event analysis and management with data center layered security design
2020
0 views
0 downloads
Advisor: Doç. Dr. Mustafa Yağcı
Abstract (EN)
With the development of computer communication and network technologies, the variety of cyber attacks has increased and different security problems have emerged. Against these problems, the importance of the concept of information security has increased. Institutions use various security products to ensure the security of information. The purpose of the security products used in the institutions is to ensure the confidentiality of unauthorized access while the information is processed, transported or stored, to protect its integrity against corruption, alteration or deletion, and to provide accessibility in order to be able to access and use the required information in the required time. Security products record users' access, system and security incidents to comply with legal reasons or standards so that the problem can be detected during a problem (cyber threats, incorrect configuration changes, system failure, etc.). Keeping these records alone is not enough for today due to the increasing variety of cyber attacks. In order to combat cyber incidents, to detect anomaly events within systems, to take precautions before cyber incident, these event records (log) should be analyzed. Critical data centers contain many security (firewall, threat prevention system etc.), network (switch, router etc.) and application (database, web server etc. application servers) devices for storing, processing and protecting critical information. These devices produce numerous logs every day. If these logs are not collected at a central point, its management will be very difficult and will extend the duration of the solution during a problem. Collecting logs alone is of course not enough. Logs from each source should be analyzed well in situations such as pre-attack detection, solution of the system problem. With SIEM (Security Information and Event Management), when collecting daily data from multiple sources and analyzing them, a holistic perspective can be gained in the information security approach. Thanks to the capabilities of SIEM solutions such as correlation, reporting and log collection, logs are collected in order to comply with laws and standards, and it is provided to understand how threats, cyber attacks, system events, IT (Information Technologies) components face in systems. In this study, it is aimed to provide maximum benefit in SIEM management in data centers with critical infrastructure with SIEM. In this regard, topics such as sample security design and suggestions, examples of effective correlations, attention to SIEM project processes were addressed, and this study was supported by a government agency data center sample application.
Author
Ali Akpınar
Institution
How to Cite
Ali Akpınar (Master Thesis). Efficient event analysis and management with data center layered security design, 2020, Kırşehir Ahi Evran University.
Keywords
License
Tüm Hakları Saklıdır
This work is shared under the specified license terms.
More theses from Kırşehir Ahi Evran University
- In teaching of mathematical concept, the effect of storyline method on attitude and success(2013)
- Jean-Jacques Rousseau's thoughts on life science and education in his Work "emile"(2019)
- The effect of pre-breeding weights and placental characteristics on birth weight in Karayaka sheeps(2020)
- H. 1301 (M. 1884) in light of the yearbook dated hejaz province during the reign of Abdulhamid II (History and geography, social-cultural, economic, administrative-military structure)(2020)
- Proteinurin in diabetic patients effect on mortality(2022)
- Wind energy forecasting methods: A case study of the long short term memory model (LSTM)(2024)
