错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Software System for Cybersecurity Events Correlation and Incident Management in Critical Infrastructure

  • Sergiy Gnatyuk,
  • Rat Berdibayev,
  • Marek Aleksander,
  • Viktoriia Sydorenko,
  • Oksana Zhyharevych,
  • Artem Polozhentsev

摘要

The current information infrastructure, with its diverse systems and components, demands continuous monitoring and management to detect and respond to potential cyber threats. To mitigate these risks, the deployment of a unified standard system, known as a Security Information and Event Management (SIEM) system, is recommended. This technology, which collects event log data, conducts real-time analysis to identify unusual activity, recognizes potential threats, generates alerts, and suggests appropriate action plans, has seen significant improvements in both quantity and quality due to advancements in artificial intelligence, the Internet of Things, and cloud technologies. These advancements enable the rapid and effective detection of threats. This study focuses on contemporary SIEM systems, exploring their functionality, fundamental operational principles, and conducting a comparative analysis of their capabilities, distinctions, benefits, and drawbacks. Additionally, the study developed and experimentally investigated a universal system for event correlation and cybersecurity incident management in critical infrastructure facilities. The study also introduced hybrid security data storage models that allow the indexing service to access external data storage, scale with increasing data volume, and ensure high search speed. Furthermore, the study developed models, methods, and algorithms for operating a distributed data bus that allows high-speed processing of large information flows, minimal latency, high resilience to failures, and flexibility. The proposed system plays a crucial role in addressing numerous cybersecurity issues and aligns with the main requirements of international standards and global best practices for creating cyber incident management systems.