错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Layer 4: Security Information and Event Management (SIEM)—Real-Time Threat Intelligence

  • Hassan Jalil Hadi,
  • Muhammad Khurram Khan,
  • Naveed Ahmad,
  • Rehana Yasmin

摘要

The increasing incidence of cyber threats highlights the necessity for stringent security protocols to protect essential assets and information in the contemporary digital environment. Small and Medium Enterprises (SMEs), essential to the global economy, are especially susceptible due to constrained resources, insufficient data protection measures, and a deficiency of specialist cybersecurity knowledge. Security Information and Event Management (SIEM) systems are essential for the monitoring, detection, and response to security incidents. Recent improvements, especially the incorporation of real-time threat information into SIEM platforms, have markedly improved their capacity to detect complex assaults, correlate Indicators of Compromise (IoCs), and prioritize high-risk events. Although proprietary SIEM solutions have historically prevailed in the market, open-source alternatives are increasingly gaining traction because to their cost-effectiveness, adaptability, and accessibility, rendering them particularly appealing to small and medium-sized enterprises. This chapter provides an in-depth examination of open-source SIEM solutions, emphasizing the integration of threat intelligence. The study assesses their efficacy in tackling contemporary security difficulties, maintaining regulatory adherence, and enhancing detection precision via augmented intelligence feeds. The research also examines performance aspects, including resource utilization, correlation accuracy, and real-time data management, inside simulated SME-scale network systems. The results offer significant insights into the advantages and drawbacks of open-source SIEM platforms, assisting decision-makers in choosing appropriate solutions that enhance SME cybersecurity while ensuring cost efficiency.