错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Utilization of Artificial Intelligence for the SIEM Logging Architecture Design in the Context of Smart City

  • Lubomir Almer,
  • Josef Horalek,
  • Vladimir Sobeslav

摘要

Smart city is an important concept that is gradually establishing in the everyday life of citizens. However, the integration of this concept brings a number of challenges in the area of cybersecurity. One of the key challenges faced by smart cities is the secure management of the big amount of data generated by various interconnected devices and systems. The complexity of managing and analyzing the enormous volume of log data generated by various systems and devices represents a security challenge. Security Information and Event Management systems (SIEMs) are used for effective processing and correlation of logs from multiple sources in real time. However, the key problem remains how to design efficient logging architecture, which includes, for example, the choice of security information source types, their data representation or parsing, and finally, their introduction into the context of a security event or incident. Designing a logging architecture is an expert activity that usually uses best practice based on the security baseline of common IT systems. The question is how to support the design of logging architecture with an emphasis on the specifics of technologies used in the smart city concept. With the development of artificial intelligence methods, the possibility of supporting the entire design process with AI tools opens. The aim of this article is to analyze the possibilities for simplifying the design process of the logging architecture in SIEM systems with an emphasis on the specifics of the smart city concept while simultaneously using artificial intelligence tools.