Integration of a system for critical infrastructure protection with the OSSIM SIEM platform: a dam case study

作者: Luigi Coppolino , Salvatore D’Antonio , Valerio Formicola , Luigi Romano , None

DOI: 10.1007/978-3-642-24270-0_15

关键词:

摘要: In recent years the monitoring and control devices in charge of supervising critical processes Critical Infrastructures have been victims cyber attacks. To face such threat, organizations providing services are increasingly focusing on protecting their network infrastructures. Security Information Event Management (SIEM) frameworks support protection by performing centralized correlation asset reports. this work we propose an extension a commercial SIEM framework, namely OSSIM AlienVault, to perform analysis reports (events) generated monitoring, security dam infrastructure. Our objective is obtain evidences misuses malicious activities occurring at system, since they can result issuing hazardous commands devices. We present examples procedures extend for analyzing new event types.

参考文章(5)
Fátima Farinha, Eliane Portela, Cristina Domingues, Luís Sousa, Knowledge-based systems in civil engineering: Three case studies Advances in Engineering Software. ,vol. 36, pp. 729- 739 ,(2005) , 10.1016/J.ADVENGSOFT.2005.03.019
Linda Briesemeister, Steven Cheung, Ulf Lindqvist, Alfonso Valdes, Detection, correlation, and visualization of attacks against critical infrastructure systems conference on privacy, security and trust. pp. 15- 22 ,(2010) , 10.1109/PST.2010.5593242
Jesung Jeon, Jongwook Lee, Donghoon Shin, Hangyu Park, Development of dam safety management system Advances in Engineering Software. ,vol. 40, pp. 554- 563 ,(2009) , 10.1016/J.ADVENGSOFT.2008.10.009
François Ingelrest, Guillermo Barrenetxea, Gunnar Schaefer, Martin Vetterli, Olivier Couach, Marc Parlange, SensorScope ACM Transactions on Sensor Networks. ,vol. 6, pp. 1- 32 ,(2010) , 10.1145/1689239.1689247
Juan Manuel Madrid, Luis Eduardo Munera, Carlos Andrey Montoya, Juan David Osorio, Luis Ernesto Cardenas, Rodrigo Bedoya, Cristian Latorre, None, Functionality, reliability and adaptability improvements to the OSSIM information security console ieee latin-american conference on communications. pp. 1- 6 ,(2009) , 10.1109/LATINCOM.2009.5305052