作者: Luigi Coppolino , Salvatore D’Antonio , Valerio Formicola , Luigi Romano , None
DOI: 10.1007/978-3-642-24270-0_15
关键词:
摘要: In recent years the monitoring and control devices in charge of supervising critical processes Critical Infrastructures have been victims cyber attacks. To face such threat, organizations providing services are increasingly focusing on protecting their network infrastructures. Security Information Event Management (SIEM) frameworks support protection by performing centralized correlation asset reports. this work we propose an extension a commercial SIEM framework, namely OSSIM AlienVault, to perform analysis reports (events) generated monitoring, security dam infrastructure. Our objective is obtain evidences misuses malicious activities occurring at system, since they can result issuing hazardous commands devices. We present examples procedures extend for analyzing new event types.