Identificador persistente para citar o vincular este elemento: http://hdl.handle.net/10662/20390
Títulos: New approach for threat classification and security risk estimations based on security event management
Autores/as: Sancho Núñez, José Carlos
Caro Lindo, Andrés
Ávila Vegas, María del Mar
Bravo Gómez, Alberto
Palabras clave: SIEM;SIEM;Ciberseguridad;Cybersecurity;STRIDE;STRIDE;Extracción de conocimiento;Knowledge extraction;Bug bar;Bug bar;Tratamiento de datos;Data processing
Fecha de publicación: 2020
Editor/a: Elsevier
Resumen: Security Information and Event Management (SIEM) systems are essential for identifying cyber attacks, being an extended practice in organizations to detect threats, vulnerabilities and to estimate security risks. The management of events and information related to security is done through systems that provide all the information, processing different data sources. The developing of alternative models that provide complementary information to commercial solutions, based on the same data sources, is presented as a novel and interesting challenge, not only for organizations, but also for the scientific community. This paper presents a new system to classify security threats, computing their criticality according to the Bug Bar technique, with the aim of addressing threats in order of priority. High correlations were achieved between severity risk values achieved from commercial systems and results computed by the new approach. Accordingly, the new proposal could complement the information of SIEM systems, and help in the prediction of criticalities of future threats.
URI: http://hdl.handle.net/10662/20390
Colección:DISIT - Artículos

Archivos
Archivo Descripción TamañoFormato 
1-s2.0-S0167739X20301849-main.pdf
???org.dspace.app.webui.jsptag.ItemTag.accessRestricted???
1,66 MBAdobe PDFDescargar    Pide una copia


Este elemento está sujeto a una licencia Licencia Creative Commons Creative Commons