Please use this identifier to cite or link to this item: http://hdl.handle.net/10662/20390
Title: New approach for threat classification and security risk estimations based on security event management
Authors: Sancho Núñez, José Carlos
Caro Lindo, Andrés
Ávila Vegas, María del Mar
Bravo Gómez, Alberto
Keywords: SIEM;SIEM;Ciberseguridad;Cybersecurity;STRIDE;STRIDE;Extracción de conocimiento;Knowledge extraction;Bug bar;Bug bar;Tratamiento de datos;Data processing
Issue Date: 2020
Publisher: Elsevier
Abstract: Security Information and Event Management (SIEM) systems are essential for identifying cyber attacks, being an extended practice in organizations to detect threats, vulnerabilities and to estimate security risks. The management of events and information related to security is done through systems that provide all the information, processing different data sources. The developing of alternative models that provide complementary information to commercial solutions, based on the same data sources, is presented as a novel and interesting challenge, not only for organizations, but also for the scientific community. This paper presents a new system to classify security threats, computing their criticality according to the Bug Bar technique, with the aim of addressing threats in order of priority. High correlations were achieved between severity risk values achieved from commercial systems and results computed by the new approach. Accordingly, the new proposal could complement the information of SIEM systems, and help in the prediction of criticalities of future threats.
URI: http://hdl.handle.net/10662/20390
Appears in Collections:DISIT - Artículos

Files in This Item:
File Description SizeFormat 
1-s2.0-S0167739X20301849-main.pdf
???org.dspace.app.webui.jsptag.ItemTag.accessRestricted???
1,66 MBAdobe PDFView/Open    Request a copy


This item is licensed under a Creative Commons License Creative Commons