Yayınlanmış 1 Ocak 2015 | Sürüm v1
Konferans bildirisi Açık

Simple Event Correlator - Best Practices for Creating Scalable Configurations

  • 1. Tallinn Univ Technol, Dept Comp Sci, Tallinn, Estonia
  • 2. TUBITAK, Cyber Secur Inst, Kocaeli, Turkey

Açıklama

During the past two decades, event correlation has emerged as a prominent monitoring technique, and is essential for achieving better situational awareness. Since its introduction in 2001 by one of the authors of this paper, Simple Event Correlator (SEC) has become a widely used open source event correlation tool. During the last decade, a number of papers have been published that describe the use of SEC in various environments. However, recent SEC versions have introduced a number of novel features not discussed in existing works. This paper fills this gap and provides an up-to-date coverage of best practices for creating scalable SEC configurations.

Dosyalar

bib-b56d3ea8-479b-4151-8276-64ff1baa77d5.txt

Dosyalar (258 Bytes)

Ad Boyut Hepisini indir
md5:a7897f8019af550fa95de175bbf3fa6b
258 Bytes Ön İzleme İndir