Autors: Nenova, M. V., Iliev, G. L., Hristov M., Avresky D.
Title: Integration of Splunk Enterprise SIEM for DDoS Attack Detection in IoT
Keywords: SIEM , real-time alert , OSINT , IoT

Abstract: Nowadays Security Information and Event Management (SIEM) is a common element of the security stack of every big and medium size company. The SIEM is becoming a vital part of the defense strategy along with firewalls, network Intrusion Prevention System / Intrusion Detection System (IPS/IDS), web/mail security appliances, and Antivirus (AV) solutions. Therefore this paper aims to propose a solution for improving the security posture of an organization by implementing Splunk Enterprise SIEM. The monitoring of various systems in real-time could be a challenge for the security analysts in the Security Operation Center (SOC). With the use of Splunk, all relevant logs are collected and stored in one instance which allows the designing of a “single pane of glass” solution. To illustrate the capabilities of the Splunk Enterprise SIEM, the proposed solution has four real-time alerts for detection of different cases of suspicious and/or malicious activity. One of them is specifically designed



    2021 IEEE 20th International Symposium on Network Computing and Applications (NCA), 2021, United States, IEEE, DOI 10.1109/NCA53618.2021.9685977

    Copyright IEEE

    Цитирания (Citation/s):
    1. M. Selvaganesh, P. Naveen Karthi, V. A. Nitish Kumar and S. R. Prashanna Moorthy, "Efficient Brute-force handling methodology using Indexed-Cluster Architecture of Splunk," 2022 International Conference on Electronics and Renewable Systems (ICEARS), 2022, pp. 697-701, doi: 10.1109/ICEARS53579.2022.9752323. - 2022 - в издания, индексирани в Scopus или Web of Science

    Вид: публикация в международен форум, публикация в реферирано издание, индексирана в Scopus