2 Days Left to Save $350 on SANS Virginia Beach 2008! >> More Info
the most trusted source for computer security training, certification and research


A Practical Application of SIM/SEM/SIEM Automating Threat Identification

Click Here
Abstract
The goal of this paper is to explain how to use a SIEM effectively to identify and respond to security threats. The paper begins with level set information including definitions, capabilities requirements, architecture and a business case. Later I will cover aggregation and correlation design concepts, with real world examples including architectural design, risk based profiling, finite state engines, and merging traditional network operations data into security operations tools for improved detection.
<<Reading Room Home     <<Back to Category

Contact us: (301) 654-SANS(7267)
Monday - Friday 9am-8pm EST/EDT