Talk With an Expert

A Framework to Collect Security Events for Intrusion Analysis

A Framework to Collect Security Events for Intrusion Analysis (PDF, 3.11MB)Published: 03 Apr, 2006
Created by:
Jim Chrisos

It becomes a problem when you have several firewalls, intrusion sensors or servers and to top it off, not all firewalls and intrusion sensors generate logs in a standard format. This means you may need several tools to analyze data maybe even one tool per each device per vendor. This can be a mess. This paper assumes you need a way to consolidate event logs from these devices and present them to the people who are chartered to analyze and take action wn an efficient manner.