Cybersecurity Unit, Atos Research & Innovation, ATOS Spain, 28037 Madrid, Spain.
Sensors (Basel). 2021 Jul 12;21(14):4759. doi: 10.3390/s21144759.
Security Information and Event Management (SIEM) systems have been widely deployed as a powerful tool to prevent, detect, and react against cyber-attacks. SIEM solutions have evolved to become comprehensive systems that provide a wide visibility to identify areas of high risks and proactively focus on mitigation strategies aiming at reducing costs and time for incident response. Currently, SIEM systems and related solutions are slowly converging with big data analytics tools. We survey the most widely used SIEMs regarding their critical functionality and provide an analysis of external factors affecting the SIEM landscape in mid and long-term. A list of potential enhancements for the next generation of SIEMs is provided as part of the review of existing solutions as well as an analysis on their benefits and usage in critical infrastructures.
安全信息和事件管理 (SIEM) 系统已被广泛部署为一种强大的工具,用于预防、检测和应对网络攻击。SIEM 解决方案已经发展成为全面的系统,提供广泛的可见性,以识别高风险领域,并积极关注缓解策略,旨在降低事件响应的成本和时间。目前,SIEM 系统和相关解决方案正在与大数据分析工具缓慢融合。我们调查了最广泛使用的 SIEM,了解其关键功能,并对中长期影响 SIEM 格局的外部因素进行了分析。作为对现有解决方案的审查的一部分,提供了下一代 SIEM 的潜在增强功能列表,并对其在关键基础设施中的收益和使用进行了分析。