School of Computer Science, University of Galway, Galway, Ireland.
National Center for Cyber Security, Islamabad, Pakistan.
PLoS One. 2024 Mar 28;19(3):e0301183. doi: 10.1371/journal.pone.0301183. eCollection 2024.
The proliferation of cyber threats necessitates robust security measures to safeguard critical assets and data in today's evolving digital landscape. Small and Medium Enterprises (SMEs), which are the backbone of the global economy are particularly vulnerable to these threats due to inadequate protection for critical and sensitive information, budgetary constraints, and lack of cybersecurity expertise and personnel. Security Information and Event Management (SIEM) systems have emerged as pivotal tools for monitoring, detecting, and responding to security incidents. While proprietary SIEM solutions have historically dominated the market, open-source SIEM systems have gained prominence for their accessibility and cost-effectiveness for SMEs. This article presents a comprehensive study focusing on the evaluation of open-source SIEM systems. The research investigates the capabilities of these open-source solutions in addressing modern security challenges and compliance with regulatory requirements. Performance aspects are explored through empirical testing in simulated enterprise-grade SME network environments to assess resource utilization, and real-time data processing capabilities. By providing a rigorous assessment of the security and performance features of open-source SIEM systems, this research offers valuable insights to cybersecurity practitioners, organizations seeking cost-effective security solutions, and the broader academic community. The findings shed light on the strengths and limitations of these systems, aiding decision-makers in selecting the most suitable SIEM solution for their specific requirements while enhancing the cybersecurity posture of SMEs.
网络威胁的泛滥使得在当今不断发展的数字环境中,必须采取强有力的安全措施来保护关键资产和数据。中小企业(SMEs)是全球经济的支柱,但由于对关键和敏感信息的保护不足、预算限制以及缺乏网络安全专业知识和人员,它们特别容易受到这些威胁的影响。安全信息和事件管理(SIEM)系统已成为监控、检测和应对安全事件的关键工具。虽然专有 SIEM 解决方案在历史上占据主导地位,但开源 SIEM 系统因其可访问性和对中小企业的成本效益而受到关注。本文对开源 SIEM 系统进行了全面研究,重点评估了这些系统应对现代安全挑战和符合法规要求的能力。通过在模拟的企业级中小企业网络环境中进行实证测试,研究了这些开源解决方案的性能方面,评估了资源利用和实时数据处理能力。通过对开源 SIEM 系统的安全性和性能特性进行严格评估,本研究为网络安全从业者、寻求具有成本效益的安全解决方案的组织以及更广泛的学术界提供了有价值的见解。研究结果揭示了这些系统的优缺点,帮助决策者根据自身特定需求选择最合适的 SIEM 解决方案,同时增强中小企业的网络安全态势。