• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

预算有限的网络安全:评估开源 SIEM 解决方案在中小企业中的安全性和性能。

Cybersecurity on a budget: Evaluating security and performance of open-source SIEM solutions for SMEs.

机构信息

School of Computer Science, University of Galway, Galway, Ireland.

National Center for Cyber Security, Islamabad, Pakistan.

出版信息

PLoS One. 2024 Mar 28;19(3):e0301183. doi: 10.1371/journal.pone.0301183. eCollection 2024.

DOI:10.1371/journal.pone.0301183
PMID:38547149
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC10977669/
Abstract

The proliferation of cyber threats necessitates robust security measures to safeguard critical assets and data in today's evolving digital landscape. Small and Medium Enterprises (SMEs), which are the backbone of the global economy are particularly vulnerable to these threats due to inadequate protection for critical and sensitive information, budgetary constraints, and lack of cybersecurity expertise and personnel. Security Information and Event Management (SIEM) systems have emerged as pivotal tools for monitoring, detecting, and responding to security incidents. While proprietary SIEM solutions have historically dominated the market, open-source SIEM systems have gained prominence for their accessibility and cost-effectiveness for SMEs. This article presents a comprehensive study focusing on the evaluation of open-source SIEM systems. The research investigates the capabilities of these open-source solutions in addressing modern security challenges and compliance with regulatory requirements. Performance aspects are explored through empirical testing in simulated enterprise-grade SME network environments to assess resource utilization, and real-time data processing capabilities. By providing a rigorous assessment of the security and performance features of open-source SIEM systems, this research offers valuable insights to cybersecurity practitioners, organizations seeking cost-effective security solutions, and the broader academic community. The findings shed light on the strengths and limitations of these systems, aiding decision-makers in selecting the most suitable SIEM solution for their specific requirements while enhancing the cybersecurity posture of SMEs.

摘要

网络威胁的泛滥使得在当今不断发展的数字环境中,必须采取强有力的安全措施来保护关键资产和数据。中小企业(SMEs)是全球经济的支柱,但由于对关键和敏感信息的保护不足、预算限制以及缺乏网络安全专业知识和人员,它们特别容易受到这些威胁的影响。安全信息和事件管理(SIEM)系统已成为监控、检测和应对安全事件的关键工具。虽然专有 SIEM 解决方案在历史上占据主导地位,但开源 SIEM 系统因其可访问性和对中小企业的成本效益而受到关注。本文对开源 SIEM 系统进行了全面研究,重点评估了这些系统应对现代安全挑战和符合法规要求的能力。通过在模拟的企业级中小企业网络环境中进行实证测试,研究了这些开源解决方案的性能方面,评估了资源利用和实时数据处理能力。通过对开源 SIEM 系统的安全性和性能特性进行严格评估,本研究为网络安全从业者、寻求具有成本效益的安全解决方案的组织以及更广泛的学术界提供了有价值的见解。研究结果揭示了这些系统的优缺点,帮助决策者根据自身特定需求选择最合适的 SIEM 解决方案,同时增强中小企业的网络安全态势。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/b264/10977669/9d50dd993310/pone.0301183.g004.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/b264/10977669/585fd0010052/pone.0301183.g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/b264/10977669/cfc8acf1385d/pone.0301183.g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/b264/10977669/d35e98b55f1f/pone.0301183.g003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/b264/10977669/9d50dd993310/pone.0301183.g004.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/b264/10977669/585fd0010052/pone.0301183.g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/b264/10977669/cfc8acf1385d/pone.0301183.g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/b264/10977669/d35e98b55f1f/pone.0301183.g003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/b264/10977669/9d50dd993310/pone.0301183.g004.jpg

相似文献

1
Cybersecurity on a budget: Evaluating security and performance of open-source SIEM solutions for SMEs.预算有限的网络安全:评估开源 SIEM 解决方案在中小企业中的安全性和性能。
PLoS One. 2024 Mar 28;19(3):e0301183. doi: 10.1371/journal.pone.0301183. eCollection 2024.
2
Security Information and Event Management (SIEM): Analysis, Trends, and Usage in Critical Infrastructures.安全信息和事件管理 (SIEM):关键基础设施中的分析、趋势和使用。
Sensors (Basel). 2021 Jul 12;21(14):4759. doi: 10.3390/s21144759.
3
We need to aim at the top: Factors associated with cybersecurity awareness of cyber and information security decision-makers.我们需要瞄准高端:与网络和信息安全决策者的网络安全意识相关的因素。
PLoS One. 2024 Oct 18;19(10):e0312266. doi: 10.1371/journal.pone.0312266. eCollection 2024.
4
Enhancing Cyber-Resilience for Small and Medium-Sized Organizations with Prescriptive Malware Analysis, Detection and Response.通过规范性恶意软件分析、检测和响应增强中小型组织的网络弹性。
Sensors (Basel). 2023 Jul 28;23(15):6757. doi: 10.3390/s23156757.
5
Cyber risk assessment in small and medium-sized enterprises: A multilevel decision-making approach for small e-tailors.中小企业的网络风险评估:小型电子零售商的多层次决策方法
Risk Anal. 2023 Oct;43(10):2082-2098. doi: 10.1111/risa.14092. Epub 2023 Jan 10.
6
Cybersecurity Enterprises Policies: A Comparative Study.网络安全企业政策:比较研究。
Sensors (Basel). 2022 Jan 11;22(2):538. doi: 10.3390/s22020538.
7
Emerging Trends in Cybersecurity: A Holistic View on Current Threats, Assessing Solutions, and Pioneering New Frontiers.网络安全的新兴趋势:对当前威胁的全面审视、评估解决方案以及开拓新领域。
Blockchain Healthc Today. 2024 Apr 30;7. doi: 10.30953/bhty.v7.302. eCollection 2024.
8
DNA encoding schemes herald a new age in cybersecurity for safeguarding digital assets.DNA 编码方案为保护数字资产的网络安全开创了一个新时代。
Sci Rep. 2024 Jun 15;14(1):13839. doi: 10.1038/s41598-024-64419-4.
9
Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study.网络卫生方法在提高医疗机构网络安全和数据隐私意识中的应用:概念研究。
J Med Internet Res. 2023 Jul 27;25:e41294. doi: 10.2196/41294.
10
Selecting a Passive Network Monitoring Solution for Medical Device Cybersecurity Management.为医疗设备网络安全管理选择被动式网络监控解决方案。
Biomed Instrum Technol. 2021 Nov 1;55(4):121-130. doi: 10.2345/0899-8205-55.4.121.

引用本文的文献

1
Intelligent penetration testing method for power internet of things systems combining ontology knowledge and reinforcement learning.结合本体知识和强化学习的电力物联网系统智能渗透测试方法
PLoS One. 2025 May 28;20(5):e0323357. doi: 10.1371/journal.pone.0323357. eCollection 2025.
2
Security Risk Assessment for Patient Portals of Hospitals: A Case Study of Taiwan.医院患者门户网站的安全风险评估:以台湾地区为例
Risk Manag Healthc Policy. 2024 Jun 18;17:1647-1656. doi: 10.2147/RMHP.S463408. eCollection 2024.

本文引用的文献

1
Security Information and Event Management (SIEM): Analysis, Trends, and Usage in Critical Infrastructures.安全信息和事件管理 (SIEM):关键基础设施中的分析、趋势和使用。
Sensors (Basel). 2021 Jul 12;21(14):4759. doi: 10.3390/s21144759.
2
BlockSIEM: Protecting Smart City Services through a Blockchain-based and Distributed SIEM.BlockSIEM:通过基于区块链的分布式 SIEM 保护智慧城市服务。
Sensors (Basel). 2020 Aug 18;20(16):4636. doi: 10.3390/s20164636.