Модель ризик-орієнтованого ранжування інцидентів інформаційної безпеки на основі правила-орієнтованої кореляції подій
Анотації
У дослідженні розглянуто підхід до виявлення та ранжування інцидентів інформаційної безпеки на основі нормалізації журналів подій, правила-орієнтованої кореляції подій і ризик-орієнтованого оцінювання. This study examines a model for detecting and ranking information security incidents based on event log normalization, rule-oriented correlation, and risk-oriented assessment. The relevance of the study is due to the growing number of security incidents in information systems and the need for automated determination of their criticality for timely response. The proposed approach involves receiving events from agents, normalizing Windows Security and
URI:
https://ir.lib.vntu.edu.ua/handle/123456789/53963

