Security Information and Event Management System

Security Information and Event Management System


Security information and event management (SIEM) combines security information management (SIM) and security event management (SEM) functions into one security management system. SIEM collects relevant data about an enterprise's security posture in multiple locations and analyzes all the data from a single point of view, providing the capability to spot trends and patterns that may be the result of malicious activity.

The SIEM system complements intrusion detection and prevention systems (IDPS) by correlating events logged by different technologies, displaying data from many event sources, and providing supporting information from other sources to help administrators verify the accuracy of alerts. SIEM data is usually recorded locally and sent to separate systems, such as centralized logging servers and the master SIEM system.

Advanced SIEM systems correlate event, threat, and risk information to detect attacks, possibly in realtime, and support forensic investigations and produce compliance reports as a result of activity monitoring.

Figure 1 - An example of a SIEM architecture.

Figure 1 shows a SIEM architecture providing for log collection, analysis and forensics, event correlation, and IT compliance evidence for auditing and monitoring. Local SEM sensors located within the organization’s networks collect and forward events to a master SIEM.

Related Patterns:

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值