Singapore boffins get diverse SIEMs singing in harmony
Vendors all use different formats. This tech translates them all so you can smooth your SOC
Academics from Singapore and China have found a way to make AI useful for cyber-defenders, by creating a technique that translates rules from diverse Security Information and Event Managements (SIEMs) so they’re easier to consume across multiple systems.
SIEMs collect log files from many sources and allow users to set rules that trigger alerts that a security operations center (SOC) considers in case they represent security incidents. Testing for an “impossible travel” scenario – in which the same user logs on from New York and London within an hour, suggesting credential theft or other skulduggery – is a common SIEM rule.
Many organizations end up with multiple SIEMs, which means complexity for SOCs.
Enter researchers from the National University of Singapore and China’s Fudan University, who recently presented a paper[PDF] titled “ARuleCon: Agentic...
Copyright of this story solely belongs to theregister.com. To see the full text click HERE