Challenges for Systems of Systems Security Information and Event Management

Roland Rieke · 2010

Security Information and Event Management (SIEM) is a key concept to identify security threats and mitigate their impact. Problems encountered by managed security service providers which cannot be adequately addressed by current SIEM solutions comprise insufficient resilience to withstand large scale attacks, inadequate trustworthiness of source data and inadequate disaster recovery capabilities. Furthermore, many current solutions are not able to consider and correlate events from multiple sources originating from different infrastructures and domains. A typical constraint of such systems is the restriction of SIEM to network infrastructure events, and therefore missing awareness of attacks that exploit complex interrelations between events on different layers such as physical events (e.g. access to buildings), application level events (e.g. financial transactions), business application monitoring, events in service oriented architectures or events on interfaces to cloud computing applications. Future multi-domain SIEM systems will additionally face new large-scale ICT dependent infrastructures deployed in sectors currently not vulnerable to Internet threats. Examples are new service infrastructures in the e-health sector, smart grids for intelligent power distribution, vehicular ad hoc networks, event-processing infrastructures for the Internet of things. The following approach addresses these challenges.

Read the paper · More papers on PaperTik