Log collection and SIEM for 5G SOC
Miklós Orsós, Miklos Vilmos Kecskes, Eszter Kail, Anna Bánáti · 2022
Today, cyber-attacks are becoming more commonplace, more complex and sophisticated every year, bypassing or remaining hidden from traditional defensive tools (such as firewall, IDS/IPS and other malware detection tools). As a consequence, centralized methods with increasingly sophisticated and comprehensive analytical capabilities are also required on the defense side. With the advent of 5G technology, the problem is even more acute and crucial, as these devices and networks have changed significantly in number and diversity, leaving behind the development and widespread deployment of security solutions. The Security Operation Center (SOC) used in traditional systems provides the necessary complexity and analytical capabilities, but in the case of 5G networks, its methodology is far from the developed techniques and tools, moreover, its applicability still poses many challenges.Our goal is to develop a SOC methodology, focusing primarily on the collection, storage, and visualization of log data originated from 5G end devices and the Radio Access Network (RAN) part of the 5G architecture since this can be the basis for a comprehensive analysis and deployment of a SIEM system in 5G networks in our future research.