DESIGN AND IMPLEMENTATION OF A SITUATIONAL AWARENESS SYSTEM BASED ON MULTI-SOURCE SECURITY LOG ANALYSIS
Fu Bin, V.V. Sarnatskyi · Scientific notes of Taurida National V I Vernadsky University Series Technical Sciences · 2024
The article is dedicated to the design and implementation of an innovative situational awareness system based on multi-source security log analysis, aimed at small and medium-sized enterprises (SMEs) facing cybersecurity challenges.It is revealed that SMEs, due to limited resources and lack of specialized security personnel, are particularly vulnerable to evolving cyber threats.The article presents a system that integrates log data from multiple security sources within the network, such as firewalls, intrusion detection systems (IDS), and web application firewalls (WAF), utilizing real-time data processing and machine learning techniques to enhance threat detection accuracy.The system leverages advanced algorithms to identify potential security incidents and reduce false positives, thus providing more reliable alerts.It is stated that the system's userfriendly interface simplifies complex security data, making it accessible to non-professional users, and enables them to take proactive actions in response to potential threats.The article also highlights the system's scalability, which allows it to adapt to various organizational sizes and threat environments, making it suitable for both small enterprises with minimal resources and larger organizations with more complex security needs.The study emphasizes the importance of accessible, intelligent security solutions in closing the cybersecurity gap for SMEs, enabling them to detect, assess, and mitigate threats with greater agility and precision, similar to larger enterprises with dedicated security teams.Moreover, the system is designed to work in real-time, processing large volumes of heterogeneous log data while ensuring high system performance without sacrificing accuracy.In addition to the primary focus on usability and scalability, the article addresses key challenges in integrating multi-source security logs, improving the speed and accuracy of threat detection, and ensuring the system remains responsive under heavy workloads.By offering a practical solution to SMEs, this research contributes to the ongoing effort to democratize cybersecurity, providing smaller organizations with the tools they need to defend themselves against increasingly sophisticated cyberattacks.