Understanding Event Correlation and the Need for Security Information Management
- Source:
- Wipro
FREE Registration is required
Overview: Enormous logs are produced by various network devices like IDS or Firewall, Webserver, applications and databases which is practically impossible to monitor manually. The challenge in the paper is to isolate and prioritize the few messages that do indeed indicate real security threats. This white paper discusses how event correlation works and how a SIM (security information management) can fit into a corporate network to minimize the challenges faced by the system administrators or security professionals. Also, it discusses ways to reduce the time spend in analyzing huge logs produced by various network devices.
(Is this item miscategorized? Does it need more tags? Let us know.)
Format: PDF | Size: 496KB | Date: Apr 2005 | Pages: 10




