RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    SIEM 환경에서 무탐지 기반 유효성 관리 = Validity Management Based on No-Hit Detection in a SIEM Environment

    한글로보기

    https://www.riss.kr/link?id=T17369892

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    As security threats become increasingly complex and diverse, the number of detection scenarios and rules in Security Information and Event Management (SIEM) environments continues to grow. SIEM systems have become a core platform for threat detection and response by collecting and correlating logs from various security devices and systems. However, in real-world operations, many detection rules remain active in the system while generating no alerts over a given period. These so-called No-Hit Rules indicate a loss of operational validity in the detection policy and increase the workload of security analysts, as they must be manually reviewed or left unmanaged.
    This study proposes a script-based operational framework that automatically identifies and manages such No-Hit Rules by correlating predefined SIEM detection rules with actual event logs at the database level. The framework periodically inspects all active rules, extracts those with no detection history within a specified time window, and outputs standardized log files that can be used for policy review and reporting. In an experimental evaluation conducted on a real SOC test environment, the proposed method identified 117 No-Hit Rules out of 300 active rules (approximately 39%), and reduced the end-to-end inspection time from about 300 minutes of manual work to 0.2 seconds through automation.
    The results demonstrate that the proposed framework provides a practical approach to managing the operational validity of SIEM detection policies, enhancing both efficiency and consistency in rule-based monitoring. Future work may extend this framework by integrating automated root-cause analysis for No-Hit Rules and coupling it with semi-automatic policy refinement mechanisms to further improve security operations.
    번역하기

    As security threats become increasingly complex and diverse, the number of detection scenarios and rules in Security Information and Event Management (SIEM) environments continues to grow. SIEM systems have become a core platform for threat detection ...

    As security threats become increasingly complex and diverse, the number of detection scenarios and rules in Security Information and Event Management (SIEM) environments continues to grow. SIEM systems have become a core platform for threat detection and response by collecting and correlating logs from various security devices and systems. However, in real-world operations, many detection rules remain active in the system while generating no alerts over a given period. These so-called No-Hit Rules indicate a loss of operational validity in the detection policy and increase the workload of security analysts, as they must be manually reviewed or left unmanaged.
    This study proposes a script-based operational framework that automatically identifies and manages such No-Hit Rules by correlating predefined SIEM detection rules with actual event logs at the database level. The framework periodically inspects all active rules, extracts those with no detection history within a specified time window, and outputs standardized log files that can be used for policy review and reporting. In an experimental evaluation conducted on a real SOC test environment, the proposed method identified 117 No-Hit Rules out of 300 active rules (approximately 39%), and reduced the end-to-end inspection time from about 300 minutes of manual work to 0.2 seconds through automation.
    The results demonstrate that the proposed framework provides a practical approach to managing the operational validity of SIEM detection policies, enhancing both efficiency and consistency in rule-based monitoring. Future work may extend this framework by integrating automated root-cause analysis for No-Hit Rules and coupling it with semi-automatic policy refinement mechanisms to further improve security operations.

    더보기

    목차 (Table of Contents)

    • 제 1 장 서 론 1
    • 1.1 연구 배경 및 필요성 1
    • 1.2 연구 방법 및 목적 3
    • 제 2 장 관련 연구 7
    • 2.1 보안 관제 개념·구조 7
    • 제 1 장 서 론 1
    • 1.1 연구 배경 및 필요성 1
    • 1.2 연구 방법 및 목적 3
    • 제 2 장 관련 연구 7
    • 2.1 보안 관제 개념·구조 7
    • 2.2 SIEM 개념·발전 12
    • 2.3 기존연구의 한계점 19
    • 2.4 본 연구의 접근 방법 21
    • 제 3 장 무탐지 발생 특성 및 운영상 과제 분석 23
    • 3.1 보안위협과 탐지실패의 개요 23
    • 3.2 무탐지 정의 24
    • 3.3 무탐지 발생 사례 및 원인 25
    • 3.4 무탐지 관리의 한계와 운영상 과제 26
    • 3.5 정량적 관리 필요성과 향후 개선 방향 28
    • 제 4 장 무탐지 자동 식별 및 정량 관리 방안
    • 4.1 무탐지 자동 식별 절차 29
    • 4.2 RM Score 기반 관리 체계 31
    • 4.3 무탐지 원인 진단 절차 35
    • 제 5 장 실험 환경 및 결과 41
    • 5.1 실험 환경 42
    • 5.2 실험 및 결과 43
    • 제 6 장 결론 및 향후 연구 46
    • 참 고 문 헌 49
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼