inklap

STUDY OF THE CURRENT STATE OF SIEM SYSTEMS

Tetiana Smirnova, Liliia Konstantynova, Oksana Konoplitska-Slobodeniuk, Yan Kozlov, Oksana Kravchuk, Nataliia Kozirova · Cybersecurity: Education, Science, Technique · 2024

In this work, a study of SIEM systems, the relevance of which has grown significantly during the full-scale invasion of Russia into Ukraine, has been carried out. The task of finding the most optimal solutions was solved according to the following criteria: ease of use, ability to integrate with other protection solutions, pricing policy and features. For this purpose, the work considered a general description of the structure and principle of operation of the SIEM system, determined the capabilities and features of modern SIEM systems, conducted a study of the following software (software): Splunk Enterprise Security (Splunk), Elastic Security, IBM QRadar SIEM, Wazuh SIEM, Microsoft Sentinel. As a result of the research, the following was revealed: modern SIEM solutions allow automating part of the processes of detection and response to security events, allow to take control of hybrid types of infrastructure, which may include cloud environments, virtualization and containerization systems, workstations and other corporate devices. They are implemented both in the form of deployment of their solutions at their own facilities, and in the form of renting relevant resources, providin

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً