Publication:
Network Security Intelligence Centres for Information Security Incident Management

dc.contributor.authorFurnell, S.
dc.contributor.authorMiloslavskaya, N.
dc.contributor.authorМилославская, Наталья Георгиевна
dc.date.accessioned2024-11-29T10:51:53Z
dc.date.available2024-11-29T10:51:53Z
dc.date.issued2021
dc.description.abstract© 2021, The Author(s), under exclusive license to Springer Nature Switzerland AG.Intensive IT development is driving current information security (IS) trends and require sophisticated structures and adequate approached to manage IS for different businesses. The wide range of threats is constantly growing in modern intranets; they have become not only numerous and diverse but also more disruptive. In such circumstances, organizations realize that IS incidents’ timely detection and prevention in the future (what is more important) are not only possible but imperative. Any delay leaves only reactive actions to IS incidents, putting assets at risk as a result. A properly designed IS incident management system (ISIMS), operating as an integral part of the whole organization’s governance system, reduces IS incidents’ number and limits damage caused by them. To maximally automate IS incident management (ISIM) within one organization and to deepen its knowledge of IS level, this research proposes to unite together all advantages of a Security Intelligence Centre (SIC) and a Network Operations Centre (NOC) with their unique and joint toolkits and techniques in a unified Network SIC (NSIC). This paper presents the research, which is focused upon the designing and evaluating the concept of NSICs, and represents a novel advancement beyond existing concepts of security and network operations centres in current security monitoring scenarios. Key contributions are made in relation to underlying taxonomies of threats and attacks, leading to the requirements for NSICs, the related design, and then evaluation in a practical context and the implications arising from this (e.g. training requirements).
dc.format.extentС. 270-282
dc.identifier.citationFurnell, S. Network Security Intelligence Centres for Information Security Incident Management / Furnell, S., Miloslavskaya, N. // Advances in Intelligent Systems and Computing. - 2021. - 1310. - P. 270-282. - 10.1007/978-3-030-65596-9_34
dc.identifier.doi10.1007/978-3-030-65596-9_34
dc.identifier.urihttps://www.doi.org/10.1007/978-3-030-65596-9_34
dc.identifier.urihttps://www.scopus.com/record/display.uri?eid=2-s2.0-85098162922&origin=resultslist
dc.identifier.urihttps://openrepository.mephi.ru/handle/123456789/23535
dc.relation.ispartofAdvances in Intelligent Systems and Computing
dc.titleNetwork Security Intelligence Centres for Information Security Incident Management
dc.typeConference Paper
dspace.entity.typePublication
oaire.citation.volume1310
relation.isAuthorOfPublication6febdbd2-58c3-4304-a960-0295f5f1ff88
relation.isAuthorOfPublication.latestForDiscovery6febdbd2-58c3-4304-a960-0295f5f1ff88
relation.isOrgUnitOfPublication010157d0-1f75-46b2-ab5b-712e3424b4f5
relation.isOrgUnitOfPublication.latestForDiscovery010157d0-1f75-46b2-ab5b-712e3424b4f5
Файлы
Коллекции