Correlation with ESM Flashcards
What is correlation?
Is the process to turn logs into meaningfull data. ERC and ACE supports correlations but ERC only support rule-based correlation while ACE supports rule-based, risk-based, and correlation with flows (ACE also can be run in real-time or historical mode).
What is Normalization?
Is the act of changing different types of logs into a single format which enables event correlation to occur.
How does it work a correlation engine on an ERC?
- Analyzes data flowing from an ESM
- Detect suspicious patterns within this data
- Create correlation alerts
- Alerts then are inserted into ERC alerts database
What are the two types of correlation engines that an ACE has?
- Risk correlation: A risk detection engine that generates a risk score using ruleless correlation.
- Rule correlation: A threat detection engine that detects threats using a traditional rule-based event correlation.
What dedicated appliance can be deployed alongside the ESM to provide correlation logic that supplements the existing event correlation capabilities?
ACE