siem Flashcards
Security Information and Event Management
SIEM
Security information and event management, SIM+SEM together
SIM
Security information management
SEM
Security event information
SIM definition
The practice of collecting, monitoring, and analyzing data from computer logs
SEM definition
The process of collecting, monitoring, and analyzing data from events in software, system, and IT environment
Types of logs to capture
Application logs, system logs, and host activity
Application logs
Logs modification of applications and changing records
System logs
Logs who logged into system and what actions they performed
Host activity
Machines starting up, rebooting, shutting down, changes to configs, and disk space
SIEM collects data from
Firewalls, intrusion detection systems, intrusion prevention systems, and application servers
Security intrusion
A security event, or a combination events, that constitutes a security incident in which an intruder
gains, or attempts to gain, access to a system (or system resource) without having authorization to do so
Intrusion detection
A security service that monitors and analyzes system events for the purpose of finding, and providing real-time or near real-time warning of, attempts to access system resources in an unauthorized
manner
Intrusion detection system
Notifies that an unusual activity has occurred and is usually placed behind the firewall
Parts of IDS
Sensors, analyzers, and user interface
IDS sensors
Collect data from network packets, logs files, and system call traces