2019 15th European Dependable Computing Conference (EDCC) 2019
DOI: 10.1109/edcc.2019.00026
|View full text |Cite
|
Sign up to set email alerts
|

Facing Cyber-Physical Security Threats by PSIM-SIEM Integration

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
2
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
3
2
2

Relationship

0
7

Authors

Journals

citations
Cited by 11 publications
(3 citation statements)
references
References 4 publications
0
2
0
Order By: Relevance
“…Fausto et al (2021) explored the integration of CPS logs into processes that review other typical information logs to detect cyber threats and physical anomalies. Frattini et al (2019) also researched a merging of log information by proposing a combination of security incident and event management and physical security incident management systems, finding that merging plant condition management software and IBM’s QRadar in test scenarios benefits security analysis in detecting attacks that target both physical and digital vulnerabilities. Razavi-Far et al (2021) note that missing information can reduce the effectiveness of classifying intrusion detections and outline approaches that can increase the accuracy of intrusion classifications by reducing missing scores in SCADA data.…”
Section: Prior Convergence Studiesmentioning
confidence: 99%
“…Fausto et al (2021) explored the integration of CPS logs into processes that review other typical information logs to detect cyber threats and physical anomalies. Frattini et al (2019) also researched a merging of log information by proposing a combination of security incident and event management and physical security incident management systems, finding that merging plant condition management software and IBM’s QRadar in test scenarios benefits security analysis in detecting attacks that target both physical and digital vulnerabilities. Razavi-Far et al (2021) note that missing information can reduce the effectiveness of classifying intrusion detections and outline approaches that can increase the accuracy of intrusion classifications by reducing missing scores in SCADA data.…”
Section: Prior Convergence Studiesmentioning
confidence: 99%
“…A framework for event collection and correlation that can process and analyze heterogeneous data through event pattern detectors-and integrate them into the open-source SIEM OSSIM-was proposed in [26]. The authors of [27] addressed the issue of physical security information management and security information and event management integration by using the IBM SIEM QRadar as a platform. The authors of [28] presented another framework, called synERGY, for cross-layer anomaly detection based on ML techniques, in order to enable the early discovery of both cyber and physical attacks that may impact the cyber-physical system.…”
Section: State-of-the-art On Siemmentioning
confidence: 99%
“…Appropriate countermeasures for critical incidents are facilitated by real-time information about affected devices, root causes and physical impact. As incidents can be caused by failure or attack against a variety of physical and digital devices, integrated monitoring of the cyber and physical domain is advantageous (Frattini et al, 2019). The problem is further complicated by new attack types or unseen physical failures, where no prior knowledge is available for event identification.…”
Section: Introductionmentioning
confidence: 99%