Skip to main content

Enhancing Security Information and Event Management Systems in Cybersecurity Using Artificial Intell

Page 1

International Research Journal of Engineering and Technology (IRJET)

e-ISSN: 2395-0056

Volume: 12 Issue: 01 | Jan 2025

p-ISSN: 2395-0072

www.irjet.net

Enhancing Security Information and Event Management Systems in Cybersecurity Using Artificial Intelligence Saba Gour1 1 Software Engineer, Seattle, USA ---------------------------------------------------------------------***---------------------------------------------------------------------

Abstract – Cybersecurity has always been important to an organization to ensure its smooth and healthy functioning. However, in recent years, cybersecurity has become increasing important due to an exponential increase in security threats. Today, we hear of critical systems in hospitals, banks, retail being hijacked by malicious actors for financial gains and enterprises are left helpless with no real choice but to concede to the demands of the attackers. With the advent of artificial intelligence (AI), attackers now use sophisticated techniques and tactics to breach systems and are successful in causing a lot of harm. Thus, it has become very important to enhance cybersecurity strategies and use artificial intelligence to improve the prevention, detection, mitigation and resolution of security threats. Applying AI correctly to cybersecurity gives us the much-needed edge to combat security attacks. Security Operations Center (SOC) is the team within an organization whose sole function is to respond to security incidents. The SOC team uses different tools; however, a Security information and event management (SIEM) system is a critical tool used for cybersecurity. We examine an SIEM system, which is a central system that collects logs from various sources within the network, correlates and analyzes the logs and uses it for efficient monitoring and alerting. The SOC team relies heavily on the SIEM system to detect Indications of Compromise (IoC) and if a compromise is detected then the Incident Response Team (IRT) is engaged. Through a comprehensive analysis, this paper not only provides insights into SIEM systems, their different sources of data, their functions and challenges but also anticipates future trends and developments in the field.

(VMs), intrusion detection systems (IDS), intrusion prevention systems (IPS), endpoint protection (EPP) tools, and data loss prevention (DLP) tools. Switches, routers: Switch is a network component which ties together different devices like computers, printers, storage servers in a small setting like a home or a small office. Router is a network component which will connect multiple switches together to connect networks in a single location or across multiple locations to form a larger network. Router is an interface through which traffic flows between the network and the internet. A larger network is broken up into smaller subnetworks, it is called network segmentation to ensure smooth network administration and enhanced security which could be on-premises or in the cloud. Firewalls: Firewall is a network component that will control the incoming and outgoing traffic between your network and the internet. It will protect your network from malicious actors based on certain predefined security rules. Larger networks benefit from having standalone firewalls for enhanced protection, whereas in your home a firewall is integrated into the router. A firewall is the first line of defense for any network and is often intruded by attackers. Load balancers: Load balancer is a network device that distributes network or application traffic across multiple hosts/servers for balancing capacity, improving response time and combating network latency. Mostly, high volume customer facing systems are load balanced. They help in diverting malicious traffic to specific hosts, keeping it away from the main network, which helps in the case of distributed denial of service (DDoS) attacks.

Key Words: cybersecurity, security information and event management (SIEM), artificial intelligence (AI), machine learning (ML), false positive alerts, correlation rules, security operations team (SOC), information technology (IT)

1.1 Collecting logs

DNS servers/resolvers: Domain name system (DNS) is the phonebook of the internet. It transforms a domain into an IP address so that it can be understood by the browser and the correct pages can be loaded. A DNS recursive resolver is the first device that receives the request and will recursively look for the IP address until it reaches the authoritative DNS server which is the final stop, and it returns the IP address to the recursive resolver that initially made the request. Many times, DNS servers are targeted by attackers that want to divert the traffic to malicious IP addresses.

The logs are collected by the SIEM system from different network devices like switches, routers, firewalls, network segments, load balancers, domain name system (DNS) servers/resolvers, hypervisors, hosts, virtual machines

Hypervisors, hosts, virtual machines (VMs): Hypervisor is the virtualization software or firmware that creates virtual machines on a physical machine. It is the underlying component that manages memory, CPU usage,

1.The main functions of SIEM systems The main purpose of an SIEM system is to collect and correlate logs from different sources in real time, set up monitoring and alerting which are then used for incident response and, compliance and auditing.

© 2025, IRJET

|

Impact Factor value: 8.315

|

ISO 9001:2008 Certified Journal

|

Page 342


Turn static files into dynamic content formats.

Create a flipbook