Network security is still a critical task that involves different disciplines aimed at proactively protecting, preventing, and swiftly responding to attacks. However, the classic management-related flaws still persist, e.g. the analysis of large amounts of reported intrusion alerts, whilst coexisting with novel problematic issues such as the integration of many heterogeneous sensing interfaces. Security information and event management (SIEM) then appears as the new paradigm to reconcile traditional intrusion detection systems along with recently advanced techniques such as event collection, aggregation, analysis, management and correlation. This book brings together the most novel research findings and the latest advances in security information management as well as compiling deeply settled technologies. The book firstly establishes the fundamentals of SIEM technology, and finally, new trends are also explored.
{{comment.content}}