• čeština
    • English
    • русский
    • Deutsch
    • français
    • polski
    • українська
  • čeština 
    • čeština
    • English
    • русский
    • Deutsch
    • français
    • polski
    • українська
  • Login
View Item 
  •   Repository Home
  • Sborníky z konferencí
  • Fakulta elektrotechniky a komunikačních technologií
  • Konference Student EEICT
  • Student EEICT 2023: Selected Papers
  • View Item
  •   Repository Home
  • Sborníky z konferencí
  • Fakulta elektrotechniky a komunikačních technologií
  • Konference Student EEICT
  • Student EEICT 2023: Selected Papers
  • View Item
JavaScript is disabled for your browser. Some features of this site may not work without it.

Enhancing Security Monitoring with AI-Enabled Log Collection and NLP Modules on a Unified Open Source Platform

Thumbnail
View/Open
217_EEICT_selected.pdf (3.532Mb)
Date
2023
Author
Safonov, Yehor
Zernovic, Michal
Altmetrics
10.13164/eeict.2023.217
Metadata
Show full item record
Abstract
The number of computer attacks continues to increasedaily, posing significant challenges to modern securityadministrators to provide security in their organizations. Withthe rise of sophisticated cyber threats, it is becoming increasinglydifficult to detect and prevent attacks using traditional securitymeasures. As a result, security monitoring solutions such asSecurity Information and Event Management (SIEM) have becomea critical component of modern security infrastructures. However,these solutions still face limitations, and administrators areconstantly seeking ways to enhance their capabilities to effectivelyprotect their cyber units. This paper explores how advanced deeplearning techniques can help boost security monitoring capabilitiesby utilizing them throughout all stages of log processing. Thepresented platform has the potential to fundamentally transformand bring about a significant change in the field of securitymonitoring with advanced AI capabilities. The study includes adetailed comparison of modern log collection platforms, with thegoal of determining the most effective approach. The key benefitsof the proposed solution are its scalability and multipurposenature. The platform integrates an open source solution andallows the organization to connect any event log sources or theentire SIEM solution, normalize and filter data, and use thisdata to train and deploy different AI models to perform differentsecurity monitoring tasks more efficiently.
Keywords
Artificial intelligence, deep learning, Fluentd, logcollection, log processing, Logstash, security monitoring, SIEM
Persistent identifier
http://hdl.handle.net/11012/210694
Document type
Peer reviewed
Document version
Final PDF
Source
Proceedings II of the 29st Conference STUDENT EEICT 2023: Selected papers. s. 217-221. ISBN 978-80-214-6154-3
https://www.eeict.cz/eeict_download/archiv/sborniky/EEICT_2023_sbornik_2_v2.pdf
DOI
10.13164/eeict.2023.217
Collections
  • Student EEICT 2023: Selected Papers [60]
Citace PRO

Portal of libraries | Central library on Facebook
DSpace software copyright © 2002-2015  DuraSpace
Contact Us | Send Feedback | Theme by @mire NV
 

 

Browse

All of repositoryCommunities & CollectionsBy Issue DateAuthorsTitlesSubjectsThis CollectionBy Issue DateAuthorsTitlesSubjects

My Account

LoginRegister

Statistics

View Usage Statistics

Portal of libraries | Central library on Facebook
DSpace software copyright © 2002-2015  DuraSpace
Contact Us | Send Feedback | Theme by @mire NV