VaultBox: Enhancing the Security and Effectiveness of Security Analytics


연구 분야: Cryptography



학회: International Conference on Science of Cyber Security


초록

Security tools like Firewalls, IDS, IPS, SIEM, EDR, and NDR effectively detect and block threats. However, these tools depend on the system, application, and event logs. Logs are the key ingredient for various purposes, including troubleshooting performance issues, satisfying compliance mandates, and monitoring and improving security. In addition, logs from multiple machines are collected and fed to the Security Information and Event Management (SIEM) system for further security analysis. Therefore, a SIEM system’s efficiency and effectiveness depend heavily on the quality and quantity of logs provided. Unfortunately, logs are often targeted brutally and tampered with after a successful intrusion to cover the attack’s traces. Thus it becomes critical to protect the confidentiality, integrity, availability, and authenticity of logs at rest or transit. This paper proposes a novel scheme to prevent logs from tampering, detect any tampering, and recuperate logs if lost or corrupt. Our scheme is forward-secure, replicated, randomized, and rate-less, aiming to help securely store and transmit logs to SIEM.


Author Profile
Devharsh Trivedi

Stevens Institute of Technology Hoboken USA

United States
Author Profile
Nikos Triandopoulos

Stevens Institute of Technology Hoboken USA

United States

📄 논문 정보

발행 연도 2023년
인용수 0
출판 국가 United States
사이트 Springer
좋아요 수 0

연관 논문 목록 (321건)