SOFTWARE METHODS OF NETWORK SECURITY MONITORING

Authors

  • D.A. Minochkin National Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute” Author
  • A.M. Nser National Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute” Author

DOI:

https://doi.org/10.17721/2519-481X/2022/77-11

Keywords:

NSM, Network Security Monitoring, network security monitoring software methods

Abstract

The software methods for monitoring network security (NSM - Network Security Monitoring) are discussed. With the growth and rapid development of mobile communications, rich data and artificial intelligence technologies, we are entering the era of the mobile Internet. With the continuous intellectualization of network security and infrastructure, information technology is widely used in the field of industrial control, making network security more and more open, bringing a new network security control system to the traditional relatively closed industrial control system. Currently, there is an increase in the number of information threats and factors leading to the unstable operation of data transmission networks. The prerequisites for this growth are the mass application, the complication of the hierarchy of computer networks and the increase in their structural complexity, the increase in the heterogeneity of software and hardware, the complication of the functionality of network services, which leads to the emergence of various vulnerabilities. Under such conditions, the development and improvement of methods for identifying information threats are of great importance. One of the components of ensuring information protection of networks is software systems designed to detect harmful or suspicious activity - network security monitoring methods (NSM). Network security monitoring techniques (NSM) are used to monitor network
133
communications for information security events. For maximum effect, a combination of capturing the entire packet in addition to logging network activity is recommended.
This article provides definitions of network security monitoring methods, their classification, phases of the method cycle and their description. Some of the best known and widely used multi-module NSM solutions have been reviewed. The best known examples of such combinations are IDS/IPS, SEM/SIEM and UTM.
Network security monitoring is important because it checks if the first lines of defense are working, gives us the opportunity to eliminate threats before they cause real damage if there is a vulnerability somewhere in your system, and allows us to understand where these vulnerabilities are and how to fix them before something will happen.

Author Biographies

References

1. Samson R., (2020) “Prevention vs DetectionBased Security Approach,” Clearnetwork, www.clearnetwork.com/prevention-vsdetection-cybersecurity-approach/, Tech. Rep.,

2. Rapid7, (2015) “Prevention vs Detection, Rebalancing Your Security Program,” www.rapid7.com/resources/prevention-vsdetection/

3. Comodo, (2020) “Advanced Threat Protection: Security Incident Response Tools,”, Tech. Rep.

4. Bejtlich, R. (2005) The TAO of the Network Security Monitoring. Beyond Intrusion Detection.

5. Camacho, J. Maciá-Fernández, G. Verdejo, J. E. D. and García-Teodoro, P. (2014) “Tackling the Big Data 4 Vs for Anomaly Detection,” INFOCOM’2014 Workshop on Security and Privacy in Big Data, pp. 500–505

6. X. Ji, K. Huang, L. Jin, H. Tang, C. Liu, Z. Zhong, W. You, X. Xu, H. Zhao, J. Wu, and M. Yi, (2018) “Overview of 5G security technology,” Science China Information Sciences, vol. 61, no. 8, pp. 1869–1919,.

7. Thudumu, S. Branch, P. Jin, J. and Singh, J. J. “A comprehensive survey of anomaly detection techniques for high dimensional big data,” vol. 7, no. 1.

8. Fuentes-García, M. Camacho, J. and Maciá-Fernández, G. “Present and Future of Network Security Monitoring” 10.1109/access.2017.doi

9. US Department of Defense Instruction 8500.2, (2003) “Information Assurance (IA) Implementation” http://www.dtic.mil/whs/directives/corres/pdf/850002p.pdf.

10. Sanders, C. (2014). “The Practice of Applied Network Security Monitoring. Applied Network Security Monitoring”, 1–24. doi:10.1016/b978-0-12-417208-1.00001-5

11. Dokman, T. Ivanjko, T. (2020). “Open Source Intelligence (OSINT): issues and trends”. doi:10.17234/infuture.2019.23

12. Collins, M. “Network Security Through Data Analysis. Building situational awareness”, O. Media, Ed. O’Reilly, 2014.

13. INCIBE, (2017) “Diseño y Configuración de IPS, IDSy SIEM en Sistemas de Control Industrial,” https://www.incibe-cert.es/blog/diseno-yconfiguracion-ips-ids-y-siem-sistemas-controlindustrial

14. Alpcan, T. and Basar, T. (2011) “Network Security. A Decision and Game-Theoretic Approach”. Cambridge University Press

15. ATT Cybersecurity, (2020) “Suricata IDS: an overview of threading capabilities,” https://cutt.ly/jyZbAeI, Tech. Rep.

16. OSSEC Project Team,(2008) “Open Source HIDS SECurity,” https://www.ossec.net/

17. Gartner, (2019) “What is Security Information and Event Management (SIEM)?” https://www.gartner.com/reviews/market/securityinformation-event-management

18. Paxson, V. and Sommer, R. “The Zeek Network Security Monitor (Bro),” https://www.zeek.org/

19. Prelude, (2020) “PRELUDE SIEM. Smart Security,” https://cutt.ly/bfTTiuN

20. Wazuh Inc., (2019) “The Open Source Security Platform,” https://wazuh.com/

21. AT&T-cybersecurity,(2019) “AlienVault(R) Unified Security Management(R) (USM),” https://www.alienvault.com/products

22. Gartner, (2019) “Unified Threat Management (utm)” https://www.gartner.com/en/informationtechnology/glossary/unified-threat-management-utm

23. Barracuda, (2020) “Barracuda CloudGen Firewall,” https://cutt.ly/FgefB

24. BAKOTECH, (2018) “WatchGuard UTM is Recognized the Only Visionary in the Gartner Magic Quadrant for the 4th Time,” https://bit.ly/3aNkYO8

25. WatchGuard, (2020) “WatchGuard Security Services,” https://www.watchguard.com/wgrdproducts/security-services

26. Sophos, (2020) “The world’s best visibility, protection, and response,” https://www.sophos.com/enus/products/next-gen-firewall.aspx

27. Visscher, B. (2014) “Sguil,” https://sourceforge.net/projects/sguil/

28. Security Onion Solutions, (2008) “Security Onion,”https://securityonion.net/

29. National Institute of Standards and Technology (NIST), (2019) “National Vulnerability Database (NVD),” https://nvd.nist.gov/

30. Molina, J. (2016) “Threat Intelligence: el porqué de las cosas,” https://www.welivesecurity.com/laes/2016/12/01/threat-intelligence/.

Published

2023-04-20

Issue

Section

INFORMATION TECHNOLOGIES