2019-345

2019-345

Automation of Security Information and Event Management

Automation of Security Information and Event Management
KYLE M. BUTERA, QUINN P. MCHUGH, ZACHARY S. MILES, DYLAN A. CHOW, KEVIN M. MALONE, DAVID
A. SERRANO, DANIEL VEGA, JACOB R. DOMINGUEZ, ROSTYSLAV S. HNATYSHYN, ALEX LAM, and ERIC
A. CURRIE

Cybersecurity awareness is extremely critical in today’s climate. Many mission-critical systems require real-time and actionable data analytics, event monitoring and response. While existing cybersecurity tools are available, they are often riddled with deficiencies that make them difficult to utilize effectively. One such tool, SPLUNK, has many challenges. While very powerful, it lacks user-friendly representation of data, algorithmic filtering mechanisms, and the ability to prioritize events by criticality. Our research for our comprehensive solution examined in detail both compliance standards from the Federal Information Systems Management Act (FISMA) of 2002, the National Institute of Standards (NIST) SP 800-53 Security Controls and the underlying functionality of SPLUNK itself. We developed a cloud-based application to merge existing security capabilities with a novel security framework.