Original title:
Získávání znalostí z logů systému SIEM
Translated title:
Knowledge Discovery from Logs of the SIEM System
Authors:
Kuna, Martin ; Popela, Pavel (referee) ; Bartík, Vladimír (advisor) Document type: Master’s theses
Year:
2025
Language:
slo Publisher:
Vysoké učení technické v Brně. Ústav soudního inženýrství Abstract:
[slo][eng]
Táto práca skúma možnosti využitia metód získavania znalostí z bezpečnostných logov za účelom zvýšenia bezpečnosti a spoľahlivosti systémov SIEM určených na identifikáciu bezpečnostných udalostí zo zariadení v sieti. Hlavné zameranie práce bolo na zhlukovú analýzu za účelom rozdelenia dát do istých skupín, ktoré sú následne vhodnejšie na ďalšiu analýzu a taktiež zistenie, ktoré metódy zhlukovania sú najviac vhodné pre daný typ. Ďalšou úlohou práce bolo otestovanie možnosti predikcie vybraných faktorov na základe ostatných údajov obsiahnutých v bezpečnostnom logu. Práca sa ďalej zaoberala taktiež, tým ako môžu metódy dolovania dát ovplyvniť tradičné metódy analýzy rizík čo bola v tomto prípade FMEA analýza. Na záver práca stanovuje odporúčania pre firmu XYZ na základe vykonaných analýz.
This thesis investigates the application of knowledge discovery techniques to security log data with the aim of enhancing the security and reliability of Security Information and Event Management (SIEM) systems, which are designed to identify security events from devices within a network. The primary focus is on cluster analysis, with the objective of partitioning the data into meaningful groups that are more amenable to subsequent analysis. Additionally, the study evaluates which clustering methods are most suitable for the given data type. Another key aspect of the research involves assessing the feasibility of predicting selected factors based on other attributes present in the security logs. Furthermore, the thesis examines the potential impact of data mining techniques on traditional risk assessment methodologies, specifically Failure Mode and Effects Analysis (FMEA). The thesis concludes by presenting a set of recommendations for company XYZ, derived from the analyses conducted.
Keywords:
classification; cluster analysis; Data mining; FMEA; IBM Qradar; security logs; SIEM
Institution: Brno University of Technology
(web)
Document availability information: Fulltext is available in the Brno University of Technology Digital Library. Original record: http://hdl.handle.net/11012/255146