Addressing Security Issues of Small and Medium
Enterprises through Enhanced SIEM Technology
Prateek Shivhare
1,
Savaridassan.P
2
Abstract— Today’s information security threats are increasing in numbers and severity but diversity of network and information
technology is increasing exponentially. So it is a challenge for small and medium enterprises, those who cannot give more importance to
security because of their capital investment. This Paper actually focuses on an efficient approach to address security issue with small and
medium enterprises. All business faces the same challenges like keeping costs down to maintain your competitive edge presses. So these
enterprises cannot spend much resource and capital on security. As a solution open source SIEM will provide an enhance and complete
security solution.
Keywords— SIEM, OSSIM, Security, Open Source, Enterprise.
1. Introduction
The Security Information and Event Management (SIEM)
system is new to information technology (IT). The SIEM
system is a complex gathering of advancements intended to
give vision and clarity on the corporate IT System as a whole,
benefitting security experts and IT administrators as well.
Security experts and investigators utilize the SIEM system to
monitor, identify, document, and sometimes respond to
security affronts. The art and science of implementing
Security Information and Event Management on any network
requires a number of moving pieces. Perhaps those of
responsible for the security of small and medium-size business
have already reached the conclusion that SIEM is beyond
grasp. But these industry can use open source SIEM so they
can save their capital and resources. It is essential to be able to
detect attacks in a timely manner and implement the relative
countermeasures, following appropriate procedures to respond
to incidents, thus minimizing the effects and the damages they
can cause. In order to detect intrusions and attacks, system
administrators and information security analysts make use of
tools, such as IDS/IPS (Intrusion Detection/Prevention
System) and analysis of logs (event records) of servers and
network devices, looking for any significant events from a
security point of view. A network of an organization of
average size produces, as a whole, such a quantity of logs that
it is very difficult (and still very expensive) to check them all,
one by one, to obtain meaningful information. A further
difficulty is that there is no single standard used to record the
logs and often, depending on the type and size, they are not
immediate or easy to understand. It is even more difficult to
relate other logs produced by many different systems to each
other manually, to highlight anomalies in the network that
would not be detectable by analyzing the logs of each machine
separately. SIEM (Security Information and Event
Management) software, therefore, is not limited to being a
centralized solution for log management, but also (and
especially) it has the ability to standardize logs in a single
format, analyze the recorded events, highlight the most
important information and relate the logs to each other
(correlation), allowing analysts to detect anomalies and attacks
more easily.
2. Information Security Challenge for Small and Medium
Enterprises
The growing complexity of information systems combined
with their regulatory compliance issues, public-network
connections and competitive necessity presents even large
enterprises with significant challenges managing information
security. For the small and medium enterprise it can seem
impossible to truly get control of the security and availability
of the systems you need to stay ahead in business.
Emerging at the same time as these challenges are potential
solutions to them. Security Information and Event
Management (SIEM) systems have matured considerably over
the past decade and are beginning to offer solutions fit for the
small and medium enterprise. AlienVault SIEM technology is
deployed at more than half of all SIEM installations
worldwide. SIEM solutions aim to simplify security
operations and compliance reporting by integrating all of the
functions of individual security products into a single
platform. While all SIEM solutions integrate with existing
security and network devices.
3. How SIEM can be helpful
Every business faces the same challenges like keeping costs
down to maintain your competitive edge presses on one side
while managing an effective information system and
compliance risk presses on the other. For smaller businesses
without the economies of scale of global multinationals, the
choice is often between spending more than you can afford for