Extending Security Event Correlation
Last year at this time I wrote a series of posts on security event correlation . I offered the following definition in the final post: Security event correlation is the process of applying criteria to data inputs, generally of a conditional ("if-then") nature, in order to generate actionable data outputs. Since then what I have found is that products and people still claim this as a goal, but for the most part achieving it remains elusive. Please also see that last post for what SEC is not , i.e., SEC is not simply collection (of data sources), normalization (of data sources), prioritization (of events), suppression (via thresholding), accumulation (via simple incrementing counters), centralization (of policies), summarization (via reports), administration (of software), or delegation (of tasks). So is SEC anything else? Based on some operational uses I have seen, I think I can safely introduce an extension to "true" SEC: applying information from one or more data...