Next Article in Journal
Independent Effects of Dopant, Oxygen Vacancy, and Specific Surface Area on Crystal Phase of HfO2 Thin Films towards General Parameters to Engineer the Ferroelectricity
Next Article in Special Issue
An Intrusion Detection System for RPL-Based IoT Networks
Previous Article in Journal
An Interactive Augmented Reality Graph Visualization for Chinese Painters
Previous Article in Special Issue
A Link Fabrication Attack Mitigation Approach (LiFAMA) for Software Defined Networks
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Automation of Asset Inventory for Cyber Security: Investigation of Event Correlation-Based Technique

St. Petersburg Federal Research Center of the Russian Academy of Sciences (SPC RAS), 14-th Liniya, 39, 199178 St. Petersburg, Russia
*
Author to whom correspondence should be addressed.
Electronics 2022, 11(15), 2368; https://doi.org/10.3390/electronics11152368
Submission received: 16 June 2022 / Revised: 23 July 2022 / Accepted: 23 July 2022 / Published: 28 July 2022

Abstract

Asset inventory is one of the essential steps in cyber security analysis and management. It is required for security risk identification. Current information systems are large-scale, heterogeneous, and dynamic. This complicates manual inventory of the assets as it requires a lot of time and human resources. At the same time, an asset inventory should be continuously repeated because continuous modifications of system objects and topology lead to changes in the cyber security situation. Thus, a technique for automated identification of system assets and connections between them is required. The paper proposes a technique for automated inventory of assets and connections between them in different organizations. The developed technique is constructed based on event correlation methods, namely linking the system events to each other. The essence of the technique consists of the investigation of event characteristics and identifying the characteristics that arise solely together. This allows determining system assets via assigning event characteristics to specific asset types. The security risks depend on the criticality of the assets; thus, a discussion of automated calculation of the outlined assets’ criticality is provided. Outlined system objects and topology can be further used for restoring possible attack paths and security assessment. The applicability of the developed technique to reveal object properties and types is demonstrated in the experiments.
Keywords: information infrastructure; criticality; cyber security; asset determination; statistical methods; event analysis information infrastructure; criticality; cyber security; asset determination; statistical methods; event analysis

Share and Cite

MDPI and ACS Style

Kotenko, I.; Doynikova, E.; Fedorchenko, A.; Desnitsky, V. Automation of Asset Inventory for Cyber Security: Investigation of Event Correlation-Based Technique. Electronics 2022, 11, 2368. https://doi.org/10.3390/electronics11152368

AMA Style

Kotenko I, Doynikova E, Fedorchenko A, Desnitsky V. Automation of Asset Inventory for Cyber Security: Investigation of Event Correlation-Based Technique. Electronics. 2022; 11(15):2368. https://doi.org/10.3390/electronics11152368

Chicago/Turabian Style

Kotenko, Igor, Elena Doynikova, Andrey Fedorchenko, and Vasily Desnitsky. 2022. "Automation of Asset Inventory for Cyber Security: Investigation of Event Correlation-Based Technique" Electronics 11, no. 15: 2368. https://doi.org/10.3390/electronics11152368

APA Style

Kotenko, I., Doynikova, E., Fedorchenko, A., & Desnitsky, V. (2022). Automation of Asset Inventory for Cyber Security: Investigation of Event Correlation-Based Technique. Electronics, 11(15), 2368. https://doi.org/10.3390/electronics11152368

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop