Security Information and Event Management (SIEM) platforms are critical for organizations to monitor and manage their security operations centers. However, organizations using SIEM platforms have several challenges su...Security Information and Event Management (SIEM) platforms are critical for organizations to monitor and manage their security operations centers. However, organizations using SIEM platforms have several challenges such as inefficiency of alert management and integration with real-time communication tools. These challenges cause delays and cost penalties for organizations in their efforts to resolve the alerts and potential security breaches. This paper introduces a cybersecurity Alert Distribution and Response Network (Adrian) system. Adrian introduces a novel enhancement to SIEM platforms by integrating SIEM functionalities with real-time collaboration platforms. Adrian leverages the uniquity of mobile applications of collaboration platforms to provide real-time alerts, enabling a two-way communication channel that facilitates immediate response to security incidents and efficient SIEM platform management. To demonstrate Adrian’s capabilities, we have introduced a case-study that integrates Wazuh, a SIEM platform, to Slack, a collaboration platform. The case study demonstrates all the functionalities of Adrian including the real-time alert distribution, alert customization, alert categorization, and enablement of management activities, thereby increasing the responsiveness and efficiency of Adrian’s capabilities. The study concludes with a discussion on the potential expansion of Adrian’s capabilities including the incorporation of artificial intelligence (AI) for enhanced alert prioritization and response automation.展开更多
Considering the dependent relationship among wave height,wind speed,and current velocity,we construct novel trivariate joint probability distributions via Archimedean copula functions.Total 30-year data of wave height...Considering the dependent relationship among wave height,wind speed,and current velocity,we construct novel trivariate joint probability distributions via Archimedean copula functions.Total 30-year data of wave height,wind speed,and current velocity in the Bohai Sea are hindcast and sampled for case study.Four kinds of distributions,namely,Gumbel distribution,lognormal distribution,Weibull distribution,and Pearson Type III distribution,are candidate models for marginal distributions of wave height,wind speed,and current velocity.The Pearson Type III distribution is selected as the optimal model.Bivariate and trivariate probability distributions of these environmental conditions are established based on four bivariate and trivariate Archimedean copulas,namely,Clayton,Frank,Gumbel-Hougaard,and Ali-Mikhail-Haq copulas.These joint probability models can maximize marginal information and the dependence among the three variables.The design return values of these three variables can be obtained by three methods:univariate probability,conditional probability,and joint probability.The joint return periods of different load combinations are estimated by the proposed models.Platform responses(including base shear,overturning moment,and deck displacement) are further calculated.For the same return period,the design values of wave height,wind speed,and current velocity obtained by the conditional and joint probability models are much smaller than those by univariate probability.Considering the dependence among variables,the multivariate probability distributions provide close design parameters to actual sea state for ocean platform design.展开更多
文摘Security Information and Event Management (SIEM) platforms are critical for organizations to monitor and manage their security operations centers. However, organizations using SIEM platforms have several challenges such as inefficiency of alert management and integration with real-time communication tools. These challenges cause delays and cost penalties for organizations in their efforts to resolve the alerts and potential security breaches. This paper introduces a cybersecurity Alert Distribution and Response Network (Adrian) system. Adrian introduces a novel enhancement to SIEM platforms by integrating SIEM functionalities with real-time collaboration platforms. Adrian leverages the uniquity of mobile applications of collaboration platforms to provide real-time alerts, enabling a two-way communication channel that facilitates immediate response to security incidents and efficient SIEM platform management. To demonstrate Adrian’s capabilities, we have introduced a case-study that integrates Wazuh, a SIEM platform, to Slack, a collaboration platform. The case study demonstrates all the functionalities of Adrian including the real-time alert distribution, alert customization, alert categorization, and enablement of management activities, thereby increasing the responsiveness and efficiency of Adrian’s capabilities. The study concludes with a discussion on the potential expansion of Adrian’s capabilities including the incorporation of artificial intelligence (AI) for enhanced alert prioritization and response automation.
基金partially supported by the National Natural Science Foundation of China(No.51479183)the National Key Research and Development Program,China(Nos.2016YFC0302301 and 2016YFC0803401)the Fundamental Research Funds for the Central University(No.201564003)
文摘Considering the dependent relationship among wave height,wind speed,and current velocity,we construct novel trivariate joint probability distributions via Archimedean copula functions.Total 30-year data of wave height,wind speed,and current velocity in the Bohai Sea are hindcast and sampled for case study.Four kinds of distributions,namely,Gumbel distribution,lognormal distribution,Weibull distribution,and Pearson Type III distribution,are candidate models for marginal distributions of wave height,wind speed,and current velocity.The Pearson Type III distribution is selected as the optimal model.Bivariate and trivariate probability distributions of these environmental conditions are established based on four bivariate and trivariate Archimedean copulas,namely,Clayton,Frank,Gumbel-Hougaard,and Ali-Mikhail-Haq copulas.These joint probability models can maximize marginal information and the dependence among the three variables.The design return values of these three variables can be obtained by three methods:univariate probability,conditional probability,and joint probability.The joint return periods of different load combinations are estimated by the proposed models.Platform responses(including base shear,overturning moment,and deck displacement) are further calculated.For the same return period,the design values of wave height,wind speed,and current velocity obtained by the conditional and joint probability models are much smaller than those by univariate probability.Considering the dependence among variables,the multivariate probability distributions provide close design parameters to actual sea state for ocean platform design.