{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T07:29:34Z","timestamp":1781076574000,"version":"3.54.1"},"reference-count":93,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2023,1,2]],"date-time":"2023-01-02T00:00:00Z","timestamp":1672617600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,2]],"date-time":"2023-01-02T00:00:00Z","timestamp":1672617600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2023,6]]},"DOI":"10.1007\/s10207-022-00657-9","type":"journal-article","created":{"date-parts":[[2023,1,2]],"date-time":"2023-01-02T02:02:23Z","timestamp":1672624943000},"page":"691-711","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":26,"title":["Systematic review of SIEM technology: SIEM-SC birth"],"prefix":"10.1007","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7178-520X","authenticated-orcid":false,"given":"Juan Miguel","family":"L\u00f3pez Vel\u00e1squez","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sergio Mauricio","family":"Mart\u00ednez Monterrubio","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Luis Enrique","family":"S\u00e1nchez Crespo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"David","family":"Garcia Rosado","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,1,2]]},"reference":[{"key":"657_CR1","doi-asserted-by":"publisher","unstructured":"Cinque, M., Cotroneo, D., Pecchia, A.: Challenges and directions in security information and event management (SIEM), In: 2018 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW), pp. 95\u201399, (2018). https:\/\/doi.org\/10.1109\/ISSREW.2018.00-24","DOI":"10.1109\/ISSREW.2018.00-24"},{"key":"657_CR2","doi-asserted-by":"publisher","unstructured":"Knapp, E.: In: Knapp, E. (ed.) Industrial Network Security, pp. 303\u2013312. Syngress, Boston (2011). https:\/\/doi.org\/10.1016\/B978-1-59749-645-2.00011-2","DOI":"10.1016\/B978-1-59749-645-2.00011-2"},{"key":"657_CR3","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1016\/B978-0-12-394397-2.00003-9","volume-title":"Detecting System Intrusions","author":"A Kakareka","year":"2013","unstructured":"Kakareka, A.: Detecting System Intrusions, pp. 47\u201362. Elsevier, Berlin (2013). https:\/\/doi.org\/10.1016\/B978-0-12-394397-2.00003-9"},{"key":"657_CR4","doi-asserted-by":"publisher","first-page":"148","DOI":"10.1007\/978-3-642-33448-1_21","volume-title":"Global Security, Safety and Sustainability & e-Democracy","author":"G Gonzalez Granadillo","year":"2012","unstructured":"Gonzalez Granadillo, G., Ben Mustapha, Y., Hachem, N., Debar, H.: An ontology-based model for SIEM environments. In: Global Security, Safety and Sustainability & e-Democracy, pp. 148\u2013155. Springer, Berlin (2012). https:\/\/doi.org\/10.1007\/978-3-642-33448-1_21"},{"key":"657_CR5","doi-asserted-by":"publisher","first-page":"102165","DOI":"10.1016\/j.cose.2020.102165","volume":"103","author":"F Menges","year":"2021","unstructured":"Menges, F., Latzo, T., Vielberth, M., Sobola, S., P\u00f6hls, H.C., Taubmann, B., K\u00f6stler, J., Puchta, A., Freiling, F., Reiser, H.P., Pernul, G.: Towards GDPR-compliant data processing in modern SIEM systems. Comput. Secur. 103, 102165 (2021). https:\/\/doi.org\/10.1016\/j.cose.2020.102165","journal-title":"Comput. Secur."},{"key":"657_CR6","doi-asserted-by":"publisher","unstructured":"Lee, J.H., Kim, Y.S., Kim, J.H., Kim, I.K.: Toward the SIEM architecture for cloud-based security services. In: 2017 IEEE Conference on Communications and Network Security (CNS), pp. 398\u2013399 (2017). https:\/\/doi.org\/10.1109\/CNS.2017.8228696","DOI":"10.1109\/CNS.2017.8228696"},{"key":"657_CR7","doi-asserted-by":"publisher","unstructured":"Chuvakin, A., Schmidt, K., Phillips, C.: In: Chuvakin, A., Schmidt, K., Phillips C. (eds.) Logging and Log Management, pp. 115\u2013125. Syngress, Boston (2013). https:\/\/doi.org\/10.1016\/B978-1-59-749635-3.00007-5","DOI":"10.1016\/B978-1-59-749635-3.00007-5"},{"key":"657_CR8","doi-asserted-by":"publisher","first-page":"101817","DOI":"10.1016\/j.cose.2020.101817","volume":"94","author":"BD Bryant","year":"2020","unstructured":"Bryant, B.D., Saiedian, H.: Improving SIEM alert metadata aggregation with a novel kill-chain based classification model. Comput. Secur. 94, 101817 (2020). https:\/\/doi.org\/10.1016\/j.cose.2020.101817","journal-title":"Comput. Secur."},{"key":"657_CR9","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1016\/j.cose.2017.03.003","volume":"67","author":"BD Bryant","year":"2017","unstructured":"Bryant, B.D., Saiedian, H.: A novel kill-chain framework for remote security log analysis with SIEM software. Comput. Secur. 67, 198 (2017). https:\/\/doi.org\/10.1016\/j.cose.2017.03.003","journal-title":"Comput. Secur."},{"key":"657_CR10","doi-asserted-by":"publisher","unstructured":"Miloslavskaya, N., Tolstoy, A.: New SIEM system for the Internet of Things. In: Lecture Notes in Control and Information Sciences, pp. 317\u2013327 (2019). https:\/\/doi.org\/10.1007\/978-3-030-16184-2_31","DOI":"10.1007\/978-3-030-16184-2_31"},{"issue":"12","key":"657_CR11","doi-asserted-by":"publisher","first-page":"2049","DOI":"10.1016\/j.infsof.2013.07.010","volume":"55","author":"B Kitchenham","year":"2013","unstructured":"Kitchenham, B., Brereton, P.: A systematic review of systematic review process research in software engineering. Inf. Softw. Technol. 55(12), 2049 (2013). https:\/\/doi.org\/10.1016\/j.infsof.2013.07.010","journal-title":"Inf. Softw. Technol."},{"key":"657_CR12","doi-asserted-by":"publisher","unstructured":"Podzins, O., Romanovs, A.: Why SIEM is irreplaceable in a secure IT environment? In: 2019 Open Conference of Electrical, Electronic and Information Sciences (eStream), pp. 1\u20135 (2019). https:\/\/doi.org\/10.1109\/eStream.2019.8732173","DOI":"10.1109\/eStream.2019.8732173"},{"key":"657_CR13","doi-asserted-by":"publisher","unstructured":"Fernandes, D.A., Soares, L.F., Gomes, J.V., Freire, M.M., In\u2019acio, P.R.: A quick perspective on the current state in cybersecurity. Emerg Trends ICT Secur. 423\u2013442 (2014). https:\/\/doi.org\/10.1016\/B978-0-12-411474-6.00025-6. https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/B9780124114746000256","DOI":"10.1016\/B978-0-12-411474-6.00025-6"},{"key":"657_CR14","doi-asserted-by":"publisher","unstructured":"Snedaker, S., Rima, C.: In: Business Continuity and Disaster Recovery Planning for IT Professionals, second edition edn. Syngress, Boston, pp. 369\u2013411 (2014). https:\/\/doi.org\/10.1016\/B978-0-12-410526-3.00007-6","DOI":"10.1016\/B978-0-12-410526-3.00007-6"},{"key":"657_CR15","doi-asserted-by":"publisher","unstructured":"Dalziel, H.: In: Dalziel, H. (ed.) Infosec Management Fundamentals, pp. 45\u201346. Syngress, Boston (2015). https:\/\/doi.org\/10.1016\/B978-0-12-804172-7.00015-5","DOI":"10.1016\/B978-0-12-804172-7.00015-5"},{"key":"657_CR16","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1016\/B978-0-12-803306-7.00006-1","volume-title":"DNS Network Security","author":"A Liska","year":"2016","unstructured":"Liska, A., Stowe, G.: DNS Network Security, pp. 93\u2013119. Elsevier (2016). https:\/\/doi.org\/10.1016\/B978-0-12-803306-7.00006-1"},{"key":"657_CR17","doi-asserted-by":"publisher","unstructured":"Knapp, E.D., Langill, J.T.: In: Knapp E.D., Langill J.T. (eds.) Industrial Network Security (Second Edition), second edition edn., pp. 387\u2013407. Syngress, Boston (2015). https:\/\/doi.org\/10.1016\/B978-0-12-420114-9.00013-7","DOI":"10.1016\/B978-0-12-420114-9.00013-7"},{"key":"657_CR18","doi-asserted-by":"publisher","unstructured":"Sood, A.K., Enbody, R.: In: Sood, A.K., Enbody, R. (eds.) Targeted Cyber Attacks, pp. 123\u2013134. Syngress, Boston (2014). https:\/\/doi.org\/10.1016\/B978-0-12-800604-7.00008-5","DOI":"10.1016\/B978-0-12-800604-7.00008-5"},{"key":"657_CR19","doi-asserted-by":"publisher","unstructured":"Casola, V., De Benedictis, A., Rak, M., Villano, U.: In: Ficco, M., Palmieri, F. (eds.) Security and Resilience in Intelligent Data-Centric Systems and Communication Networks, Intelligent Data-Centric Systems, pp. 235\u2013259. Academic Press (2018). https:\/\/doi.org\/10.1016\/B978-0-12-811373-8.00011-2","DOI":"10.1016\/B978-0-12-811373-8.00011-2"},{"key":"657_CR20","doi-asserted-by":"publisher","first-page":"165607","DOI":"10.1109\/ACCESS.2019.2953095","volume":"7","author":"J Lee","year":"2019","unstructured":"Lee, J., Kim, J., Kim, I., Han, K.: Cyber threat detection based on artificial neural networks using event profiles. IEEE Access 7, 165607 (2019). https:\/\/doi.org\/10.1109\/ACCESS.2019.2953095","journal-title":"IEEE Access"},{"issue":"4","key":"657_CR21","doi-asserted-by":"publisher","first-page":"1","DOI":"10.2200\/S00431ED1V01Y201207DTM028","volume":"4","author":"E Bertino","year":"2012","unstructured":"Bertino, E.: Data protection from insider threats. Synth. Lect. Data Manag. 4(4), 1 (2012). https:\/\/doi.org\/10.2200\/S00431ED1V01Y201207DTM028","journal-title":"Synth. Lect. Data Manag."},{"key":"657_CR22","doi-asserted-by":"publisher","unstructured":"Staffa, M., Coppolino, L., Sgaglione, L., Gelenbe, E., Komnios, I., Grivas, E., Stan, O., Castaldo, L.: KONFIDO: an OpenNCP-based secure eHealth data exchange system. In: Communications in Computer and Information Science, vol. 821, pp. 11\u201327. Springer (2018). https:\/\/doi.org\/10.1007\/978-3-319-95189-8_2","DOI":"10.1007\/978-3-319-95189-8_2"},{"key":"657_CR23","doi-asserted-by":"publisher","unstructured":"Kotenko, I., Doynikova, E.: Security assessment of computer networks based on attack graphs and security events, In: Linawati, Mahendra, M.S., Neuhold, E.J., Tjoa, A.M., You, I. (eds.) Information and Communication Technology, vol. 8407, pp. 462\u2013471. Springer, Berlin (2014). https:\/\/doi.org\/10.1007\/978-3-642-55032-4_47","DOI":"10.1007\/978-3-642-55032-4_47"},{"key":"657_CR24","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1007\/978-1-4842-5952-8_9","volume-title":"Institute Resilience Through Detection, Response, and Recovery","author":"D Blum","year":"2020","unstructured":"Blum, D.: Institute Resilience Through Detection, Response, and Recovery, pp. 259\u2013295. Apress, Berkeley (2020). https:\/\/doi.org\/10.1007\/978-1-4842-5952-8_9"},{"key":"657_CR25","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1007\/978-1-4302-6146-9_3","volume-title":"Platform Boot Integrity: Foundation for Trusted Compute Pools","author":"R Yeluri","year":"2014","unstructured":"Yeluri, R., Castro-Leon, E.: Platform Boot Integrity: Foundation for Trusted Compute Pools, pp. 37\u201364. Apress, Berkeley (2014). https:\/\/doi.org\/10.1007\/978-1-4302-6146-9_3"},{"key":"657_CR26","doi-asserted-by":"publisher","first-page":"297","DOI":"10.1007\/978-1-4842-5952-8_10","volume-title":"Create Your Rational Cybersecurity Success Plan","author":"D Blum","year":"2020","unstructured":"Blum, D.: Create Your Rational Cybersecurity Success Plan, pp. 297\u2013313. Apress, Berkeley (2020). https:\/\/doi.org\/10.1007\/978-1-4842-5952-8_10"},{"key":"657_CR27","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1007\/978-3-662-44885-4_5","volume-title":"Communications and Multimedia Security","author":"P Chen","year":"2014","unstructured":"Chen, P., Desmet, L., Huygens, C.: A study on advanced persistent threats. In: Communications and Multimedia Security, vol. 8735, pp. 63\u201372. Springer, Berlin (2014). https:\/\/doi.org\/10.1007\/978-3-662-44885-4_5"},{"key":"657_CR28","doi-asserted-by":"publisher","unstructured":"Tiwari, S., Suryani, E., Ng, A.K., Mishra, K.K., Singh, N.: In: Tiwari, S., Suryani, E., Ng, A.K., Mishra, K.K., Singh N. (eds.) Proceedings of International Conference on Big Data, Machine Learning and their Applications, Lecture Notes in Networks and Systems, vol. 150, Springer, Singapore (2021). https:\/\/doi.org\/10.1007\/978-981-15-8377-3","DOI":"10.1007\/978-981-15-8377-3"},{"issue":"16","key":"657_CR29","doi-asserted-by":"publisher","first-page":"4636","DOI":"10.3390\/s20164636","volume":"20","author":"JV Botello","year":"2020","unstructured":"Botello, J.V., Mesa, A.P., Rodr\u00edguez, F.A., D\u00edaz-L\u00f3pez, D., Nespoli, P., M\u00e1rmol, F.G.: BlockSIEM: protecting smart city services through a Blockchain-based and distributed SIEM. Sensors 20(16), 4636 (2020). https:\/\/doi.org\/10.3390\/s20164636","journal-title":"Sensors"},{"key":"657_CR30","doi-asserted-by":"publisher","unstructured":"Qusa, H., Allam, H., Younus, F., Ali, M., Ahmad, S.: Secure smart home using open security intelligence systems. In: 2019 Sixth HCT Information Technology Trends (ITT), pp. 12\u201317 (2019). https:\/\/doi.org\/10.1109\/ITT48889.2019.9075129","DOI":"10.1109\/ITT48889.2019.9075129"},{"key":"657_CR31","doi-asserted-by":"publisher","unstructured":"Perera, V.H., Senarathne, A.N., Rupasinghe, L.: Intelligent SOC Chatbot for Security Operation Center. In: 2019 International Conference on Advancements in Computing (ICAC), pp. 340\u2013345 (2019). https:\/\/doi.org\/10.1109\/ICAC49085.2019.9103388","DOI":"10.1109\/ICAC49085.2019.9103388"},{"key":"657_CR32","doi-asserted-by":"publisher","first-page":"217977","DOI":"10.1109\/ACCESS.2020.3041837","volume":"8","author":"ME Aminanto","year":"2020","unstructured":"Aminanto, M.E., Ban, T., Isawa, R., Takahashi, T., Inoue, D.: Threat alert prioritization using isolation forest and stacked auto encoder with day-forward-chaining analysis. IEEE Access 8, 217977 (2020). https:\/\/doi.org\/10.1109\/ACCESS.2020.3041837","journal-title":"IEEE Access"},{"key":"657_CR33","doi-asserted-by":"publisher","first-page":"101586","DOI":"10.1016\/j.is.2020.101586","volume":"95","author":"F Alves","year":"2021","unstructured":"Alves, F., Bettini, A., Ferreira, P.M., Bessani, A.: Processing tweets for cybersecurity threat awareness. Inf. Syst. 95, 101586 (2021). https:\/\/doi.org\/10.1016\/j.is.2020.101586","journal-title":"Inf. Syst."},{"key":"657_CR34","doi-asserted-by":"publisher","unstructured":"Rahman, N.H.A., Choo, K.K.R.: In: Ko, R., Choo, K.K.R. (eds.) The Cloud Security Ecosystem. pp. 383\u2013400, Syngress, Boston (2015). https:\/\/doi.org\/10.1016\/B978-0-12-801595-7.00017-3","DOI":"10.1016\/B978-0-12-801595-7.00017-3"},{"issue":"1","key":"657_CR35","doi-asserted-by":"publisher","first-page":"55","DOI":"10.1109\/MSP.2011.153","volume":"10","author":"I Aguirre","year":"2012","unstructured":"Aguirre, I., Alonso, S.: Improving the automation of security information management: a collaborative approach. IEEE Secur. Priv. Mag. 10(1), 55 (2012). https:\/\/doi.org\/10.1109\/MSP.2011.153","journal-title":"IEEE Secur. Priv. Mag."},{"key":"657_CR36","doi-asserted-by":"publisher","first-page":"581","DOI":"10.1016\/j.future.2019.12.028","volume":"105","author":"JPA Yaacoub","year":"2020","unstructured":"Yaacoub, J.P.A., Noura, M., Noura, H.N., Salman, O., Yaacoub, E., Couturier, R., Chehab, A.: Securing internet of medical things systems: limitations, issues and recommendations. Future Gener. Comput. Syst. 105, 581 (2020). https:\/\/doi.org\/10.1016\/j.future.2019.12.028","journal-title":"Future Gener. Comput. Syst."},{"key":"657_CR37","doi-asserted-by":"publisher","first-page":"251","DOI":"10.1016\/j.future.2020.08.044","volume":"115","author":"M Repetto","year":"2021","unstructured":"Repetto, M., Carrega, A., Rapuzzi, R.: An architecture to manage security operations for digital service chains. Future Gener. Comput. Syst. 115, 251 (2021). https:\/\/doi.org\/10.1016\/j.future.2020.08.044","journal-title":"Future Gener. Comput. Syst."},{"issue":"9","key":"657_CR38","doi-asserted-by":"publisher","first-page":"6","DOI":"10.1016\/S1353-4858(20)30104-5","volume":"2020","author":"M Campfield","year":"2020","unstructured":"Campfield, M.: The problem with (most) network detection and response. Netw. Secur. 2020(9), 6 (2020). https:\/\/doi.org\/10.1016\/S1353-4858(20)30104-5","journal-title":"Netw. Secur."},{"key":"657_CR39","doi-asserted-by":"publisher","unstructured":"Serckumecka, A., Medeiros, I., Bessani, A.: Low-cost serverless SIEM in the cloud. In: 2019 38th Symposium on Reliable Distributed Systems (SRDS), pp. 381\u20133811 (2019). https:\/\/doi.org\/10.1109\/SRDS47363.2019.00057","DOI":"10.1109\/SRDS47363.2019.00057"},{"key":"657_CR40","doi-asserted-by":"publisher","unstructured":"Kotenko, I., Fedorchenko, A., Saenko, I., Kushnerevich, A.: Parallelization of security event correlation based on accounting of event type links. In: 2018 26th Euromicro International Conference on Parallel, Distributed and Network-based Processing (PDP), pp. 462\u2013469 (2018). https:\/\/doi.org\/10.1109\/PDP2018.2018.00080","DOI":"10.1109\/PDP2018.2018.00080"},{"issue":"10","key":"657_CR41","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1016\/S1353-4858(20)30119-7","volume":"2020","author":"R Meyers","year":"2020","unstructured":"Meyers, R.: Data highway and the digital transformation: arguments for secure, centralised log management. Netw. Secur. 2020(10), 17 (2020). https:\/\/doi.org\/10.1016\/S1353-4858(20)30119-7","journal-title":"Netw. Secur."},{"key":"657_CR42","doi-asserted-by":"publisher","first-page":"102066","DOI":"10.1016\/j.cose.2020.102066","volume":"99","author":"L Giddens","year":"2020","unstructured":"Giddens, L., Amo, L.C., Cichocki, D.: Gender bias and the impact on managerial evaluation of insider security threats. Comput. Secur. 99, 102066 (2020). https:\/\/doi.org\/10.1016\/j.cose.2020.102066","journal-title":"Comput. Secur."},{"key":"657_CR43","doi-asserted-by":"publisher","unstructured":"Winkler, I., Gomes, A.T.: In: Winkler, I., Gomes A.T. (eds.), Advanced Persistent Security, pp. 105\u2013130. Syngress (2017). https:\/\/doi.org\/10.1016\/B978-0-12-809316-0.00010-5","DOI":"10.1016\/B978-0-12-809316-0.00010-5"},{"key":"657_CR44","doi-asserted-by":"publisher","unstructured":"Nathans, D.: In: Nathans, D. (ed.), Designing and Building Security Operations Center, pp. 25\u201347. Syngress (2015). https:\/\/doi.org\/10.1016\/B978-0-12-800899-7.00002-1","DOI":"10.1016\/B978-0-12-800899-7.00002-1"},{"key":"657_CR45","doi-asserted-by":"publisher","unstructured":"Li, Y., Zhang, T., Li, X., Li, T.: A model of apt attack defense based on cyber threat detection. In: Yun, X., Wen, W., Lang, B., Yan, H., Ding, L., Li, J., Zhou, Y. (eds.) Cyber Security, vol. 970, pp. 122\u2013135. Springer, Singapore (2019). https:\/\/doi.org\/10.1007\/978-981-13-6621-5_10","DOI":"10.1007\/978-981-13-6621-5_10"},{"issue":"5","key":"657_CR46","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1109\/MSP.2014.103","volume":"12","author":"S Bhatt","year":"2014","unstructured":"Bhatt, S., Manadhata, P.K., Zomlot, L.: The Operational role of security information and event management systems. IEEE Secur. Priv. 12(5), 35 (2014). https:\/\/doi.org\/10.1109\/MSP.2014.103","journal-title":"IEEE Secur. Priv."},{"issue":"6","key":"657_CR47","doi-asserted-by":"publisher","first-page":"74","DOI":"10.1109\/MSP.2013.138","volume":"11","author":"AA C\u00e1rdenas","year":"2013","unstructured":"C\u00e1rdenas, A.A., Manadhata, P.K., Rajan, S.P.: Big data analytics for security. IEEE Secur. Priv. 11(6), 74 (2013). https:\/\/doi.org\/10.1109\/MSP.2013.138","journal-title":"IEEE Secur. Priv."},{"issue":"3","key":"657_CR48","doi-asserted-by":"publisher","first-page":"84","DOI":"10.1109\/MSP.2015.50","volume":"13","author":"J Margulies","year":"2015","unstructured":"Margulies, J.: A developer\u2019s guide to audit logging. IEEE Secur. Priv. 13(3), 84 (2015). https:\/\/doi.org\/10.1109\/MSP.2015.50","journal-title":"IEEE Secur. Priv."},{"issue":"1","key":"657_CR49","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1007\/s42979-021-00858-4","volume":"3","author":"L Coppolino","year":"2021","unstructured":"Coppolino, L., Sgaglione, L., D\u2019Antonio, S., Magliulo, M., Romano, L., Pacelli, R.: Risk assessment driven use of advanced SIEM technology for cyber protection of critical e-health processes. SN Comput. Sci. 3(1), 16 (2021). https:\/\/doi.org\/10.1007\/s42979-021-00858-4","journal-title":"SN Comput. Sci."},{"key":"657_CR50","doi-asserted-by":"publisher","first-page":"580","DOI":"10.1016\/j.procs.2017.09.117","volume":"115","author":"MSN Raja","year":"2017","unstructured":"Raja, M.S.N., Vasudevan, A.: Rule generation for TCP SYN flood attack in SIEM environment. Procedia Comput. Sci. 115, 580 (2017). https:\/\/doi.org\/10.1016\/j.procs.2017.09.117","journal-title":"Procedia Comput. Sci."},{"key":"657_CR51","doi-asserted-by":"publisher","unstructured":"Mulyadi, F., Annam, L.A., Promya, R., Charnsripinyo, C.: Implementing Dockerized Elastic Stack for Security Information and Event Management. In: 2020\u20145th International Conference on Information Technology (InCIT), pp. 243\u2013248 (2020). https:\/\/doi.org\/10.1109\/InCIT50588.2020.9310950","DOI":"10.1109\/InCIT50588.2020.9310950"},{"key":"657_CR52","doi-asserted-by":"publisher","unstructured":"Vasilyev, V., Shamsutdinov, R.: Security analysis of wireless sensor networks using SIEM and multi-agent approach. In: 2020 Global Smart Industry Conference (GloSIC), pp. 291\u2013296 (2020). https:\/\/doi.org\/10.1109\/GloSIC50886.2020.9267830","DOI":"10.1109\/GloSIC50886.2020.9267830"},{"key":"657_CR53","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1155\/2016\/4731953","volume":"2016","author":"I Almomani","year":"2016","unstructured":"Almomani, I., Al-Kasasbeh, B., Al-Akhras, M.: WSN-DS: a dataset for intrusion detection systems in wireless sensor networks. J. Sens. 2016, 1 (2016). https:\/\/doi.org\/10.1155\/2016\/4731953","journal-title":"J. Sens."},{"key":"657_CR54","doi-asserted-by":"publisher","unstructured":"Kotenko I, Fedorchenko A, Saenko I, Kushnerevich A (2017) Big data technologies for security event correlation based on event type accounting. Vopr. Kiberbezopasnosti 5(24), 2. https:\/\/doi.org\/10.21681\/2311-3456-2017-5-2-16","DOI":"10.21681\/2311-3456-2017-5-2-16"},{"key":"657_CR55","doi-asserted-by":"publisher","unstructured":"Vianello, V., Gulisano, V., Jimenez-Peris, R., Patino-Martinez, M., Torres, R., Diaz, R., Prieto, E.: A Scalable SIEM Correlation Engine and Its Application to the Olympic Games IT Infrastructure. In: 2013 International Conference on Availability, Reliability and Security, pp. 625\u2013629 (2013). https:\/\/doi.org\/10.1109\/ARES.2013.82","DOI":"10.1109\/ARES.2013.82"},{"key":"657_CR56","doi-asserted-by":"publisher","unstructured":"Stephen, J.J., Gmach, D., Block, R., Madan, A., AuYoung, A.: Distributed real-time event analysis. In: 2015 IEEE International Conference on Autonomic Computing, pp. 11\u201320 (2015). https:\/\/doi.org\/10.1109\/ICAC.2015.12","DOI":"10.1109\/ICAC.2015.12"},{"key":"657_CR57","doi-asserted-by":"publisher","unstructured":"Malkhi, D. (ed.): Concurrency: The Works of Leslie Lamport. Association for Computing Machinery, New York (2019). https:\/\/doi.org\/10.1145\/3335772","DOI":"10.1145\/3335772"},{"key":"657_CR58","doi-asserted-by":"publisher","unstructured":"Iskhakov, A., Iskhakov, S.: Data Normalization models in the security event management systems. In: 2020 13th International Conference \u201dManagement of large-scale system development\u201d (MLSD), pp. 1\u20135 (2020). https:\/\/doi.org\/10.1109\/MLSD49919.2020.9247682","DOI":"10.1109\/MLSD49919.2020.9247682"},{"key":"657_CR59","doi-asserted-by":"publisher","unstructured":"Coppolino, L., D\u2019Antonio, S., Formicola, V., Romano, L.: Integration of a system for critical infrastructure protection with the OSSIM SIEM platform: a dam case study, In: Flammini, F., Bologna, S., Vittorini, V. (ed.) Computer Safety, Reliability, and Security. SAFECOMP 2011, pp. 199\u2013212. Springer, Berlin (2011). https:\/\/doi.org\/10.1007\/978-3-642-24270-0_15","DOI":"10.1007\/978-3-642-24270-0_15"},{"key":"657_CR60","doi-asserted-by":"publisher","unstructured":"Hindy, H., Brosset, D., Bayne, E., Seeam, A., Bellekens, X.: Improving SIEM for critical SCADA water infrastructures using machine learning. In: Lecture Notes in Computer Science, vol. 11387, pp. 3\u201319. Springer, Switzerland (2019). https:\/\/doi.org\/10.1007\/978-3-030-12786-2_1","DOI":"10.1007\/978-3-030-12786-2_1"},{"key":"657_CR61","doi-asserted-by":"publisher","unstructured":"Formicola, V., Di Pietro, A., Alsubaie, A., D\u2019Antonio, S., Marti, J.: Assessing the impact of cyber attacks on wireless sensor nodes that monitor interdependent physical systems. In: International Conference on Critical Infrastructure Protection, vol. 441, pp. 213\u2013229. Springer (2014). https:\/\/doi.org\/10.1007\/978-3-662-45355-1_14","DOI":"10.1007\/978-3-662-45355-1_14"},{"key":"657_CR62","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1016\/j.jisa.2017.12.001","volume":"38","author":"M Di Mauro","year":"2018","unstructured":"Di Mauro, M., Di Sarno, C.: Improving SIEM capabilities through an enhanced probe for encrypted Skype traffic detection. J. Inf. Secur. Appl. 38, 85 (2018). https:\/\/doi.org\/10.1016\/j.jisa.2017.12.001","journal-title":"J. Inf. Secur. Appl."},{"key":"657_CR63","doi-asserted-by":"publisher","unstructured":"Chernov, A.V., Butakova, M.A., Karpenko, E.V.: Security incident detection technique for multilevel intelligent control systems on railway transport in Russia. In: 2015 23rd Telecommunications Forum Telfor (TELFOR), pp. 1\u20134 (2015). https:\/\/doi.org\/10.1109\/TELFOR.2015.7377381","DOI":"10.1109\/TELFOR.2015.7377381"},{"issue":"8","key":"657_CR64","doi-asserted-by":"publisher","first-page":"673","DOI":"10.3103\/S0146411616080125","volume":"50","author":"DS Lavrova","year":"2016","unstructured":"Lavrova, D.S.: An approach to developing the SIEM system for the Internet of Things. Autom. Control Comput. Sci. 50(8), 673 (2016). https:\/\/doi.org\/10.3103\/S0146411616080125","journal-title":"Autom. Control Comput. Sci."},{"key":"657_CR65","doi-asserted-by":"publisher","first-page":"533","DOI":"10.1007\/978-981-15-7062-9_53","volume":"196","author":"S Muthuraj","year":"2021","unstructured":"Muthuraj, S., Sethumadhavan, M., Amritha, P.P., Santhya, R.: Detection and prevention of attacks on active directory using SIEM. Inf. Commun. Technol. Intell. Syst. 196, 533 (2021). https:\/\/doi.org\/10.1007\/978-981-15-7062-9_53","journal-title":"Inf. Commun. Technol. Intell. Syst."},{"key":"657_CR66","doi-asserted-by":"publisher","unstructured":"Hwoij, A., Khamaiseh, A., Ababneh, M.: SIEM architecture for the Internet of Things and smart city. In: International Conference on Data Science, E-Learning and Information Systems 2021. Association for Computing Machinery, New York, DATA\u201921, pp. 147\u2013152 (2021). https:\/\/doi.org\/10.1145\/3460620.3460747","DOI":"10.1145\/3460620.3460747"},{"key":"657_CR67","doi-asserted-by":"publisher","unstructured":"Anumol, E.T.: Use of machine learning algorithms with SIEM for attack prediction. In: Jain, L.C., Patnaik, S., Ichalkaranje, N. (eds.), Intelligent Computing, Communication and Devices, pp. 231\u2013235. Springer, New Delhi (2015). https:\/\/doi.org\/10.1007\/978-81-322-2012-1_24","DOI":"10.1007\/978-81-322-2012-1_24"},{"key":"657_CR68","doi-asserted-by":"publisher","unstructured":"Zhong, C., Yen, J., Liu, P., Erbacher, R.F.: Automate cybersecurity data triage by leveraging human analysts\u2019 cognitive process. In: 2016 IEEE 2nd International Conference on Big Data Security on Cloud (BigDataSecurity), IEEE International Conference on High Performance and Smart Computing (HPSC), and IEEE International Conference on Intelligent Data and Security (IDS), pp. 357\u2013363 (2016). https:\/\/doi.org\/10.1109\/BigDataSecurity-HPSC-IDS.2016.41","DOI":"10.1109\/BigDataSecurity-HPSC-IDS.2016.41"},{"key":"657_CR69","doi-asserted-by":"publisher","first-page":"124","DOI":"10.1016\/j.future.2021.01.004","volume":"118","author":"N Usman","year":"2021","unstructured":"Usman, N., Usman, S., Khan, F., Jan, M.A., Sajid, A., Alazab, M., Watters, P.: Intelligent dynamic malware detection using machine learning in IP reputation for forensics data analytics. Future Gener. Comput. Syst. 118, 124 (2021). https:\/\/doi.org\/10.1016\/j.future.2021.01.004","journal-title":"Future Gener. Comput. Syst."},{"key":"657_CR70","doi-asserted-by":"publisher","unstructured":"Bachane, I., Adsi, Y.I.K., Adsi, H.C.: Real time monitoring of security events for forensic purposes in Cloud environments using SIEM. In: 2016 Third International Conference on Systems of Collaboration (SysCo) (IEEE, 2016), pp. 1\u20133. https:\/\/doi.org\/10.1109\/SYSCO.2016.7831327. http:\/\/ieeexplore.ieee.org\/document\/7831327\/","DOI":"10.1109\/SYSCO.2016.7831327"},{"key":"657_CR71","doi-asserted-by":"publisher","first-page":"219","DOI":"10.1007\/978-3-642-31833-7_14","volume-title":"Dynamical Attack Simulation for Security Information and Event Management","author":"I Kotenko","year":"2014","unstructured":"Kotenko, I., Shorov, A., Chechulin, A., Novikova, E.: Dynamical Attack Simulation for Security Information and Event Management, pp. 219\u2013234. Springer, Berlin (2014). https:\/\/doi.org\/10.1007\/978-3-642-31833-7_14"},{"key":"657_CR72","first-page":"129","volume":"8","author":"I Kotenko","year":"2012","unstructured":"Kotenko, I., Chechulin, A.: Attack modeling and security evaluation in SIEM systems. Int. Trans. Syst. Sci. Appl. 8, 129 (2012)","journal-title":"Int. Trans. Syst. Sci. Appl."},{"key":"657_CR73","doi-asserted-by":"publisher","first-page":"771","DOI":"10.1007\/978-3-540-24693-0_63","volume":"3042","author":"T Peng","year":"2004","unstructured":"Peng, T., Leckie, C., Ramamohanarao, K.: Proactively detecting distributed denial of service attacks using source IP address monitoring. Networking 3042, 771 (2004). https:\/\/doi.org\/10.1007\/978-3-540-24693-0_63","journal-title":"Networking"},{"key":"657_CR74","doi-asserted-by":"publisher","unstructured":"Di Sarno, C., Formicola, V., Sicuranza, M., Paragliola, G.: Addressing security issues of electronic health record systems through enhanced SIEM technology. In: 2013 International Conference on Availability, Reliability and Security, pp. 646\u2013653 (2013). https:\/\/doi.org\/10.1109\/ARES.2013.85","DOI":"10.1109\/ARES.2013.85"},{"key":"657_CR75","doi-asserted-by":"publisher","unstructured":"Afzaal, M., Di Sarno, C., Dantonio, S., Romano, L.: An intrusion and fault tolerant forensic storage for a SIEM system. In: 2012 Eighth International Conference on Signal Image Technology and Internet Based Systems, pp. 579\u2013586 (2012). https:\/\/doi.org\/10.1109\/SITIS.2012.89","DOI":"10.1109\/SITIS.2012.89"},{"issue":"5","key":"657_CR76","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1016\/S1353-4858(14)70051-0","volume":"2014","author":"J Inns","year":"2014","unstructured":"Inns, J.: The evolution and application of SIEM systems. Netw. Secur. 2014(5), 16 (2014). https:\/\/doi.org\/10.1016\/S1353-4858(14)70051-0","journal-title":"Netw. Secur."},{"issue":"8","key":"657_CR77","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1016\/S1361-3723(15)30077-4","volume":"2015","author":"D Howell","year":"2015","unstructured":"Howell, D.: Building better data protection with SIEM. Comput. Fraud Secur. 2015(8), 19 (2015). https:\/\/doi.org\/10.1016\/S1361-3723(15)30077-4","journal-title":"Comput. Fraud Secur."},{"issue":"1","key":"657_CR78","doi-asserted-by":"publisher","first-page":"12","DOI":"10.1016\/S1353-4858(21)00008-8","volume":"2021","author":"S Udipi","year":"2021","unstructured":"Udipi, S.: The event data management problem: getting the most from network detection and response. Netw. Secur. 2021(1), 12 (2021). https:\/\/doi.org\/10.1016\/S1353-4858(21)00008-8","journal-title":"Netw. Secur."},{"key":"657_CR79","doi-asserted-by":"publisher","unstructured":"Bachane, I., Adsi, Y.I.K., Adsi, H.C.: Real time monitoring of security events for forensic purposes in Cloud environments using SIEM. In: 2016 Third International Conference on Systems of Collaboration (SysCo), pp. 1\u20133 (2016). https:\/\/doi.org\/10.1109\/SYSCO.2016.7831327","DOI":"10.1109\/SYSCO.2016.7831327"},{"key":"657_CR80","doi-asserted-by":"publisher","first-page":"167","DOI":"10.1007\/978-3-319-68505-2\\_15","volume":"167\u2013175","author":"T Li","year":"2017","unstructured":"Li, T., Yan, L.: SIEM based on big data analysis. Lect. Notes Comput. Sci. 167\u2013175, 167 (2017). https:\/\/doi.org\/10.1007\/978-3-319-68505-2_15","journal-title":"Lect. Notes Comput. Sci."},{"key":"657_CR81","doi-asserted-by":"publisher","unstructured":"Nabil, M., Soukainat, S., Lakbabi, A., Ghizlane, O.: SIEM selection criteria for an efficient contextual security. In: 2017 International Symposium on Networks, Computers and Communications (ISNCC), pp. 1\u20136 (2017). https:\/\/doi.org\/10.1109\/ISNCC.2017.8072035","DOI":"10.1109\/ISNCC.2017.8072035"},{"key":"657_CR82","doi-asserted-by":"publisher","unstructured":"Mokalled, H., Catelli, R., Casola, V., Debertol, D., Meda, E., Zunino, R.: The applicability of a SIEM solution: requirements and evaluation. In: 2019 IEEE 28th International Conference on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE), pp. 132\u2013137 (2019). https:\/\/doi.org\/10.1109\/WETICE.2019.00036","DOI":"10.1109\/WETICE.2019.00036"},{"key":"657_CR83","doi-asserted-by":"publisher","first-page":"476","DOI":"10.1007\/978-3-030-34339-2\\_28","volume":"11879","author":"M Safarzadeh","year":"2019","unstructured":"Safarzadeh, M., Gharaee, H., Panahi, A.H.: A novel and comprehensive evaluation methodology for SIEM. Lect. Notes Comput. Sci. 11879, 476 (2019). https:\/\/doi.org\/10.1007\/978-3-030-34339-2_28","journal-title":"Lect. Notes Comput. Sci."},{"key":"657_CR84","doi-asserted-by":"publisher","unstructured":"Leszczyna, R., Wrobel, M.R.: Evaluation of open source SIEM for situation awareness platform in the smart grid environment. In: 2015 IEEE World Conference on Factory Communication Systems (WFCS), pp. 1\u20134 (2015). https:\/\/doi.org\/10.1109\/WFCS.2015.7160577","DOI":"10.1109\/WFCS.2015.7160577"},{"issue":"2","key":"657_CR85","doi-asserted-by":"publisher","first-page":"97","DOI":"10.1108\/02635570310463429","volume":"103","author":"B Sahay","year":"2003","unstructured":"Sahay, B., Gupta, A.: Development of software selection criteria for supply chain solutions. Ind. Manag. Data Syst. 103(2), 97 (2003). https:\/\/doi.org\/10.1108\/02635570310463429","journal-title":"Ind. Manag. Data Syst."},{"key":"657_CR86","doi-asserted-by":"publisher","unstructured":"Vazao, A., Santos, L., Piedade, M.B., Rabadao, C.: SIEM open source solutions: a comparative study. In: 2019 14th Iberian Conference on Information Systems and Technologies (CISTI), pp. 1\u20135 (2019). https:\/\/doi.org\/10.23919\/CISTI.2019.8760980","DOI":"10.23919\/CISTI.2019.8760980"},{"key":"657_CR87","doi-asserted-by":"publisher","unstructured":"\u00dcnal, U., Kahya, C.N., Kurtlutepe, Y., Da\u011f, H.: Investigation of cyber situation awareness via SIEM tools: a constructive review. In: 2021 6th International Conference on Computer Science and Engineering (UBMK), pp. 676\u2013681 (2021). https:\/\/doi.org\/10.1109\/UBMK52708.2021.9558964","DOI":"10.1109\/UBMK52708.2021.9558964"},{"key":"657_CR88","doi-asserted-by":"publisher","unstructured":"Svoboda, T., Horalek, J., Sobeslav, V.: Behavioral analysis of SIEM solutions for energy technology systems. In: Context-Aware Systems and Applications, and Nature of Computation and Communication. Springer, pp. 265\u2013276 (2021). https:\/\/doi.org\/10.1007\/978-3-030-67101-3_21","DOI":"10.1007\/978-3-030-67101-3_21"},{"key":"657_CR89","unstructured":"Gartner, I.N.C.: IT Glossary. https:\/\/www.gartner.com\/en\/information-technology\/glossary. Accessed 05 Sept 2022"},{"key":"657_CR90","unstructured":"Ko\u0144czak, J., de Sousa Santos, N.F., \u017burkowski, T., Wojciechowski, P.T., Schiper, A.: JPaxos: state machine replication based on the Paxos protocol (2011)"},{"key":"657_CR91","doi-asserted-by":"publisher","unstructured":"Coppolino, L., D\u2019Antonio, S., Formicola, V., Romano, L.: Enhancing SIEM technology to protect critical infrastructures. In: H\u00e4mmerli, B.M., Kalstad Svendsen, N., Lopez, J. (eds.) Critical Information Infrastructures Security, pp. 10\u201321. Springer, Berlin (2013). https:\/\/doi.org\/10.1007\/978-3-642-41485-5_2","DOI":"10.1007\/978-3-642-41485-5_2"},{"key":"657_CR92","doi-asserted-by":"publisher","unstructured":"Vaz\u00e3o, A., Santos, L., Oliveira, A., Rabad\u00e3o, C.: A GDPR compliant SIEM solution. In: European Conference on Cyber Warfare and Security. Academic Conferences International Limited PP, Reading, i, pp. 440\u2013448, XIV (2021). https:\/\/doi.org\/10.34190\/EWS.21.081","DOI":"10.34190\/EWS.21.081"},{"key":"657_CR93","unstructured":"I.B.M. Corp. QRadar on Cloud (2022). https:\/\/www.ibm.com\/products\/hosted-security-intelligence. Accessed 05 Sept 2022"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-022-00657-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10207-022-00657-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-022-00657-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,5,26]],"date-time":"2023-05-26T01:18:36Z","timestamp":1685063916000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10207-022-00657-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,1,2]]},"references-count":93,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2023,6]]}},"alternative-id":["657"],"URL":"https:\/\/doi.org\/10.1007\/s10207-022-00657-9","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,1,2]]},"assertion":[{"value":"2 January 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"There are no conflicts of interest within this manuscript.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"This article does not contain any studies with human participants performed by any of the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}}]}}