<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-title-group>
        <journal-title>Computing, Telecommunication and Control</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Информатика, телекоммуникации и управление</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2687-0517</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">1</article-id>
      <title-group>
        <article-title>New generation of security information and event management systems</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Новое поколение систем мониторинга и управления инцидентами безопасности</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name>
            <surname>Kotenko</surname>
            <given-names>Igor</given-names>
          </name>
          <email>ivkote@comsec.spb.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Saenko</surname>
            <given-names>Igor</given-names>
          </name>
          <email>ibsaen@comsec.spb.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Yusupov</surname>
            <given-names>Rafael</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>spiiran@iias.spb.su</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">St. Petersburg Institute for Informatics and Automation of the Russian Academy of Sciences</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2014-06-10">
        <day>10</day>
        <month>06</month>
        <year>2014</year>
      </pub-date>
      <issue>3</issue>
      <issue-id pub-id-type="publisher-id">198</issue-id>
      <fpage>7</fpage>
      <lpage>18</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://infocom.spbstu.ru/userfiles/files/articles/2014/3/01.pdf"/>
      <abstract xml:lang="en">
        <p>The given paper justifies the technological necessity to develop a new generation of security monitoring and event management systems based on security information and event management technology. We have focused on the typical architecture and key solutions to design the individual modules of such systems collecting constant security data, their universal translation, scalable processing, hybrid ontological storage and rich visualization, as well as a cross-level correlation of events, attack modelling and predictive security analysis. We have also stated some proposals to use such systems in the domains related to security protection in critical infrastructures.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>security monitoring and management</kwd>
        <kwd>computer network</kwd>
        <kwd>security event</kwd>
        <kwd>information infrastructure</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
