<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE book PUBLIC "-//NLM//DTD BITS Book Interchange DTD v2.3 20210610//EN" "BITS-book2.3.dtd"> <book xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" book-type="conference-proceedings" dtd-version="2.3" xml:lang="ru"> <front> <book-meta>  <book-id book-id-type="isbn">978-5-6042142-4-4</book-id>   <book-id pub-id-type="doi">10.21661/a-574</book-id>   <title-group>  <book-title xml:lang="ru">Студенческая наука: современные реалии</book-title>   <trans-title-group xml:lang="en"> <trans-title>Students&#039; science: current realities</trans-title> </trans-title-group>  </title-group>  <description xml:lang="ru"> <p>В сборнике представлены материалы участников VI Международной студенческой научно-практической конференции, посвященные актуальным вопросам науки и образования. Приведены результаты оригинальных научных разработок и учебно-методические пособия с участием студентов высшего и среднего профессионального образования, а также магистрантов.</p> </description>   <contrib-group>  <contrib contrib-type="editor" id="editor1">  <contrib-id contrib-id-type="role">chief_editor</contrib-id>    <name-alternatives>  <name name-style="eastern" xml:lang="ru"> <surname>Широков</surname> <given-names>Олег Николаевич</given-names> </name>   <name name-style="western" xml:lang="en"> <surname>Shirokov</surname> <given-names>Oleg Nikolaevich</given-names> </name>  </name-alternatives>   <email xlink:type="simple">425954@rambler.ru</email> </contrib>  <contrib contrib-type="editor" id="editor2">    <name-alternatives>  <name name-style="eastern" xml:lang="ru"> <surname>Абрамова</surname> <given-names>Людмила Алексеевна</given-names> </name>   <name name-style="western" xml:lang="en"> <surname>Abramova</surname> <given-names>Lyudmila Alexeevna</given-names> </name>  </name-alternatives>   <email xlink:type="simple">labramova@interactive-plus.ru</email> </contrib>  <contrib contrib-type="editor" id="editor3">  <contrib-id contrib-id-type="role">executive_editor</contrib-id>    <name-alternatives>  <name name-style="eastern" xml:lang="ru"> <surname>Яковлева</surname> <given-names>Татьяна Валериановна</given-names> </name>   <name name-style="western" xml:lang="en"> <surname>Yakovleva</surname> <given-names>Tatyana Valerianovna</given-names> </name>  </name-alternatives>   <email xlink:type="simple">info@interactive-plus.ru</email> </contrib>  <contrib contrib-type="editor" id="editor4">  <contrib-id contrib-id-type="role">associate_editor</contrib-id>    <name-alternatives>  <name name-style="eastern" xml:lang="ru"> <surname>Толкушкина</surname> <given-names>Наталья Константиновна</given-names> </name>   <name name-style="western" xml:lang="en"> <surname>Tolkushkina</surname> <given-names>Natalya Konstantinovna</given-names> </name>  </name-alternatives>   <email xlink:type="simple">ntolkushkina@interactive-plus.ru</email> </contrib>  </contrib-group>   <contrib-group>  <contrib contrib-type="member-of-organizing-committee" id="orgcomm1">  <contrib-id contrib-id-type="role">chief_editor</contrib-id>    <name-alternatives>  <name name-style="eastern" xml:lang="ru"> <surname>Широков</surname> <given-names>Олег Николаевич</given-names> </name>   <name name-style="western" xml:lang="en"> <surname>Shirokov</surname> <given-names>Oleg Nikolaevich</given-names> </name>  </name-alternatives>   </contrib>  <contrib contrib-type="member-of-organizing-committee" id="orgcomm2">    <name-alternatives>  <name name-style="eastern" xml:lang="ru"> <surname>Абрамова</surname> <given-names>Людмила Алексеевна</given-names> </name>   <name name-style="western" xml:lang="en"> <surname>Abramova</surname> <given-names>Lyudmila Alexeevna</given-names> </name>  </name-alternatives>   </contrib>  <contrib contrib-type="member-of-organizing-committee" id="orgcomm3">    <name-alternatives>  <name name-style="eastern" xml:lang="ru"> <surname>Бекназаров</surname> <given-names>Рахым Агибаевич</given-names> </name>   <name name-style="western" xml:lang="en"> <surname>Beknazarov</surname> <given-names>Rahym Agibaevich</given-names> </name>  </name-alternatives>   </contrib>  <contrib contrib-type="member-of-organizing-committee" id="orgcomm4">    <name-alternatives>  <name name-style="eastern" xml:lang="ru"> <surname>Иваницкий</surname> <given-names>Александр Юрьевич</given-names> </name>   <name name-style="western" xml:lang="en"> <surname>Ivanitsky</surname> <given-names>Aleksandr Yuryevich</given-names> </name>  </name-alternatives>   </contrib>  <contrib contrib-type="member-of-organizing-committee" id="orgcomm5">    <name-alternatives>  <name name-style="eastern" xml:lang="ru"> <surname>Мейманов</surname> <given-names>Бактыбек Каттоевич</given-names> </name>   <name name-style="western" xml:lang="en"> <surname>Meimanov</surname> <given-names>Baktybek Kattoevich</given-names> </name>  </name-alternatives>   </contrib>  </contrib-group>   <event>  <event-desc xml:lang="ru">Студенческая наука: современные реалии</event-desc>   <event-desc xml:lang="en">Students&#039; science: current realities</event-desc>   <conf-date> <day>01</day> <month>01</month> <year>1900</year> </conf-date>    <conf-loc xml:lang="ru">Чебоксары</conf-loc>  </event>   <publisher> <publisher-name>Центр научного сотрудничества «Интерактив плюс»</publisher-name> </publisher>    <pub-date date-type="collection" publication-format="electronic" iso-8601-date="2019"> <year>2019</year> </pub-date>    <permissions>  <copyright-statement xml:lang="en">© 2018 Andrei A. Kravtsov</copyright-statement>   <copyright-statement xml:lang="ru">© 2018 Кравцов А. А.</copyright-statement>   <copyright-year>2018</copyright-year>  <copyright-holder xml:lang="ru">Кравцов А. А.</copyright-holder>   <copyright-holder xml:lang="en">Andrei A. Kravtsov</copyright-holder>    <license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by/4.0/" xml:lang="en" xlink:type="simple"> <license-p>This work is licensed under a Creative Commons Attribution 4.0 International License (CC BY 4.0)</license-p> </license>   <license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by/4.0/" xml:lang="ru" xlink:type="simple"> <license-p>Это произведение доступно по лицензии Creative Commons Attribution 4.0 International (CC BY 4.0)</license-p> </license>   </permissions>  </book-meta> <book-part book-part-type="conference-paper"> <book-part-meta>  <book-id pub-id-type="doi">10.21661/r-474921</book-id>   <book-id custom-type="publisher-id" pub-id-type="custom">474921</book-id> <title-group>  <chapter-title xml:lang="ru">SIEM – инструмент управления информационной безопасностью</chapter-title>   <trans-title-group xml:lang="en"> <trans-title>SIEM - instrument upravleniia informatsionnoi bezopasnost&#039;iu</trans-title> </trans-title-group>  </title-group>  <contrib-group>   <contrib contrib-type="author" id="author1">   <name-alternatives>  <name name-style="eastern" xml:lang="ru"> <surname>Кравцов</surname> <given-names>Андрей Андреевич</given-names> </name>   <name name-style="western" xml:lang="en"> <surname>Kravtsov</surname> <given-names>Andrei Andreevich</given-names> </name>   </name-alternatives>  <email xlink:type="simple">pupkin.andru@yandex.ru</email> <xref ref-type="aff" rid="aff1"/> </contrib>    <aff-alternatives id="aff1">   <aff xml:lang="ru">  <institution>ФГБОУ ВО «Государственный университет морского и речного флота им. адмирала С.О. Макарова»</institution>   <country>Россия</country> </aff>    <aff xml:lang="en">  <institution>FSFEI of HE &quot;Admiral Makarov State University of See and River Fleet”</institution>   <country>Russia</country> </aff>   </aff-alternatives>  </contrib-group>   <fpage>59</fpage> <lpage>67</lpage>   <abstract xml:lang="ru"> <p>в данной статье рассмотрены решения по управлению информацией и событиями безопасности – SIEM. Дано определение и указаны задачи, для которых применяются SIEM-системы. Приведены: базовые возможности, модульная структура и пример работы некоторой организации без/с внедрённой SIEM-системой. Проведён краткий обзор рынка и сравнение двух ведущих SIEM-систем на рынке. На основе обзора рынка и результатов сравнения даны рекомендации приобретению SIEM как систем централизованного ведения журнала регистрации и помощи в обнаружении, анализе и смягчении событий безопасности.</p> </abstract>           <kwd-group xml:lang="ru">  <kwd>сбор информации</kwd>  <kwd>анализ информации</kwd>  <kwd>управление безопасностью</kwd>  <kwd>SIEM</kwd>  <kwd>журналы событий</kwd>  </kwd-group>        </book-part-meta> </book-part> </front>  <back> <ref-list> <title>References</title>  <ref id="ref1"> <label>1</label> <citation-alternatives>  <mixed-citation xml:lang="ru">Security Information and Event Management (SIEM) [Электронный ресурс]. – Режим доступа: http://www.tadviser.ru/index.php/Статья:Security_Information_and_Event_Management_(SIEM)</mixed-citation>    </citation-alternatives> <element-citation publication-type="web">   <article-title>Security Information and Event Management (SIEM)</article-title>         <ext-link ext-link-type="uri" xlink:href="http://www.tadviser.ru/index.php/Статья">http://www.tadviser.ru/index.php/Статья</ext-link>      </element-citation> </ref>  <ref id="ref2"> <label>2</label> <citation-alternatives>  <mixed-citation xml:lang="ru">What is log management and how to choose the right tools [Электронный ресурс]. – Режим доступа: https://www.csoonline.com/article/2126060/network-security/network-security-what-is-log-management-and-how-to-choose-the-right-tools.html</mixed-citation>    </citation-alternatives> <element-citation publication-type="web">   <article-title>What is log management and how to choose the right tools</article-title>         <ext-link ext-link-type="uri" xlink:href="https://www.csoonline.com/article/2126060/network-security/network-security-what-is-log-management-and-how-to-choose-the-right-tools.html">https://www.csoonline.com/article/2126060/network-security/network-security-what-is-log-management-and-how-to-choose-the-right-tools.html</ext-link>      </element-citation> </ref>  <ref id="ref3"> <label>3</label> <citation-alternatives>  <mixed-citation xml:lang="ru">A comprehensive guide to SIEM products [Электронный ресурс]. – Режим доступа: https://searchsecurity.techtarget.com/feature/Introduction-to-SIEM-services-and-products</mixed-citation>    </citation-alternatives> <element-citation publication-type="web">   <article-title>A comprehensive guide to SIEM products</article-title>         <ext-link ext-link-type="uri" xlink:href="https://searchsecurity.techtarget.com/feature/Introduction-to-SIEM-services-and-products">https://searchsecurity.techtarget.com/feature/Introduction-to-SIEM-services-and-products</ext-link>      </element-citation> </ref>  <ref id="ref4"> <label>4</label> <citation-alternatives>  <mixed-citation xml:lang="ru">Top 10 SIEM Products [Электронный ресурс]. – Режим доступа: https://www.esecurityplanet.com/products/top-siem-products.html</mixed-citation>    </citation-alternatives> <element-citation publication-type="web">   <article-title>Top 10 SIEM Products</article-title>         <ext-link ext-link-type="uri" xlink:href="https://www.esecurityplanet.com/products/top-siem-products.html">https://www.esecurityplanet.com/products/top-siem-products.html</ext-link>      </element-citation> </ref>  <ref id="ref5"> <label>5</label> <citation-alternatives>  <mixed-citation xml:lang="ru">Evaluation criteria for SIEM [Электронный ресурс]. – Режим доступа: https://www.csoonline.com/article/2124605/network-security/network-security-evaluation-criteria-for-siem.html</mixed-citation>    </citation-alternatives> <element-citation publication-type="web">   <article-title>Evaluation criteria for SIEM</article-title>         <ext-link ext-link-type="uri" xlink:href="https://www.csoonline.com/article/2124605/network-security/network-security-evaluation-criteria-for-siem.html">https://www.csoonline.com/article/2124605/network-security/network-security-evaluation-criteria-for-siem.html</ext-link>      </element-citation> </ref>  <ref id="ref6"> <label>6</label> <citation-alternatives>  <mixed-citation xml:lang="ru">IBM QRadar vs. Splunk [Электронный ресурс]. – Режим доступа: https://www.itcentralstation.com/products/comparisons/ibm-qradar_vs_splunk</mixed-citation>    </citation-alternatives> <element-citation publication-type="web">   <article-title>IBM QRadar vs. Splunk</article-title>         <ext-link ext-link-type="uri" xlink:href="https://www.itcentralstation.com/products/comparisons/ibm-qradar_vs_splunk">https://www.itcentralstation.com/products/comparisons/ibm-qradar_vs_splunk</ext-link>      </element-citation> </ref>  <ref id="ref7"> <label>7</label> <citation-alternatives>  <mixed-citation xml:lang="ru">IBM QRadar vs. Splunk Enterprise [Электронный ресурс]. – Режим доступа: https://www.trustradius.com/compare-products/ibm-qradar-vs-splunk-enterprise</mixed-citation>    </citation-alternatives> <element-citation publication-type="web">   <article-title>IBM QRadar vs. Splunk Enterprise</article-title>         <ext-link ext-link-type="uri" xlink:href="https://www.trustradius.com/compare-products/ibm-qradar-vs-splunk-enterprise">https://www.trustradius.com/compare-products/ibm-qradar-vs-splunk-enterprise</ext-link>      </element-citation> </ref>  </ref-list> </back>  </book>