作者
Muhammad Afzaal, Cesario Di Sarno, Luigi Coppolino, Salvatore D'Antonio, Luigi Romano
发表日期
2012/10/25
研讨会论文
2012 IEEE 14th international symposium on high-assurance systems engineering
页码范围
48-55
出版商
IEEE
简介
In Critical Infrastructures, forensic analysis of stored events is an essential task when a security breach occurs. The goal of forensic analysis is to provide evidence to be used as valid proofs in a legal proceeding. So, it is very important to ensure the integrity of the events stored in order to perform a correct forensic analysis. Today, most of the SIEMs used to protect the Critical Infrastructures sign the security events with RSA classic algorithm in order to ensure their integrity. The signed security events cannot be admissible as evidence if the secret key is compromised, or when the module responsible for signing operations is down for any reason. In this paper a new architecture that overcomes these limitations has been proposed. Experimental tests show the performance of our architecture and the high resilience in faulty situations, i.e. some nodes are under attack.
引用总数
20112012201320142015201620172018201920202021202220232024114104101123152
学术搜索中的文章
M Afzaal, C Di Sarno, L Coppolino, S D'Antonio… - 2012 IEEE 14th international symposium on high …, 2012