Article citationsMore >>

Waltz, E. (2000, June). Data fusion in offensive and defensive information operations. In NSSDF Symposium.

has been cited by the following article:

Article

Cybersecurity Data Sources and Practices

1Institute for IT Innovation and Smart Health, Mississippi, USA

2Institute for Systems Engineering Research, Mississippi State University, Mississippi, USA


Journal of Computer Networks. 2024, Vol. 12 No. 1, 1-6
DOI: 10.12691/jcn-12-1-1
Copyright © 2024 Science and Education Publishing

Cite this paper:
Cheryl Ann Alexander, Lidong Wang. Cybersecurity Data Sources and Practices. Journal of Computer Networks. 2024; 12(1):1-6. doi: 10.12691/jcn-12-1-1.

Correspondence to: Cheryl  Ann Alexander, Institute for IT Innovation and Smart Health, Mississippi, USA. Email: cheryl.alexander@techhealthsolutions.org

Abstract

Today, with technology exploding in every organization, massive amounts of data are being generated, thus, approaches to processing such huge amounts of data are necessary and key to threat detection and cybersecurity. Currently, artificial intelligence (AI)/machine learning (ML), and cyber automation help to process these huge amounts of data, however, much of the data is unstructured and unlabeled and can be a considerable challenge for off-the-shelf AI/ML. This paper introduces cybersecurity data sources; the functions, features, limitations, and future trends of security information and event management (SIEM); potential enhancements of future SIEM; offense data and defense data; and data sources and AI for SIEM. Cybersecurity data sources and practices are also discussed in a large medical center as a case study. Data sources in healthcare can be internal or external. Offensive and defensive strategies must include where the data comes from and how the data is used. A future enhancement of SIEM is beneficial such as improving prediction, detection, correlation, and reaction capabilities. Networks are the platform of cyber data sources and practices (such as data storage and transfer), networked medical equipment, health monitoring, SIEM, and even malicious attacks. A key to robust cybersecurity is to enhance the security of computer networks.

Keywords