Skip to content

Use Case: Support event data analysis from a diverse set of sensors

Ivan Kirillov edited this page Sep 23, 2015 · 4 revisions

Abstraction Level: Medium

Related Use Cases

Description

The ability to characterize various types of event data as generated from different types of sensors (e.g., DPI, IDS, etc.) and having such data in a standardized format can assist with correlation, aggregation, and analysis. Accordingly, such analysis can have multiple outcomes, including the generation of indicators for malicious activity detection, supporting threat actor attribution, etc.

Requirements

  1. The ability to characterize event data
  2. The ability to characterize a diverse range of sensor outputs

Applicable Domains

  • Indicator sharing
  • Malware analysis
  • Incident response
Clone this wiki locally