Claim Missing Document
Check
Articles

Found 1 Documents
Search

Analysis of the Effectiveness of Security Information and Event Management (SIEM) Detection Against Advanced Threats Dilla Ghaisani Putri
Greenation International Journal of Engineering Science Vol. 3 No. 3 (2025): (GIJES) Greenation International Journal of Engineering Science (September - No
Publisher : Greenation Research & Yayasan Global Resarch National

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.38035/gijes.v3i3.849

Abstract

Advanced Persistent Threats (APTs) pose a serious challenge to information systems security. APTs employ complex and persistent techniques to achieve their goal of infiltrating an organization’s network. APTs often operate undetected for prolonged periods, which can last months or even years. The combination of intricate techniques and long-term persistence is what makes APTs so difficult to detect and counter. Security Information and Event Management (SIEM) is a type of security solution used for cyber threat detection and response. This research analyzed the effectiveness of SIEM in detecting APTs based on parameters such as detection speed, accuracy, and false positive rate. Simulations of repeated attacks demonstrate that SIEM expands security visibility and enhances the network’s ability to respond to attacks rapidly. However, large log volumes present a challenge to the entire system, and optimal configuration incurs a high cost for such analysis.