Ottimizzazione e monitoraggio del sistema di gestione degli eventi e delle informazioni ArcSight
View/ Open
Author
Urso, Federico <2004>
Date
2026-07-28Data available
2026-08-06Abstract
Come tutti sappiamo il mondo digitale è attualmente in espansione, vengono assegnati compiti
sempre più complicati e critici ai sistemi informatici e codesti sistemi sono sempre più un bersaglio
di attacchi da parte di organizzazioni criminali o stati ostili.
Attualmente le soluzioni per proteggere i sistemi informatici aziendali sono molteplici: firewall e apparati di rete con funzionalità di sicurezza per la segmentazione della rete, Endpoint Detection and Response (EDR) per i singoli dispositivi, Intrusion Detection / Prevention System (IDS/IPS) per analisi del traffico, Web Application Firewall (WAF) per i server web.
Ognuna di queste soluzioni dispone di una propria interfaccia di gestione e monitoraggio ed è in
grado di identificare gli attacchi solo da una specifica prospettiva dell’infrastruttura di rete. Dalla
necessità di disporre di una visione centralizzata e completa della sicurezza nasce l’esigenza dei
moderni sistemi SIEM.
Un Security Information and Event Management (SIEM) System è un sistema in grado di
raccogliere numerosi log generati da dispositivi di rete, server e altri sistemi informatici al fine di
identificare minacce informatiche, mitigare eventuali danni causati da esse e offrire tracciabilità
delle operazioni svolte dall’interno dell’azienda dal personale.
I log sopra citati sono la rappresentazione di un evento avvenuto in un sistema informatico, ad
esempio l’avvenuto accesso di un utente ad un computer o l’interruzione di un’applicazione.
La mia attività di tirocinio ha quindi previsto l’accrescimento della mia conoscenza rispetto al
sistema SIEM ArcSight, la sua ottimizzazione in modo che possa fornire delle “viste” rilevanti
sulle attività presenti nei sistemi dell’ARPAL e l’analisi delle attività in tempo reale in modo da
identificare eventuali minacce. Ho quindi prodotto Dashboard e Report che permettono la visualizzazione di dati rilevanti e
personalizzati per i sistemi presenti nell’ARPAL, un software di inoltro di eventi As we all know, the digital world is currently expanding with increasingly complex and critical
tasks being assigned to IT systems which are more and more becoming targets for criminal
organizations or hostile states.
There are currently many solutions for protecting such corporate IT systems: firewalls and network devices with security features for network segmentation, Endpoint Detection and Response (EDR) for single devices, Intrusion Detection/Prevention Systems (IDS/IPS) for traffic analysis, Web Application Firewalls (WAF) for web servers.
Each of these solutions has its own management and monitoring interface and can only identify
attacks from a specific perspective of the network infrastructure. The need for a centralized and
comprehensive view of security has led to the need for modern SIEM systems.
A Security Information and Event Management (SIEM) system is capable of collecting numerous
event logs generated by network devices, servers, and other IT systems in order to perform various
activities including identifying cyber threats and provide traceability of staff operations.
The above-mentioned log represent an event that occurred in an IT system, such as a user's
successful login or the unexpected termination of an application.
My internship therefore involved increasing my knowledge of the ArcSight SIEM system,
optimizing it to provide relevant "views" of the activities in ARPAL's systems and analyzing real
time events to identify potential threats. I produced dashboards and reports that allow the visualization of relevant and customized data for
the systems in ARPAL, an event forwarding software that allows the integration of data relating to
ARPAL phishing campaigns into the Arcsight SIEM and new correlation rules that can identify a
specific attack chain that I hypothesized.
Type
info:eu-repo/semantics/bachelorThesisCollections
- Laurea Triennale [4980]

