TL;DR: In this paper, a distributed software agent of a network security system determines a priority of each received security event, and stores the security events in a plurality of prioritized event buffers based on the determined priorities for a period of time determined by a timer.
Abstract: In one embodiment, the present invention provides for receiving security events from a network device by a distributed software agent of a network security system, determining a priority of each received security event, and storing the security events in a plurality of prioritized event buffers based on the determined priorities for a period of time determined by a timer. Upon expiration of the timer, a batch of security events for transport to a security event manager of the network security system can be created by including security events in the batch in order of priority until the batch is full.
TL;DR: In this article, a method and device for managing security events includes establishing a security event manager on a mobile computing device, which may be embodied as software and/or hardware components.
Abstract: A method and device for managing security events includes establishing a security event manager on a mobile computing device. The security event manager may be embodied as software and/or hardware components. The security event manager receives security event data from a plurality of security event sources of the mobile computing device and correlates the security event data based on a security policy to determine whether a security event has occurred. The security event manager responds to the security event based on the security policy.
TL;DR: A Security Event Manager (SEM) called the Grid Security Operation Center (GSOC) is proposed, which facilitates IT security managers in giving a view of the security of the whole grid network without compromising confidentiality of security data.