Leveraging Security Management with Low-Level System Monitoring and Visualization

Karlen Avogian,Basel Sababa,Ioanna Dionysiou,Harald Gjermundrød
DOI: https://doi.org/10.1007/978-3-030-71017-0_30
2021-01-01
Abstract:Preventing security breaches in today’s heterogeneous and diverse environment is nontrivial, despite the abundance of security products and technologies in the market, as the attack surface is simply too broad. This paper presents SMAD, an open-source security monitoring tool that monitors kernel and system resources data and aims to detect abnormal activity on a Linux server. As it is not uncommon for users to maintain personal home servers, SMAD empowers these novice administrators with a tool to track their Linux server’s health in an intuitive and user-friendly manner. The user-centric SMAD environment allows the specifications of monitors, alerts, and anomaly detection rules to be done in a free-of-errors manner.
What problem does this paper attempt to address?