, 13 2017 . 17:15
+
, Alienvault OSSIM (USM) . .. - , SIEM . SIEM . , - - lookup/active DST_IP, SRC_IP, DST_PORT, SRC_PORT.
SEC (Simple Event Correlator) OSSIM/USM.
-> https://habrahabr.ru/post/340042/
:
author shudv
linux
ossim
sec
alienvault
simple event correlator