login
Home / Papers / Present and Future of Network Security Monitoring

Present and Future of Network Security Monitoring

22 Citations•2021•
M. Fuentes-García, J. Camacho, G. Maciá-Fernández
IEEE Access

This paper reviews the state-of-the-art in NSM, and derives a new taxonomy of the functionalities and modules in an NSM system, which is useful to assess current NSM deployments and tools for both researchers and practitioners.

Abstract

Network Security Monitoring (NSM) is a popular term to refer to the detection of security incidents by monitoring the network events. An NSM system is central for the security of current networks, given the escalation in sophistication of cyberwarfare. In this paper, we review the state-of-the-art in NSM, and derive a new taxonomy of the functionalities and modules in an NSM system. This taxonomy is useful to assess current NSM deployments and tools for both researchers and practitioners. We organize a list of popular tools according to this new taxonomy, and identify challenges in the application of NSM in modern network deployments, like Software Defined Network (SDN) and Internet of Things (IoT).