Javascript must be enabled to continue!
Systematic Review of SIEM Integration for Threat Detection and Log Correlation in AWS-Based Infrastructure
View through CrossRef
The increasing migration of enterprise operations to Amazon Web Services (AWS) has amplified the need for robust, scalable, and intelligent cybersecurity solutions. Security Information and Event Management (SIEM) systems have become vital for detecting threats, correlating logs, and maintaining compliance in cloud environments. This systematic review explores the integration of SIEM tools within AWS-based infrastructures, focusing on their effectiveness in threat detection and log correlation. It examines leading SIEM solutions such as Splunk, IBM QRadar, Sumo Logic, and AWS-native services like Amazon GuardDuty, AWS CloudTrail, and AWS Security Hub. Emphasis is placed on key integration approaches, including API-based ingestion, agentless data capture, and real-time event streaming through AWS services like Kinesis and S3. The review critically analyzes studies published between 2018 and 2023, highlighting trends in the automation of log management, enrichment of security alerts through machine learning, and orchestration via Security Orchestration, Automation, and Response (SOAR) platforms. Challenges such as data normalization, scalability limitations, cross-service visibility, and compliance adherence in multi-account AWS architectures are discussed. The findings indicate that SIEM integration enhances threat detection efficiency by enabling proactive anomaly detection, facilitating rapid incident response, and improving forensic investigation capabilities. However, the review identifies gaps, particularly in cost optimization, handling high-velocity log streams, and adapting traditional SIEM models to dynamic, serverless AWS architectures. Best practices for successful SIEM deployment include leveraging AWS-native integrations, prioritizing event prioritization algorithms, applying continuous tuning, and aligning with security frameworks like NIST and CIS AWS Foundations Benchmark. Future research directions propose the development of AI-driven adaptive SIEM systems tailored for cloud-native environments, advanced correlation engines for serverless and containerized workloads, and strategies to optimize licensing and resource utilization. This systematic review provides cybersecurity practitioners, cloud architects, and researchers with a comprehensive understanding of SIEM integration complexities and evolving practices in AWS infrastructures, ultimately contributing to improved cloud security postures and operational resilience in the face of sophisticated cyber threats.
Title: Systematic Review of SIEM Integration for Threat Detection and Log Correlation in AWS-Based Infrastructure
Description:
The increasing migration of enterprise operations to Amazon Web Services (AWS) has amplified the need for robust, scalable, and intelligent cybersecurity solutions.
Security Information and Event Management (SIEM) systems have become vital for detecting threats, correlating logs, and maintaining compliance in cloud environments.
This systematic review explores the integration of SIEM tools within AWS-based infrastructures, focusing on their effectiveness in threat detection and log correlation.
It examines leading SIEM solutions such as Splunk, IBM QRadar, Sumo Logic, and AWS-native services like Amazon GuardDuty, AWS CloudTrail, and AWS Security Hub.
Emphasis is placed on key integration approaches, including API-based ingestion, agentless data capture, and real-time event streaming through AWS services like Kinesis and S3.
The review critically analyzes studies published between 2018 and 2023, highlighting trends in the automation of log management, enrichment of security alerts through machine learning, and orchestration via Security Orchestration, Automation, and Response (SOAR) platforms.
Challenges such as data normalization, scalability limitations, cross-service visibility, and compliance adherence in multi-account AWS architectures are discussed.
The findings indicate that SIEM integration enhances threat detection efficiency by enabling proactive anomaly detection, facilitating rapid incident response, and improving forensic investigation capabilities.
However, the review identifies gaps, particularly in cost optimization, handling high-velocity log streams, and adapting traditional SIEM models to dynamic, serverless AWS architectures.
Best practices for successful SIEM deployment include leveraging AWS-native integrations, prioritizing event prioritization algorithms, applying continuous tuning, and aligning with security frameworks like NIST and CIS AWS Foundations Benchmark.
Future research directions propose the development of AI-driven adaptive SIEM systems tailored for cloud-native environments, advanced correlation engines for serverless and containerized workloads, and strategies to optimize licensing and resource utilization.
This systematic review provides cybersecurity practitioners, cloud architects, and researchers with a comprehensive understanding of SIEM integration complexities and evolving practices in AWS infrastructures, ultimately contributing to improved cloud security postures and operational resilience in the face of sophisticated cyber threats.
Related Results
Impact of water demand for irrigation on the water availability of the Urubu River in Brazil 
Impact of water demand for irrigation on the water availability of the Urubu River in Brazil 
<p>There are 37 hydraulic water catchment pumps installed in the Urubu River hydrographic basin, located in an important agricultural area in the northern region of B...
Open source SIEM solutions for an enterprise
Open source SIEM solutions for an enterprise
Purpose
The security of applications, systems and networks has always been the source of great concern for both enterprises and common users. Different security...
Evaluating the Science to Inform the Physical Activity Guidelines for Americans Midcourse Report
Evaluating the Science to Inform the Physical Activity Guidelines for Americans Midcourse Report
Abstract
The Physical Activity Guidelines for Americans (Guidelines) advises older adults to be as active as possible. Yet, despite the well documented benefits of physical activi...
Securing Systems using SIEM and FIM Tools
Securing Systems using SIEM and FIM Tools
Today, computer networks are heavily documented security issues, making it impractical to manage them without Security Event Management (SIEM). A SIEM solution sets the controls ev...
Real-Time Patient Monitoring and Alerting in Hospitals Using AWS Lake House Architecture
Real-Time Patient Monitoring and Alerting in Hospitals Using AWS Lake House Architecture
A modern data architecture that integrates the capabilities of a data lake and a data warehouse into a single, cohesive platform is an Amazon Web Services (AWS) Lake House. It prov...
An overview of AWS
An overview of AWS
The provision of scalable, on-demand computer resources via the internet has brought about a revolution in the IT sector through cloud computing. Amazon Web Services (AWS) is a lea...
Cognitive bias and stuttering in adolescence
Cognitive bias and stuttering in adolescence
<p>Purpose: The tendency to prioritize negative or threatening social information, a cognitive process known as cognitive bias, has been linked to the development of social a...
Large-Scale SAP HANA Database Backup and Restoration on AWS Cloud Infrastructure
Large-Scale SAP HANA Database Backup and Restoration on AWS Cloud Infrastructure
The migration of SAP HANA databases to AWS cloud infrastructure represents a fundamental transformation in enterprise resource planning systems management, enabling organizations t...

