What is 事件关联?
In this glossary, 事件关联 refers to: The process of analyzing and combining related security events from multiple sources to identify patterns indicative of incidents or attacks.
How is 事件关联 used in cybersecurity?
In cybersecurity communication, this term appears in contexts such as: "SIEM中的事件关联汇总来自多个系统的日志,以检测协同攻击和复杂安全事件。"
Why does 事件关联 matter in cybersecurity?
事件关联 matters because it supports clear communication in SOC contexts for SOC Analysts, Security Engineers, and Incident Responders. It also connects to aviation training and exam language such as CISSP, CompTIA Security+, and CEH.
Who uses 事件关联?
事件关联 is mainly used by SOC Analysts, Security Engineers, and Incident Responders.
What category does 事件关联 belong to?
In this glossary, 事件关联 is grouped under SOC. Related pages in this category explain adjacent procedures, commands and operational concepts.
Where does this definition come from?
This definition is sourced from ISO 27001, NIST Cybersecurity Framework, MITRE ATT&CK and published by Protermify Cybersecurity as a static cybersecurity reference page.