Academic Journal

An Overview of EDR Serviceability for Security Information and Event Management (SIEM).

Λεπτομέρειες βιβλιογραφικής εγγραφής
Τίτλος: An Overview of EDR Serviceability for Security Information and Event Management (SIEM).
Συγγραφείς: Pradhan, Padma Lochan
Πηγή: Journal of Information Assurance & Security; 2026, Vol. 21 Issue 2, p52-88, 37p
Θεματικοί όροι: Anomaly detection (Computer security), Machine learning, Internet security, Data analytics, Open source software, Artificial intelligence
Περίληψη: This review paper focuses on and addresses Endpoint Detection and Response (EDR) tools, providing an overview of their purpose, functions, operations, services, and benefits within the cybersecurity landscape. Specifically, EDR solutions are designed to detect, prevent, investigate, and respond to advanced cyber threats that often bypass traditional antivirus programs. To achieve this, these tools continuously collect and analyze data in real time using behavioral analytics, artificial intelligence (AI), and machine learning (ML). This enables the identification of anomalous activities and sophisticated attack patterns, such as zero-day exploits and fileless malware. Furthermore, the integration of open-source tools strengthens an organization's security posture by enhancing service capabilities, scalability, reliability, and availability. The paper also discusses the evolution of EDR from standalone tools to integrated, interoperable, automated, and intelligence-driven platforms that utilize behavioral and predictive analysis to counter increasingly sophisticated threats. Such integration, in turn, enables faster decision-making while reducing code complexity, operational costs, and response times. Ultimately, the sustainability of open-source tools contributes to higher quality, improved performance, effective cost management, better decision-making, and reduced risk. In summary, this review synthesizes key developments and innovations in the EDR-SIEM domain, drawing from academic research, industry analysis, and real-world applications. [ABSTRACT FROM AUTHOR]
Copyright of Journal of Information Assurance & Security is the property of Paradigm Publishing Services and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Βάση Δεδομένων: Complementary Index
Περιγραφή
ISSN:15541010
DOI:10.2478/ias-2026-0004