Many preventive security measures have been proposed to protect network from cyber intrusions. Many of the adopted measures generate a large amount of information that should be stored and analyzed to enable response actions to detected attacks. A Security Information and Event Manager (SIEM) has become an indispensable tool to collect all of a system´s security-related information in a central repository. This can then be used for trend analysis and adoption of appropriate actions. In this article, we present a collaborative work approach between SIEMs of different trusted domains that share alarms and the consequent adopted countermeasures. These have been based on traffic patterns related to offered online services. The concept of sharing alarms and adopted measures in domains with similar profiles, intends to enhance a global view of the security and, by this way, facilitate decision-making for security domain administrators.
