You are currently viewing Cyber situational awareness in the network security

Cyber situational awareness in the network security

Práca

Autor: doc. RNDr. JUDr. Pavol Sokol, PhD.

Abstrakt

Cyber security is an ever-evolving field due to the ever-changing cyberspace and its technologies. It also affects the usual approaches and procedures. Understanding the changing cyberspace is now essential to ensure cybersecurity. Perception and understanding of the current cyber situation help the organization to respond adequately to security threats. For several years now, there has been a trend toward moving from dealing with a cyber security incident (reactive activities) to preventing it (proactive activities). Situational awareness has a wide application in various areas of social life. One of these areas is cyber situational awareness. The results of our research activities in cyber situational awareness are summarized in this work. The thesis is based on several published research papers. Nine of these works are part of the appendix to this thesis. The first research area of cyber situational awareness is perception. We focused on deception systems, especially traps for attackers (honeypots) in this area. The thesis contains a summary of the analysis of privacy and processing of personal data in the design, deployment, and operation of honeypots. The second area of cyber situational awareness is understanding. In this area, we focused mainly on profiling the threat agents (attackers) and the behavior of botnets in the first two phases of their life cycle, in the so-called early and secondary stages of infection. Also, we summarized the results from the area of multi-stage attacks and the assessment of the skill level of threat agents (attackers) based on the analysis of meta-alerts. The projection of the future state represents the third, highest level of cyber situational awareness. This projection is closely related to cyber security predictive analysis. In this thesis, we summarize the results of attack projection and situational awareness prediction. We describe the early detection of cyber-attacks based on attack projection. Also, we present the results related to the forecasting of network situational awareness based on statistical methods and neural network methods.

Ciele

Zatiaľ nezverejnené

Literatúra

Zatiaľ nezverejnené

Priebeh práce

Zatiaľ nezverejnené