Logo do repositório
 
Publicação

HANDLING CYBERSECURITY RELATED INCIDENTS IN THE SECURITY OPERATION CENTER OF THE POLYTECHNIC OF LEIRIA

datacite.subject.fosEngenharia e Tecnologia::Engenharia Eletrotécnica, Eletrónica e Informáticapt_PT
dc.contributor.advisorRabadão, Carlos Manuel da Silva
dc.contributor.advisorOliveira, Adail Domingues da Silva de
dc.contributor.authorMateus, Marco Alexandre Clemente
dc.date.accessioned2022-02-21T14:12:48Z
dc.date.available2022-02-21T14:12:48Z
dc.date.issued2021-12-06
dc.description.abstractIn the present day, IT systems are an integral part of most organizations, and play a huge role it their success. With the necessity to connect these systems to the internet to further amplify their benefits and possibilities, comes the issue of cybersecurity. Allied to the importance of these systems for the organizations, comes the interest of attackers in disrupting these same services. When the amount of cyberattacks occurring everyday is taken into consideration, and how these might impact organizations, this issue becomes one of the greatest challenges they have to deal with. The problems that this project deals with is fundamentally connect with this issue. With the variety of attacks that currently circulates Security Operations Center (SOC) rely on many different software to monitor their systems, which in turn create too much information to be handled individually by security analysts. In this project this issue was analyzed, as well how it can be handled, as the main objective of this is project is to find a solution for the SOC of the Instituto Politécnico de Leiria (IPLeiria) which is facing this very same issue. The proposed solution to this problem is through Security Orchestration, Automation and Response (SOAR). SOAR encompasses different concepts that help in creating effective and efficient routines to handles the incidents that a SOC faces on a daily basis. To tackle this problem in the case of the IPLeiria SOC, the solution found relied on the use of a SOAR platform or software. For this effect different solutions available were analysed, including free and paid software. The choice came down to using a free software called Shuffle 1 in conjunction with the already existent in the IPLeiria SOC case management platform TheHive 2. With these two tools, different playbooks were developed to handle the most prominent type of incidents the SOC faces.pt_PT
dc.identifier.tid202944310pt_PT
dc.identifier.urihttp://hdl.handle.net/10400.8/6695
dc.language.isoengpt_PT
dc.subjectCybersecuritypt_PT
dc.subjectSecurity Operations Center (SOC)pt_PT
dc.subjectSecurity Orchestration Automation and Response (SOAR) x Softwarept_PT
dc.subjectInformation securitypt_PT
dc.subjectPolitécnico de Leiriapt_PT
dc.titleHANDLING CYBERSECURITY RELATED INCIDENTS IN THE SECURITY OPERATION CENTER OF THE POLYTECHNIC OF LEIRIApt_PT
dc.typemaster thesis
dspace.entity.typePublication
rcaap.rightsopenAccesspt_PT
rcaap.typemasterThesispt_PT
thesis.degree.nameMestrado em Cibersegurança e Informática Forensept_PT

Ficheiros

Principais
A mostrar 1 - 1 de 1
A carregar...
Miniatura
Nome:
Projeto_MarcoMateus_2190376.pdf
Tamanho:
8.44 MB
Formato:
Adobe Portable Document Format
Descrição: