SOC R&D
One of our main research directions is the expansion and continuous development of our Security Operations Center (SOC), which is currently operating on campus and built with open-source tools. This will primarily involve optimization based on log and monitoring data from SOC-connected devices, but we are also working on broader solutions for attack detection. In a general network, we will fine-tune devices used on the defense side, such as firewalls, intrusion prevention/intrusion detection, antivirus and others, by analyzing data coming into the SOC, where appropriate using machine learning assisted methods. The result of the research is applied in various research, development and consultancy projects to prepare the systems and human resource of our partners to be cyber resilient.
Related thesis / dissertation topics HERE...
- Logelemzés – a SOC-ba kötött eszközök naplózási adataiból érkező adatok feldolgozása prevenció, optimalizálás és hálózat védelmének megerősítése céljából
- Az egyetemi SOC rendszerhez tartozó felhasználókezelési rendszer megtervezése, összeállítása és implementálása
- SOC továbbfejlesztése SIEM megoldással
- Forgalomelemzésen alapuló felhasználói profilozás
- Felhasználói profilozáson alapuló behatolás detektálás
- IDS/IPS rendszerek optimalizálása biztonsági műveleti központban
- Biztonsági platformok vizsgálata (Security Onion, Opensearch, OSSIM)
- Kártékony programok viselkedésének elemzése, működési mechanizmusuk visszafejtése, felismerésükre automatizált folyamatok kialakítása
- Víruskereső módszerek és megoldások feltérképezése, ezek összehasonlítása a SOC követelményeit is figyelembe vevő szempontrendszer alapján, továbbá az optimális megoldás megvalósítása és tesztelése
