Investigating the applicability of attack graphs in SOC environments
Identification of vulnerabilities, security analysis and risk assessment, which are essential to identify and improve the security level of a network. It is also important for risk assessment to visualize the correlations between the attack actions that attackers can take. Tree structure-based or graph-based models are commonly used to represent attack paths. However, the use of these methods poses scalability problems and existing graph and tree generating applications usually have a very limited toolbox. The main thrust of our research is to implement an attack graph generator stored in a graph database that meets our own requirements, which will help to further optimize the functions supported by the SOC by scanning, analyzing and evaluating the data stored in our other research topics.
Related thesis / dissertation topics HERE...
- A gráf adatbázis adatgyűjtő szolgáltatásának megvalósítása
- Hálózatfelderítési modul megépítése
- A gráf adatbázis és a vizualizációs réteg közötti kommunikációs interfész implementálása
- Támadási gráfok automatikus megjelenítése nyílt forráskodú eszközökkel
- IDS/IPS rendszerek optimalizálása a támadási gráfok segítségével beazonosítható true pozitív támadásokkal
