Bakalářská práce

Processing of DNS BIND server logs for Cybersecurity Incident Response Teams

Jiří Šimek
Anotace

Cílem této práce je vytvořit nástroj pro analýzu logů DNS serveru pro potřeby Kyberbezpečnostního týmu Masarykovy univerzity. V rámci práce má být vytvořena konfigurace pro zpracování logů a jejich normalizaci za účely datové analýzy. Data pak budou předána architektuře Elastic stack, kterou budou zpracována a vizualizována v aplikaci Kibana. Výstupem práce je dashboard v aplikaci Kibana, jehož cílem …více

Abstract

The main goal of this thesis is to create a DNS server log analysis tool for the needs of the Cybersecurity Incident Response Team of Masaryk University. This goal will be achieved by implementing a pipeline, which receives raw logs produced by the server's logging service, extracts relevant information from the logs, and restructures them for the purpose of data analysis. The data is then shipped …více

Zadání práce
As part of the bachelor's thesis, the student will get acquainted with the issues of processing and security monitoring of DNS server logs. The student will get access to an anonymized dataset of logs collected from BIND servers operating the DNS service, connected to the Masaryk University network. In this dataset, the student first describes the features of the records that appear in the log. Then creates a Syslog-ng configuration that normalizes log events and transports them to the Elasticsearch-Logstash-Kibana (ELK) system. Finally, in cooperation with CSIRT-MU security staff, the student identifies features and metrics that should be monitored in the DNS server log considering the cybersecurity point of view of and creates visualization plugins for them within the Kibana dashboard.
The output of the work will be the configuration of all tools used for log processing and dashboard in Kibana, containing visualizations of features of interest.

The work procedure will consist of the following steps:
  • Learn how to log in BIND DNS, Syslog-ng, and ELK
  • Description of DNS log features
  • Log normalization
  • Identification of features of interest that may occur in DNS queries in the MU network
  • Design visualizations for identified features in Kibana
  • Implement proposed visualizations within the Kibana dashboard
Práce zkontrolována:
20. 12. 2021 10:23, RNDr. Stanislav Špaček, Ph.D., učo 324802
Jazyk práce
angličtina angličtina
Termín obhajoby
9. 2. 2022
Práce byla úspěšně obhájena

Vedoucí

RNDr. Stanislav Špaček, Ph.D., učo 324802
PB DKSD ÚVT MU

Oponent

RNDr. Martin Laštovička, Ph.D., učo 395855
TCSIRT DKSD ÚVT MU

Masarykova univerzita Fakulta informatiky
Studijní program
Aplikovaná informatika
  • Přidání souboru

    Soubor nebo složku lze nahrát pomocí tlačítka Přidat.
  • Další operace se soubory

    Podrobnosti lze zjistit označením příslušného řádku.
  • Pohled pro experty

    Pro častou práci je možné zvolit režim Více možností.
  • Vyhledávání souborů

    Vyhledávaný výraz můžete zadat přímo do adresního řádku.
  • Rychlý přístup k souborům

    Pomocí funkce Nedávné je možné se rychle vrátit k právě prohlíženým souborům. Oblíbené soubory je také možné označit Hvězdičkou.