Bakalářská práce

Gathering Information from Community Threat Intelligence Platform

Šimon Bezek
Anotace

Táto práca poskytuje náhľad na základy kybernetického spravodajstva o hrozbách, enumerácie a platformy pre spravodajstvo o hrozbách, so zameraním na platformu OTX a znalostnú bázu MITRE ATT&CK. Analýzy údajov z týchto zdrojov poskytujú dodatočný pohľad na to, ako získané údaje dopĺňajú enumeráciu CVE a znalostnú bázu ATT&CK. Dodatočné štatistiky určujú krajiny napádané najväčším počtom útokov a zoznam …více

Abstract

This thesis provides insight into the fundamentals of cyber threat intelligence, enumerations, and threat intelligence platforms, focusing on the OTX platform and MITRE ATT&CK knowledge base. Analyses of data from these sources provide an additional view of how the obtained data complements the CVE enumeration and ATT&CK knowledge base. Additional statistics determine the top countries targeted by …více

Zadání práce
Several cybersecurity enumerations and knowledge bases allow sharing information about vulnerabilities or types of attacks. Examples are Common Vulnerabilities and Exposures (CVE) and MITRE ATT&CK. Threat intelligence platforms provide data about cyber threats complementing the data about vulnerabilities and types of attacks. This bachelor thesis aims to create a tool that gathers data from a community threat intelligence platform called Open Threat Exchange (OTX) and complements it with the content of the MITRE ATT&CK knowledge base. Consequently, the thesis analyzes obtained data. The thesis consists of the following subtasks:
  • Familiarize with OTX and MITRE ATT&CK.
  • Create a tool that obtains data from the OTX platform and parses the content of the MITRE ATT&CK knowledge base according to the supervisor’s requirements. Create a suitable representation of data stored in a graph database Neo4j.
  • Implement an algorithm that determines the level of trust for individual users of OTX based on relationships subscribe and follow. Analyze to what extent it is beneficial to download data from users in the distance of n relationships follow or subscribe from a trusted user.
  • Analyze how and to what extent the obtained information complements information from the enumerations about vulnerabilities and types of attacks.

Implementation should be prepared so that its launching requires the least possible number of manual steps.

Práce zkontrolována:
20. 5. 2022 09:26, RNDr. Lukáš Sadlek, Ph.D., učo 445581
Jazyk práce
angličtina angličtina
Termín obhajoby
27. 6. 2022
Práce byla úspěšně obhájena

Vedoucí

RNDr. Lukáš Sadlek, Ph.D., učo 445581
PB DKSD ÚVT MU

Oponent

RNDr. Daniel Tovarňák, Ph.D., učo 172673
TR DKSD ÚVT MU

Masarykova univerzita Fakulta informatiky
Studijní program
Informatika
  • Přidání souboru

    Soubor nebo složku lze nahrát pomocí tlačítka Přidat.
  • Další operace se soubory

    Podrobnosti lze zjistit označením příslušného řádku.
  • Pohled pro experty

    Pro častou práci je možné zvolit režim Více možností.
  • Vyhledávání souborů

    Vyhledávaný výraz můžete zadat přímo do adresního řádku.
  • Rychlý přístup k souborům

    Pomocí funkce Nedávné je možné se rychle vrátit k právě prohlíženým souborům. Oblíbené soubory je také možné označit Hvězdičkou.