Bakalářská práce

Gathering Information about Cyber Threats

Michal Cikatricis
Anotace

Táto práca popisuje požiadavky kladené na informácie o kyber hrozbách. Ďalej nám predstaví platformu MISP a framework VERIS, ktoré ich schémami podporujú ukladanie a spracovanie informacií o kyber hrozbách. Nakoniec nás oboznámi s vedomostnou základňou MITRE ATT&CK a enumeráciou CVE, ktoré sa používajú na spresnenie opisu bezpečnostných incidentov. Práca objasňuje úlohu zdrojov informácií a dátových …více

Abstract

This thesis describes the requirements for creating cyber-threat intelligence. Moreover, it introduces us to the platform MISP and framework VERIS supporting cyber-threat intelligence storing and processing with its schemas. Finally, it acquaints us with the knowledge base MITRE ATT\&CK and enumeration CVE used for a more accurate description of incidents transformed into cyber-threat intelligence …více

Zadání práce
Several cybersecurity enumerations and knowledge bases allow sharing information about vulnerabilities or types of attacks. Examples are Common Vulnerabilities and Exposures (CVE) and MITRE ATT&CK. Sources describing cyber threats and incidents complement the data about vulnerabilities and types of attacks. This bachelor thesis aims to create a tool that gathers data from an open-source threat intelligence platform MISP (Malware Information Sharing Platform) and from a community database of VERIS (Vocabulary for Event Recording and Incident Sharing) called VCDB (VERIS Community Database). The thesis consists of the following subtasks:
  • Familiarize with MISP, VCDB, and mapping of VERIS to MITRE ATT&CK.
  • Create a tool that obtains data from selected sources of the MISP platform and from VCDB. Parse mapping of VERIS to MITRE ATT&CK.
  • Create a suitable representation of data stored in a graph database Neo4j.
  • Analyze how and to what extent the obtained information complements information from the enumerations about vulnerabilities and types of attacks.

Implementation should be prepared so that its launching requires the least possible number of manual steps.

Práce zkontrolována:
20. 5. 2022 09:27, RNDr. Lukáš Sadlek, Ph.D., učo 445581
Jazyk práce
angličtina angličtina
Termín obhajoby
27. 6. 2022
Práce byla úspěšně obhájena

Vedoucí

RNDr. Lukáš Sadlek, Ph.D., učo 445581
PB DKSD ÚVT MU

Oponent

RNDr. Daniel Tovarňák, Ph.D., učo 172673
TR DKSD ÚVT MU

Masarykova univerzita Fakulta informatiky
Studijní program
Aplikovaná informatika
  • Přidání souboru

    Soubor nebo složku lze nahrát pomocí tlačítka Přidat.
  • Další operace se soubory

    Podrobnosti lze zjistit označením příslušného řádku.
  • Pohled pro experty

    Pro častou práci je možné zvolit režim Více možností.
  • Vyhledávání souborů

    Vyhledávaný výraz můžete zadat přímo do adresního řádku.
  • Rychlý přístup k souborům

    Pomocí funkce Nedávné je možné se rychle vrátit k právě prohlíženým souborům. Oblíbené soubory je také možné označit Hvězdičkou.