Publication:
An Open-Source Solution for Corporates to Implement Scenario based Intrusion Detection for Incident Response

dc.contributor.authorKithulgoda, D.S.
dc.date.accessioned2022-08-24T06:50:17Z
dc.date.available2022-08-24T06:50:17Z
dc.date.issued2021
dc.description.abstractDetecting potential security compromises to aid in formulating a proactive response strategy is still a relatively new field in the local network security arena. Even managed security service providers who support these corporates on different digital security tiers face difficulties when using practical implementations that have the capability to detect and escalate to relevant parties for mitigation. This research discusses how a third-tier detection strategy can be developed with open-source toolkits like the Snort intrusion detection system as the second line of defense to support network teams. The necessity of auxiliary packages to work along with Snort must be stressed upon because the demands are higher in corporate environment settings. Some examples include Zeek and Security Onion. The placement of an IDS to perform as expected requires careful planning after a thorough examination of the relevant network diagrams. For this, the recommendation is to use dedicated hardware composed of all tools mentioned on an ad-hoc basis with a switch-span setup. It is also commonly known as port mirroring, so that an exact copy of the traffic that flows can be fed for investigation. To suit the Sri Lankan context, a stripped-down version of the MITRE ATT&CK + SHIELD Active Defense Matrix will be used to choose the applied malicious datasets and for designing the security playbooksen_US
dc.identifier.urihttps://rda.sliit.lk/handle/123456789/2928
dc.language.isoenen_US
dc.titleAn Open-Source Solution for Corporates to Implement Scenario based Intrusion Detection for Incident Responseen_US
dc.typeThesisen_US
dspace.entity.typePublication

Files

Original bundle

Now showing 1 - 2 of 2
No Thumbnail Available
Name:
MS20907198.pdf
Size:
2.4 MB
Format:
Adobe Portable Document Format
Description:
Thumbnail Image
Name:
MS20907198_Abs.pdf
Size:
249.57 KB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: