Systém pro detekci a správu bezpečnostních incidentů

Abstract

This master thesis deals with design and implementation of a centralized system for detection, analysis, and management of cybersecurity incidents. The main objective is to create an effective architecture capable of processing and analyzing large data volumes whilst enabling the management of security events. Theory describes modern approaches to anomaly detection and process models of surveillance centers. Attention is focused on solving problems regarding analyst attention overload by optimizing detection rules, filtering false positives and integrating automation elements of related events. The result is functional, secure ecosystem that makes it easier for operators to assess risks and substantially reduces the time it takes to respond to cyber threats.

Description

Delayed publication

Available after

Subject(s)

Anomaly detection, automation, correlation, cybersecurity, incident management, log analysis, SIEM, SOAR

Citation