Augmenting security event information with contextual data to improve the detection capabilities of a SIEM

dc.contributor.advisorHutchison, Andrewen_ZA
dc.contributor.authorBissict, Jasonen_ZA
dc.date.accessioned2017-09-14T12:28:47Z
dc.date.available2017-09-14T12:28:47Z
dc.date.issued2017en_ZA
dc.description.abstractThe increasing number of cyber security breaches have revealed a need for proper cyber security measures. The emergence of the internet and the increase in overall connectivity means that data is more easily accessible and available. Using the available data in a security context may provide a system with an external contextual insight such as environmental awareness or current affair awareness. A security information and event management (SIEM) system is a security system that correlates security event information from surrounding systems and decides whether the surrounding environment (possibly an enterprise's network) is vulnerable or even under attack by a malicious person whether they be internal (authorised) or external (unauthorised). In this thesis, the aim is to provide such a system with con- text by adding non-security related information from surrounding available sources known as context information feeds. Contextual information feeds are added to the SIEM and tested using randomised events. There are various context information types used in this thesis, namely: social media, meteorological, calendar information and terror threat level. The SIEM is tested with each contextual data feed active and the results are recorded. The testing shows that the addition of contextual data feeds actively affects the sensitivity of OSSIM and hence results in higher alarms raised during elevated context triggered states. The system showed a greater and deeper visibility of its surrounding environment and hence an improved detection capability.en_ZA
dc.identifier.apacitationBissict, J. (2017). <i>Augmenting security event information with contextual data to improve the detection capabilities of a SIEM</i>. (Thesis). University of Cape Town ,Faculty of Science ,Department of Computer Science. Retrieved from http://hdl.handle.net/11427/25207en_ZA
dc.identifier.chicagocitationBissict, Jason. <i>"Augmenting security event information with contextual data to improve the detection capabilities of a SIEM."</i> Thesis., University of Cape Town ,Faculty of Science ,Department of Computer Science, 2017. http://hdl.handle.net/11427/25207en_ZA
dc.identifier.citationBissict, J. 2017. Augmenting security event information with contextual data to improve the detection capabilities of a SIEM. University of Cape Town.en_ZA
dc.identifier.ris TY - Thesis / Dissertation AU - Bissict, Jason AB - The increasing number of cyber security breaches have revealed a need for proper cyber security measures. The emergence of the internet and the increase in overall connectivity means that data is more easily accessible and available. Using the available data in a security context may provide a system with an external contextual insight such as environmental awareness or current affair awareness. A security information and event management (SIEM) system is a security system that correlates security event information from surrounding systems and decides whether the surrounding environment (possibly an enterprise's network) is vulnerable or even under attack by a malicious person whether they be internal (authorised) or external (unauthorised). In this thesis, the aim is to provide such a system with con- text by adding non-security related information from surrounding available sources known as context information feeds. Contextual information feeds are added to the SIEM and tested using randomised events. There are various context information types used in this thesis, namely: social media, meteorological, calendar information and terror threat level. The SIEM is tested with each contextual data feed active and the results are recorded. The testing shows that the addition of contextual data feeds actively affects the sensitivity of OSSIM and hence results in higher alarms raised during elevated context triggered states. The system showed a greater and deeper visibility of its surrounding environment and hence an improved detection capability. DA - 2017 DB - OpenUCT DP - University of Cape Town LK - https://open.uct.ac.za PB - University of Cape Town PY - 2017 T1 - Augmenting security event information with contextual data to improve the detection capabilities of a SIEM TI - Augmenting security event information with contextual data to improve the detection capabilities of a SIEM UR - http://hdl.handle.net/11427/25207 ER - en_ZA
dc.identifier.urihttp://hdl.handle.net/11427/25207
dc.identifier.vancouvercitationBissict J. Augmenting security event information with contextual data to improve the detection capabilities of a SIEM. [Thesis]. University of Cape Town ,Faculty of Science ,Department of Computer Science, 2017 [cited yyyy month dd]. Available from: http://hdl.handle.net/11427/25207en_ZA
dc.language.isoengen_ZA
dc.publisher.departmentDepartment of Computer Scienceen_ZA
dc.publisher.facultyFaculty of Scienceen_ZA
dc.publisher.institutionUniversity of Cape Town
dc.subject.otherComputer Scienceen_ZA
dc.titleAugmenting security event information with contextual data to improve the detection capabilities of a SIEMen_ZA
dc.typeMaster Thesis
dc.type.qualificationlevelMasters
dc.type.qualificationnameMScen_ZA
uct.type.filetypeText
uct.type.filetypeImage
uct.type.publicationResearchen_ZA
uct.type.resourceThesisen_ZA
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
thesis_sci_2017_bissict_jason.pdf
Size:
5.94 MB
Format:
Adobe Portable Document Format
Description:
Collections