University of South Wales
An Integrated Cyber Threat Hunting Program Applying Machine Learning for Enhanced Intelligence Capabilities
Abstract
dc:description.abstractThis project entails the creation of a simplified event log filterer that can be used by new threat hunters to the field of threat intelligence. The event log filterer employs three filtering options that allow the threat hunter to analyse application, system, security and Sysmon logs, which are the most common logs used for hunting for threats. This tool was created to allow new users to get to grips with threat hunting without the need go through the hundreds of unnecessary logs that Windows Event Viewer collects and displays and the array of options that may seem overwhelming to those starting out in this field. The tool also analyses Sysmon logs using anomaly spike detection machine learning to highlight any logs that may be anomalous and should be investigated further. The idea of this is to allow the new threat hunter to pinpoint which Sysmon logs require attention, whereas the conventional Windows Event Viewer approach does not afford this anomaly detection and is a laborious task to sift through all the logs looking for anomalies, which is difficult for experienced hunters, let alone novices.
Degree
thesis:*- Name dc:type.qualificationname
- Master's Thesis
- Level dc:type.qualificationlevel
- Student thesis
- Year dc:date.issued
- 2021
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Richards, Joshua
- Advisor dc:contributor.advisor
-
- Ward, Richard
Subjects
dc:subject × 6Rights
- Language dc:language
- eng
Identifiers
dc:identifier.*- Identifier
- oai:pure.atira.dk:studenttheses/3dfe8c83-3cfd-461c-9b24-28e8513b868d
- OAI identifier oai:identifier
- oai:pure.atira.dk:studenttheses/3dfe8c83-3cfd-461c-9b24-28e8513b868d