{"id":{"repo_id":"emich","oai_identifier":"oai:commons.emich.edu:theses-2598"},"canonical_url":"https://search.dev.ndltd.org/etd/emich/oai:commons.emich.edu:theses-2598","repository":{"repo_id":"emich","name":"Eastern Michigan University","base_url":"https://commons.emich.edu/do/oai/"},"display":{"title":"Automatic modeling of cyber intrusions using the diamond model utilizing security logs and events","abstract":"<p>Current intrusion analysis models suffer from unreliability and inaccuracy due to their reliance on outdated and inadequate data sources. Numerous models focus on a particular type of data, leading to potential modeling faults in intrusion analysis models' recommendations. The objective of this thesis is to build a modernized model by integrating the diamond model with security information and event management systems. This thesis presents a detailed cyber intrusion analysis model; in which Elasticsearch is being used to collect and analyze logs about cyber attacks and extract major indicators of compromise then finally map them to the diamond model. The results demonstrate that integrating Elasticsearch with the diamond model would export an effective cyber intrusion analysis model. Overall, our findings suggest that the integration of the diamond model and Elasticsearch has the potential to become an important intrusion analysis model and warrant further research and development in this area.</p>","abstract_html":"&lt;p&gt;Current intrusion analysis models suffer from unreliability and inaccuracy due to their reliance on outdated and inadequate data sources. Numerous models focus on a particular type of data, leading to potential modeling faults in intrusion analysis models&#x27; recommendations. The objective of this thesis is to build a modernized model by integrating the diamond model with security information and event management systems. This thesis presents a detailed cyber intrusion analysis model; in which Elasticsearch is being used to collect and analyze logs about cyber attacks and extract major indicators of compromise then finally map them to the diamond model. The results demonstrate that integrating Elasticsearch with the diamond model would export an effective cyber intrusion analysis model. Overall, our findings suggest that the integration of the diamond model and Elasticsearch has the potential to become an important intrusion analysis model and warrant further research and development in this area.&lt;/p&gt;","abstract_has_math":false,"creators":["Al-Maani, Mahmoud"],"institution":null,"degree_name":"Master of Science (MS)","degree_level":"Open Access Thesis","degree_discipline":"Information Security and Applied Computing","degree_department":null,"school":null,"contributors":["Mohammed Alsaleh, PhD","Munther Abualkibash, PhD","Ourania Spantidi, PhD"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2024,"date_issued":"2024-01-01T08:00:00Z","date_published":"2024-01-01T08:00:00Z","updated_at":"2026-07-24T02:17:53Z","subjects":["Computer Sciences"],"languages":[],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://commons.emich.edu/theses/1259","outbound_label":"Repository record","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Mohammed Alsaleh, PhD","Munther Abualkibash, PhD","Ourania Spantidi, PhD"]},{"key":"dc:creator","label":"Author","values":["Al-Maani, Mahmoud"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.available","label":"Dc Date Available","values":["2024-09-13T07:00:00Z"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Information Security and Applied Computing"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Open Access Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science (MS)"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Computer Sciences"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://commons.emich.edu/theses/1259"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["<p>Current intrusion analysis models suffer from unreliability and inaccuracy due to their reliance on outdated and inadequate data sources. Numerous models focus on a particular type of data, leading to potential modeling faults in intrusion analysis models' recommendations. The objective of this thesis is to build a modernized model by integrating the diamond model with security information and event management systems. This thesis presents a detailed cyber intrusion analysis model; in which Elasticsearch is being used to collect and analyze logs about cyber attacks and extract major indicators of compromise then finally map them to the diamond model. The results demonstrate that integrating Elasticsearch with the diamond model would export an effective cyber intrusion analysis model. Overall, our findings suggest that the integration of the diamond model and Elasticsearch has the potential to become an important intrusion analysis model and warrant further research and development in this area.</p>"]},{"key":"dc:title","label":"Title","values":["Automatic modeling of cyber intrusions using the diamond model utilizing security logs and events"]}]}],"canonical_facts":{"dc:contributor":["Mohammed Alsaleh, PhD","Munther Abualkibash, PhD","Ourania Spantidi, PhD"],"dc:creator":["Al-Maani, Mahmoud"],"dc:date.available":["2024-09-13T07:00:00Z"],"dc:description.abstract":["<p>Current intrusion analysis models suffer from unreliability and inaccuracy due to their reliance on outdated and inadequate data sources. Numerous models focus on a particular type of data, leading to potential modeling faults in intrusion analysis models' recommendations. The objective of this thesis is to build a modernized model by integrating the diamond model with security information and event management systems. This thesis presents a detailed cyber intrusion analysis model; in which Elasticsearch is being used to collect and analyze logs about cyber attacks and extract major indicators of compromise then finally map them to the diamond model. The results demonstrate that integrating Elasticsearch with the diamond model would export an effective cyber intrusion analysis model. Overall, our findings suggest that the integration of the diamond model and Elasticsearch has the potential to become an important intrusion analysis model and warrant further research and development in this area.</p>"],"dc:identifier":["https://commons.emich.edu/theses/1259"],"dc:subject":["Computer Sciences"],"dc:title":["Automatic modeling of cyber intrusions using the diamond model utilizing security logs and events"],"thesis:degree_discipline":["Information Security and Applied Computing"],"thesis:degree_level":["Open Access Thesis"],"thesis:degree_name":["Master of Science (MS)"]},"updated_at":"2026-07-24T02:17:53Z"}