Eastern Michigan University
Automatic modeling of cyber intrusions using the diamond model utilizing security logs and events
Abstract
dc:description.abstract<p>Current intrusion analysis models suffer from unreliability and inaccuracy due to their reliance on outdated and inadequate data sources. Numerous models focus on a particular type of data, leading to potential modeling faults in intrusion analysis models' recommendations. The objective of this thesis is to build a modernized model by integrating the diamond model with security information and event management systems. This thesis presents a detailed cyber intrusion analysis model; in which Elasticsearch is being used to collect and analyze logs about cyber attacks and extract major indicators of compromise then finally map them to the diamond model. The results demonstrate that integrating Elasticsearch with the diamond model would export an effective cyber intrusion analysis model. Overall, our findings suggest that the integration of the diamond model and Elasticsearch has the potential to become an important intrusion analysis model and warrant further research and development in this area.</p>
Degree
thesis:*- Name thesis:degree_name
- Master of Science (MS)
- Level thesis:degree_level
- Open Access Thesis
- Discipline thesis:degree_discipline
- Information Security and Applied Computing
- Year dc:date.available
- 2024
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Al-Maani, Mahmoud
- Contributors dc:contributor
-
- Mohammed Alsaleh, PhD
- Munther Abualkibash, PhD
- Ourania Spantidi, PhD
Subjects
dc:subject × 1Identifiers
dc:identifier.*- Repository record dc:identifier
- https://commons.emich.edu/theses/1259
- OAI identifier oai:identifier
- oai:commons.emich.edu:theses-2598