Vis enkel innførsel

dc.contributor.advisorNoori, Nadia Saad
dc.contributor.advisorHalsnes, Erlend
dc.contributor.authorStaer, Martin Nauf
dc.contributor.authorDybdahl, Sverre Ose
dc.date.accessioned2023-08-19T16:23:10Z
dc.date.available2023-08-19T16:23:10Z
dc.date.issued2023
dc.identifierno.uia:inspera:145680144:96048536
dc.identifier.urihttps://hdl.handle.net/11250/3084904
dc.description.abstractIn this paper we aim to develop a proof of concept framework as a step-by-step process for identifying what type of information and log types a SOC analyst needs to analyze and handle an alarm based on the alarms MITRE technique. To solve this, it was decided that using both theoretical and experimental research methodologies could be advantageous. Hence we first used a Systematic Literature Review to search, screen, and select relevant literature. Followed by the usage of Design Science Research method for conducting the research based upon a theoretical basis, and an experimental process. To develop a framework consisting of an easy to understand and independent step-by-step process. The proof of concept framework introduced in this paper, is an eight step process describing how one may proceed when gathering data needed for automating information gathering based on alarms MITRE techniques. In these eight steps it revolves around three main concepts, which are gathering a theoretical foundation by research and discussion, improving the theoretical foundation by testing and adjusting, and ends with a continuous process of maintaining the constructed automations when used in a production setting. This framework produced accurate results when tested during research, and we believe it should be further explored and tested in a larger scale. Also it should be considered a stepping stone into further automating the whole alarm handling process, from gathering data to response.
dc.description.abstract
dc.language
dc.publisherUniversity of Agder
dc.titleDesigning a framework for data populating alarms based on MITRE techniques
dc.typeMaster thesis


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel