Skoči na glavni sadržaj

Izvorni znanstveni članak

https://doi.org/10.24138/jcomss-2022-0033

Security Incident Response Automation for xPON Networks

Vaclav Oujezsky orcid id orcid.org/0000-0001-7629-6299 ; Department of Telecommunication, Brno University of Technology, Brno, Czech Republic
Tomas Horvath ; Department of Telecommunication, Brno University of Technology, Brno, Czech Republic
Martin Holik ; Department of Telecommunication, Brno University of Technology, Brno, Czech Republic


Puni tekst: engleski pdf 1.812 Kb

str. 144-152

preuzimanja: 266

citiraj


Sažetak

This paper presents a developed tool for automated security incident reporting in passive optical networks. This tool interacts with our programmable development card, developed detection modules, and TheHive project. The custom implementation of the solution has resulted in anomaly reporting templates for xPON networks that can be universally applied and new definitions of indicators of compromise. The custom implementation consists of a collector and middleware layer between the programmable card and Apache Kafka.

Ključne riječi

Automation, CERT, Incidents, Reports, SIRAP, Tool

Hrčak ID:

275782

URI

https://hrcak.srce.hr/275782

Datum izdavanja:

30.6.2022.

Posjeta: 661 *