Назва: Threats detection and analysis based on SYSMON tool
| custom.quartile | Scopus (Q4) | |
| dc.contributor.author | Nataliia Bahniuk | |
| dc.contributor.author | Oleksandr Linchuk | |
| dc.contributor.author | Kateryna Bortnyk | |
| dc.contributor.author | Inna Kondius | |
| dc.contributor.author | Kateryna Melnyk | |
| dc.contributor.author | Kostiantyn Kondius | |
| dc.date.accessioned | 2026-06-09T12:36:42Z | |
| dc.date.issued | 2023 | |
| dc.description.abstract | In this work, an nalysis for the study of threats in a real environment with the possibility of conducting a fullfledged analysis of threats, as well as their simulationhas been developed for research purposes. Designed laboratory was built for the threats research, specification of deploying and configuring Sysmon, imitation of an attack in laboratory conditions and its investigation by implicit signs, the processesing of threat analysis using the Sysmon tool. We present a system based on the analysis of continuous input chan-nels of Sysmon logs. The system is based on the Cyber Threat Analysis Ontology and analyzes SYSMON logs to classify software according to different threat levels and enhance cyber defense capabilities with situational awareness, prediction and auto-mated actions. The developed laboratory improves the effectiveness of threat analysis using the Sysmon tool, makes study of threats, deploying and configuring Sysmon, imitation of an attack in laboratory conditions and its investigation by implicit signs. It can be applied for the study of threats in a real environment with the possibility of conducting a full-fledged analysis of threats, as well as their simulation for research purposes. | |
| dc.identifier.citation | N. Bahniuk, O. Linchuk, K. Bortnyk, I.Kondius, K. Melnyk and K. Kondius, "Threats Detection and Analysis Based on SYSMON Tool," 2023 13th International Conference on Dependable Systems, Services and Technologies (DESSERT), Athens, Greece, 2023, pp. 1-7 | |
| dc.identifier.doi | 10.1109/DESSERT61349.2023.10416443 | |
| dc.identifier.uri | https://repository.lntu.edu.ua/handle/123456789/3643 | |
| dc.language.iso | en | |
| dc.subject | SYSMON tool | |
| dc.subject | Threats Detection | |
| dc.subject | Cyberattacks | |
| dc.title | Threats detection and analysis based on SYSMON tool | |
| dc.type | Article | |
| dspace.entity.type | ScientificArticle |
Файли
Контейнер файлів
1 - 1 з 1
Вантажиться...
- Назва:
- Threats Detection and Analysis Based on SYSMON Tool.pdf
- Розмір:
- 288.13 KB
- Формат:
- Adobe Portable Document Format
Ліцензійна угода
1 - 1 з 1
Вантажиться...
- Назва:
- license.txt
- Розмір:
- 1.59 KB
- Формат:
- Item-specific license agreed to upon submission
- Опис: