D 2024

The Evolution of the CRUSOE Toolset: Enhancing Decision Support in Network Security Management

HUSÁK, Martin; Lukáš SADLEK; Martin HESKO; Vít ŠEBELA; Stanislav ŠPAČEK et al.

Základní údaje

Originální název

The Evolution of the CRUSOE Toolset: Enhancing Decision Support in Network Security Management

Autoři

HUSÁK, Martin; Lukáš SADLEK; Martin HESKO; Vít ŠEBELA a Stanislav ŠPAČEK

Vydání

New York, NY, 2024 20th International Conference on Network and Service Management (CNSM), od s. 1-3, 3 s. 2024

Nakladatel

IEEE

Další údaje

Jazyk

angličtina

Typ výsledku

Stať ve sborníku

Stát vydavatele

Spojené státy

Utajení

není předmětem státního či obchodního tajemství

Forma vydání

elektronická verze "online"

Odkazy

URL, URL

Označené pro přenos do RIV

Ne

Organizace

Ústav výpočetní techniky – Masarykova univerzita – Repozitář

ISBN

979-8-3315-0515-8

ISSN

DOI

https://doi.org/10.23919/CNSM62983.2024.10814288

UT WoS

001414325200004

EID Scopus

2-s2.0-85216535336

Klíčová slova anglicky

decision support;network security management;incident response;orchestration;automation

Návaznosti

EH22_010/0003229, projekt VaV. MUNI/A/1586/2023, interní kód Repo.
Změněno: 1. 4. 2025 00:50, RNDr. Daniel Jakubík

Anotace

V originále

This demo paper presents the recent development of the CRUSOE toolset. CRUSOE enables cyber situational awareness and provides decision support for network security management. The first public version from 2021 used a combination of active and passive network monitoring to enumerate cyber assets and discover their vulnerabilities, visualize the collected data in a dashboard, conduct a risk assessment to recommend the most resilient infrastructure configuration, and facilitate attack mitigation. It also used novel approaches, such as a graph database for storing the data on cyber assets, which essentially became a knowledge graph for network security management. In the recent development, we managed to automate the deployment of CRUSOE via Ansible and Docker. Further, we implemented additional recommender systems and attack impact assessment capabilities and their visualizations. Finally, several sample datasets were created to facilitate the demonstration of the toolset and to enable testing it without one's data.
Zobrazeno: 9. 5. 2026 13:28