ČERMÁK, Milan. Incident Investigation: From Packets to Graph-Based Analysis. In International Workshop on Graph-based network Security (GraSec) in conjunction with IEEE/IFIP Network Operations and Management Symposium NOMS 2022. 2022.
Other formats:   BibTeX LaTeX RIS
Basic information
Original name Incident Investigation: From Packets to Graph-Based Analysis
Authors ČERMÁK, Milan.
Edition International Workshop on Graph-based network Security (GraSec) in conjunction with IEEE/IFIP Network Operations and Management Symposium NOMS 2022, 2022.
Other information
Original language English
Type of outcome Requested lectures
Country of publisher Hungary
Confidentiality degree is not subject to a state or trade secret
WWW URL
Organization Ústav výpočetní techniky – Repository – Repository
Keywords in English Network Forensics;Graph Database;Incident Investigation;Dgraph;Zeek;Association-based Analysis
Links 833418, interní kód Repo.
Changed by Changed by: RNDr. Daniel Jakubík, učo 139797. Changed: 29/4/2022 03:09.
Abstract
Analysis of network traffic allows us to explore events in the monitored network (even retrospectively). It benefits from the fact that it is almost impossible to maliciously affect the captured data (as opposed to system logs, for example). Therefore, it is a reliable source that suitably complements cyber incident investigation. The analysis of network traffic is currently performed by the use of tools such as Wireshark or Arkime, which allow manual data browsing, filtering, aggregation, and provide interactive visualizations but don't account for the fact that the human brain perceives the data as associations/graphs. This interactive keynote will show you how network traffic is typically analyzed today and how it can be adapted to human thinking by using a graph database. In the introductory part, you will see what a typical network attack looks like, how it can be analyzed using Wireshark, and what the advantages and disadvantages of today's analysis techniques are. We will then show you how to transform network data into a format suitable for a graph database while at the same time preserving the natural perception of network traffic. In the final part of the keynote, we will introduce the Granef toolkit (https://granef.csirt.muni.cz/) and use it to analyze the given data. Through simple tutorial exercises, participants will have the opportunity to explore graph-based analysis on their own and gain new insights into network traffic data.
Type Name Uploaded/Created by Uploaded/Created Rights
2022-GraSec-incident-investigation-from-packets-to-graph-based-analysis.pdf Licence Creative Commons 29/4/2022

Properties

Name
2022-GraSec-incident-investigation-from-packets-to-graph-based-analysis.pdf
Address within IS
https://repozitar.cz/auth/repo/50045/1291517/
Address for the users outside IS
https://repozitar.cz/repo/50045/1291517/
Address within Manager
https://repozitar.cz/auth/repo/50045/1291517/?info
Address within Manager for the users outside IS
https://repozitar.cz/repo/50045/1291517/?info
Uploaded/Created
Fri 29/4/2022 03:09

Rights

Right to read
  • anyone on the Internet
Right to upload
 
Right to administer:
  • a concrete person Mgr. Lucie Vařechová, uco 106253
  • a concrete person RNDr. Daniel Jakubík, uco 139797
  • a concrete person Mgr. Jolana Surýnková, uco 220973
Attributes
 
2022-GraSec-incident-investigation-from-packets-to-graph-based-analysis.pptx Licence Creative Commons 29/4/2022

Properties

Name
2022-GraSec-incident-investigation-from-packets-to-graph-based-analysis.pptx
Address within IS
https://repozitar.cz/auth/repo/50045/1291516/
Address for the users outside IS
https://repozitar.cz/repo/50045/1291516/
Address within Manager
https://repozitar.cz/auth/repo/50045/1291516/?info
Address within Manager for the users outside IS
https://repozitar.cz/repo/50045/1291516/?info
Uploaded/Created
Fri 29/4/2022 03:09

Rights

Right to read
  • anyone on the Internet
Right to upload
 
Right to administer:
  • a concrete person Mgr. Lucie Vařechová, uco 106253
  • a concrete person RNDr. Daniel Jakubík, uco 139797
  • a concrete person Mgr. Jolana Surýnková, uco 220973
Attributes
 
Print
Add to clipboard Displayed: 27/9/2024 13:19