Please use this identifier to cite or link to this item:
https://hdl.handle.net/11264/1224
Full metadata record
DC Field | Value | Language |
---|---|---|
dc.contributor.author | Ménard, Sébastien | - |
dc.contributor.other | Royal Military College of Canada / Collège militaire royal du Canada | en_US |
dc.date.accessioned | 2017-02-01T14:34:50Z | - |
dc.date.accessioned | 2019-12-04T18:39:25Z | - |
dc.date.available | 2017-02-01T14:34:50Z | - |
dc.date.available | 2019-12-04T18:39:25Z | - |
dc.date.issued | 2017-02-01 | - |
dc.identifier.uri | https://hdl.handle.net/11264/1224 | - |
dc.description.abstract | Security information and Event management (SIEM) software enable the aggregation of information generated by all security sensors within a defended network providing optimal visibility on security alerts. SIEMS have become the main information management tool used by system defenders to organize logs and security alerts for an organization's Network Operation Center (NOC). The training of system defenders is a recurring challenge, which is costly in terms of both money and time. This research contributes to the development of training methods that does not depend on network penetration teams. This research is based on the development of new techniques to train network defenders, particularly SIEM operators. We intend to develop a new approach that does not rely on the presence of a penetration testing team. The use of SIEM replay connectors is a viable alternative to train SIEMS operators. However, organizing logs characteristic of malicious scenarios in a way which can be useable by SIEM replay connectors is not trivial. This research has developed techniques and proposes an architecture to assemble logs useable by replay connectors to train SIEM operators in a semi-automatic fashion. | en_US |
dc.language.iso | fr | en_US |
dc.subject | SIEM | en_US |
dc.subject | CYBER TRAINING | en_US |
dc.subject | SIMULATION | en_US |
dc.subject | LOGS | en_US |
dc.subject | EMULATION | en_US |
dc.subject | Network operantion Center | en_US |
dc.subject | cyber defense | en_US |
dc.title | ASSEMBLAGE SEMI-AUTOMATIQUE DE LOGS POUR ENTRAINEMENT D’OPÉRATEURS DE SIEM | en_US |
dc.type | Theses | - |
dc.title.translated | SEMI-AUTOMATED LOG SEQUENCE GENERATION FOR SIEM OPERATOR | en_US |
dc.contributor.supervisor | Leblanc, Sylvain | - |
dc.date.acceptance | 2017-01-30 | - |
thesis.degree.discipline | Electrical and Computer Engineering/Génie électrique et informatique | en_US |
thesis.degree.name | MASc (Master of Applied Science/Maîtrise ès sciences appliquées) | en_US |
Appears in Collections: | Theses |
Files in This Item:
File | Description | Size | Format | |
---|---|---|---|---|
Thèse MScA Capt Ménard Mémoire.pdf | Thesis | 1.82 MB | Adobe PDF | View/Open |
Items in eSpace are protected by copyright, with all rights reserved, unless otherwise indicated.