Threat Modeling and Threat Intelligence System for Cloud using Splunk

被引:3
作者
Ananthapadmanabhan, A. [1 ]
Achuthan, Krishnashree [1 ]
机构
[1] Amrita Vishwa Vidyapeetham, Ctr Cyber Secur Syst & Networks, Kollam, India
来源
2022 10TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSICS AND SECURITY (ISDFS) | 2022年
关键词
Cloud security; Cyber-attacks; Threat modeling; Threat intelligence; Splunk; Cloud systems;
D O I
10.1109/ISDFS55398.2022.9800787
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Threat modeling is one of the traditional mechanisms used for finding the potential threats in a system. Majority of the existing threat models rely on the possible ways of modeling attacks. This work proposes a combination of both threat modeling and threat intelligence for cloud systems using Splunk towards developing a comprehensive model. The existing cloud threat models rely on the types of attacks that are possible at certain phases of the system. The combined system proposed here is a granular model, that helps in capturing the potential threats based on the attacker's behavior after a data breach. The threat intelligence module existing in the system will help identify live threats. The integrated plugin which combines both the adversarial threat model and threat monitoring dashboard were able to categorise and monitor the activities happening in the cloud using Splunk.
引用
收藏
页数:6
相关论文
共 22 条
[1]  
Ahlberg Christopher, 2019, MOVING SECURITY INTE
[2]  
Al-Shaer R, 2020, IEEE CONF COMM NETW
[3]  
Alam T, 2020, IAIC Transactions on Sustainable Digital Innovation (ITSDI), V1, P108, DOI [10.34306/itsdi.v1i2.103, 10.2139/ssrn.3639063, DOI 10.2139/SSRN.3639063, 10.34306/ITSDI.V1I2.103, DOI 10.34306/ITSDI.V1I2.103]
[4]  
Alhebaishi Nawaf, 2016, INT S FDN PRACTICE S
[5]  
[Anonymous], 2016, DESIGN IMPLEMENTATIO
[6]  
Brazhuk A, 2021, International journal of open information technologies, V9, P36
[7]  
Buddha Jyothi Prasad, DEFINITIVE GUIDE AWS
[8]  
Carasso D., 2012, Exploring Splunk
[9]  
Chandran S, 2015, 2015 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), P2001, DOI 10.1109/ICACCI.2015.7275911
[10]  
Farhat V, 2011, PRACTICAL LAW, P1