Please use this identifier to cite or link to this item: https://hdl.handle.net/10216/119207
Author(s): Pedro Daniel Carvalho de Sousa Rodrigues
Title: An OSINT Approach to Automated Asset Discovery and Monitoring
Issue Date: 2019-02-15
Abstract: The main objective of this thesis is to improve the efficiency of security operations centers through the articulation of different publicly open sources of security related feeds. This is challenging because of the different abstraction models of the feeds that need to be made compatible, of the range of control values that each data source can have and that will impact the security events, and of the scalability of computational and networking resources that are required to collect security events. Following the industry standards proposed by the literature (OSCP guide, PTES and OWASP), the detection of hosts and sub-domains using an articulation of several sources is regarded as the first interaction in an engagement. This first interaction often misses some sources that could allow the disclosure of more assets. This became important since networks have scaled up to the cloud, where IP address range is not owned by the company, and important applications are often shared within the same IP, like the example of Virtual Hosts to host several application in the same server. We will focus on the first step of any engagement, the enumeration of the target network. Attackers often use several techniques to enumerate the target to discover vulnerable services. This enumeration could be improved by the addition of several other sources and techniques that are often left aside from the literature. Also, by creating an automated process it is possible for security operation centers to discover these assets and map the applications in use to keep track of said vulnerabilities using OSINT techniques and publicly available solutions, before the attackers try to exploit the service. This gives a vision of the Internet facing services often seen by attackers without querying the service directly evading therefore detection. This research is in frame with the complete engagement process and should be integrate in already built solutions, therefore the results should be able to connect to additional applications in order to reach forward in the engagement process. By addressing these challenges we expect to come in great aid of sysadmin and security teams, helping them with the task of securing their assets and ensuring security cleanliness of the enterprise resulting in a better policy compliance without ever connecting to the client hosts.
Subject: Engenharia electrotécnica, electrónica e informática
Electrical engineering, Electronic engineering, Information engineering
Scientific areas: Ciências da engenharia e tecnologias::Engenharia electrotécnica, electrónica e informática
Engineering and technology::Electrical engineering, Electronic engineering, Information engineering
DOI: 10.34626/sewy-x460
TID identifier: 202396517
URI: https://hdl.handle.net/10216/119207
Document Type: Dissertação
Rights: openAccess
Appears in Collections:FEUP - Dissertação

Files in This Item:
File Description SizeFormat 
318708.pdfAn OSINT Approach to Automated Asset Discovery and Monitoring1.75 MBAdobe PDFThumbnail
View/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.