| Nome: | Descrição: | Tamanho: | Formato: | |
|---|---|---|---|---|
| 5.12 MB | Adobe PDF |
Orientador(es)
Resumo(s)
Nos dias de hoje, a realidade dos sistemas de informação das organizações, está cada vez mais complexa e com requisitos de segurança mais exigentes. Nos últimos anos, a firewall tornou-se uma ferramenta essencial para atingir o nível desejado de isolamento dentro das várias redes existentes que uma organização pode ter.
A abordagem que tem sido cada vez mais posta em prova é de Threat Hunting, exigindo abordagens de segurança mais proativas e eficazes. Este tipo de caça às ameaças (Threat Hunting), um processo caracterizado pela identificação ativa e antecipada de potenciais riscos que possam vir a comprometer sistemas ou dados das empresas, este tipo de método, requer o uso de ferramentas avançadas de segurança, tais como, plataformas de Gestão de Informação e Eventos de Segurança (Security Information and Event Management – SIEM), onde desempenham um papel essencial na deteção e análise de potenciais ciberameaças.
As plataformas SIEM permitem detetar e analisar dados provenientes de diversas fontes, como o tráfego de rede, registo de sistemas e informação de dispositivos, desde que os mesmos estejam devidamente configurados. Este tipo de análise permite identificar possíveis ameaças e gerar alertas em tempo real, possibilitando um tipo de resposta mais ágil e eficiente.
Esta dissertação explora o papel crucial das plataformas SIEM em conjunto com uma Firewall no contexto da caça às ameaças, com o foco nos desafios que são enfrentados pelas PMEs no atual contexto de ciberameaças. Vai ser analisado diversos tipos de conceitos com enfoque à Threat Hunting, os principais tipos de riscos que afetam as organizações, o tipo de cultura, bem como a relevância da inteligência de ameaças para uma abordagem mais eficaz.
Como demonstração da aplicabilidade prática destas soluções, vai ser elaborado um caso prático baseado na plataforma SIEM Wazuh, uma plataforma SIEM de código aberto, em conjunto com a firewall da Sophos. Este caso prático vai ter como objetivo avaliar a eficácia destas tecnologias na identificação e análise de possíveis ameaças existentes e a importância que consegue trazer às PMEs em estar num estado de alerta em tempo real e de conseguir decidir diversas medidas proativas para mitigar riscos cibernéticos. Este estudo visa ainda evidenciar como as plataformas SIEM em conjunto com uma firewall podem apoiar as PMEs
na proteção dos seus sistemas e redes, no qual proporciona uma visão integrada da segurança e facilitando ações de mitigação baseadas em evidências num contexto prático real.
Nowadays, the reality of organisations' information systems is becoming increasingly complex and security requirements more demanding. In recent years, the firewall has become an essential tool for achieving the desired level of isolation within the various existing networks that an organisation may have. The approach that has been increasingly put to the test is Threat Hunting, requiring more proactive and effective security approaches. Threat hunting, a process characterised by the active and early identification of potential risks that could compromise company systems or data, requires the use of advanced security tools, such as Security Information and Event Management (SIEM) platforms, which play an essential role in detecting and analysing potential cyber threats. SIEM platforms make it possible to detect and analyse data from various sources, such as network traffic, system logs and device information, as long as they are properly configured. This type of analysis makes it possible to identify possible threats and generate alerts in real time, enabling a more agile and efficient type of response. This dissertation explores the crucial role of SIEM platforms in conjunction with a Firewall in the context of threat hunting, with a focus on the challenges faced by SMEs in the current context of cyber threats. It will analyse various types of concepts with a focus on Threat Hunting, the main types of risks affecting organisations, the type of culture, as well as the relevance of threat intelligence for a more effective approach. As a demonstration of the practical applicability of these solutions, a practical case will be developed based on the Wazuh SIEM platform, an open source SIEM platform, in conjunction with the Sophos firewall. The aim of this case study will be to assess the effectiveness of these technologies in identifying and analysing possible threats and the importance they can bring to SMEs in being alert in real time and being able to decide on various proactive measures to mitigate cyber risks. This study also aims to show how SIEM platforms in conjunction with a firewall can support SMEs in protecting their systems and networks, providing an integrated view of security and facilitating evidence-based mitigation actions in a real practical context.
Nowadays, the reality of organisations' information systems is becoming increasingly complex and security requirements more demanding. In recent years, the firewall has become an essential tool for achieving the desired level of isolation within the various existing networks that an organisation may have. The approach that has been increasingly put to the test is Threat Hunting, requiring more proactive and effective security approaches. Threat hunting, a process characterised by the active and early identification of potential risks that could compromise company systems or data, requires the use of advanced security tools, such as Security Information and Event Management (SIEM) platforms, which play an essential role in detecting and analysing potential cyber threats. SIEM platforms make it possible to detect and analyse data from various sources, such as network traffic, system logs and device information, as long as they are properly configured. This type of analysis makes it possible to identify possible threats and generate alerts in real time, enabling a more agile and efficient type of response. This dissertation explores the crucial role of SIEM platforms in conjunction with a Firewall in the context of threat hunting, with a focus on the challenges faced by SMEs in the current context of cyber threats. It will analyse various types of concepts with a focus on Threat Hunting, the main types of risks affecting organisations, the type of culture, as well as the relevance of threat intelligence for a more effective approach. As a demonstration of the practical applicability of these solutions, a practical case will be developed based on the Wazuh SIEM platform, an open source SIEM platform, in conjunction with the Sophos firewall. The aim of this case study will be to assess the effectiveness of these technologies in identifying and analysing possible threats and the importance they can bring to SMEs in being alert in real time and being able to decide on various proactive measures to mitigate cyber risks. This study also aims to show how SIEM platforms in conjunction with a firewall can support SMEs in protecting their systems and networks, providing an integrated view of security and facilitating evidence-based mitigation actions in a real practical context.
Descrição
Palavras-chave
Sophos SIEM Segurança Informática PME
