Uppsats
Howthe difficulty of obtaining intrusion artifacts can influence threat modeling : An experiment that shows how IT forensics can be used preventingly
Master-uppsats
KTH/Skolan för elektroteknik och datavetenskap (EECS)
Publicerad: 2022
Språk: Engelska
Sammanfattning
IT system intrusions are a problem today and the belief that all you need is a strong outer defense has faded. Today continuous monitoring of the IT infrastructure is widespread and alerts are continuously investigated. The clarity of what caused the alert will vary from a clear brute-force attempt to something more sophisticated that could be perceived as normal activity. The investigation of these alerts can bring clarity or in the worst case dismiss a legit intrusion as some system event or user action. The risk should vary depending on how easy or hard an intrusion is to detect, investigate, and for how long the artifacts will remain on a system. By investigating if different attacks carry different risks it should be possible to use this in a tool like threat modeling. The detection risk that different attacks carry can affect where a defender should spend their resources and provides awareness of the types of attack that they are especially vulnerable to. An environment is set up where an attacker targets a victim with chosen attacks and each attack step is forensically investigation with open-source tools. In this forensic investigation logs, files, active tasks, and network connections are investigated. In the end, the results indicate that it is possible to conclude that different attacks carry different risks. Three grading parameters are suggested based on this work, and these parameters could be used in a threat modeling implementation.
Information
- Författare
- Meyer, Oscar
- Lärosäte / institution
- KTH/Skolan för elektroteknik och datavetenskap (EECS)
- Publiceringsdatum
- 2022
- Uppsatstyp
- Master-uppsats
- Språk
- Engelska
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Master-uppsats, Linköpings universitet/Cybersäkerhet
Bruno, ELias, Lidberg, Erik
Publicerad: 2026
Kandidat-uppsats, Högskolan i Halmstad/Akademin för informationsteknologi
Emanuelsson, Julia, Karlsson, Moa
Publicerad: 2026
Yrkesexamen på avancerad nivå, Blekinge Tekniska Högskola/Institutionen för programvaruteknik
Gustafsson, William, Hedin, Christoffer
Publicerad: 2026
Kandidat-uppsats, Karlstads universitet/Institutionen för matematik och datavetenskap (from 2013)
Rodrigo Verdu, Juan
Publicerad: 2026
Master-uppsats, Göteborgs universitet/Graduate School
Ihala Wanni Arachchillage, Tharindi Bhagya, Mannanayake Arachchige, Chelmini Anjana Mannanayake
Publicerad: 2026-07-02
Master-uppsats, Lunds universitet/Internationella miljöinstitutet
Ramaprasad, Ananya Nag
Publicerad: 2025