Details

Razvoj informacijskega sistema za upravljanje varnostnih informacij in dogodkov s podporo analitike
ID Sterle, Jan (Author), ID Fujs, Damjan (Mentor) More about this mentor... This link opens in a new window

.pdfPDF - Presentation file, Download (1,07 MB)
MD5: 77E54767DBB116F88E8E89C00E7DE01C

Abstract
Diplomska naloga obravnava razvoj eksperimentalnega sistema za upravlja- nje varnostnih informacij in dogodkov, ki omogoča zbiranje, normalizacijo, pretočno obdelavo, shranjevanje in analizo varnostnih dogodkov. Sistem te- melji na modularni arhitekturi, v kateri se sintetično generirani dnevniški zapisi in sistemske metrike pretvorijo v standardizirano obliko OCSF ter posredujejo prek sporočilnega sistema Redpanda. V okviru naloge sta im- plementirana analitični modul za zaznavo groženj na podlagi pravil in odsto- panj ter večnivojska hramba podatkov z uporabo vroče in hladne hrambe. Rezultat naloge je delujoč prototip sistema SIEM, ki prikazuje uporabnost sodobnih pretočnih arhitektur in napredne analitike pri zaznavi varnostnih incidentov.

Language:Slovenian
Keywords:SIEM, varnostni dogodki, OCSF, pretočna obdelava, za- znava groženj, analitika.
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FRI - Faculty of Computer and Information Science
Year:2026
PID:20.500.12556/RUL-184371 This link opens in a new window
COBISS.SI-ID:285904899 This link opens in a new window
Publication date in RUL:06.07.2026
Views:189
Downloads:86
Metadata:XML DC-XML DC-RDF
:
Copy citation
Share:Bookmark and Share

Secondary language

Language:English
Title:Development of an Information System for Security Information and Event Management with Analytics Support
Abstract:
The diploma thesis addresses the development of an experimental Security Information and Event Management system that enables the collection, nor- malization, stream processing, storage, and analysis of security events. The system is based on a modular architecture in which synthetically generated log records and system metrics are transformed into the standardized OCSF format and forwarded through the messaging system Redpanda. As part of the thesis, an analytical module for threat detection based on rules and anomalies is implemented, together with multi-tier data storage using hot and cold storage. The result of the thesis is a working SIEM system pro- totype that demonstrates the usefulness of modern streaming architectures and analytics in the detection of security incidents.

Keywords:SIEM, security events, OCSF, stream processing, analytics.

Similar documents

Similar works from RUL:
Similar works from other Slovenian collections:

Back