Показати скорочену інформацію

dc.contributor.authorКондратюк, А. В.uk
dc.contributor.authorKondratiuk, A. V.en
dc.date.accessioned2026-09-03T10:38:56Z
dc.date.available2026-09-03T10:38:56Z
dc.date.issued2026
dc.identifier.citationКондратюк А. В. Метод зниження рівня хибних спрацювань (False Positives) при моніторингу технік Living off The Land у корпоративних мережах // Матеріали Міжнародної науково-практичної інтернет-конференції «Молодь в науці: дослідження, проблеми, перспективи (МН-2026)», м. Вінниця, 22-26 червня 2026 р. Електрон. текст. дані. 2026. URI: https://conferences.vntu.edu.ua/index.php/mn/mn2026/paper/view/29014.uk
dc.identifier.urihttps://ir.lib.vntu.edu.ua/handle/123456789/53306
dc.description.abstractУ роботі досліджується проблема критичного перевантаження центрів моніторингу безпеки (SOC) хибними спрацюваннями (False Positives), що виникають під час спроб виявлення атак типу «Living off the Land» (LotL).uk
dc.description.abstractThe paper investigates the critical problem of Security Operations Centers (SOC) being overloaded with false positives during attempts to detect "Living off the Land" (LotL) attacks. Since attackers utilize legitimate system tools (PowerShell, WMI, PsExec), classic signature-based SIEM rules cannot distinguish malicious activity from the routine work of system administrators. This leads to the phenomenon of "alert fatigue" and the missing of actual incidents. To address this issue, a method of contextual security data enrichment is proposed, which integrates technical events with organizational metadata (user role, behavioral profile, asset criticality). The application of this method automates the filtering of legitimate activity and significantly reduces the level of information noise.en
dc.language.isouk_UAuk_UA
dc.publisherВНТУuk
dc.relation.ispartofМатеріали Міжнародної науково-практичної інтернет-конференції «Молодь в науці: дослідження, проблеми, перспективи (МН-2026)», м. Вінниця, 22-26 червня 2026 р.uk
dc.relation.urihttps://conferences.vntu.edu.ua/index.php/mn/mn2026/paper/view/29014
dc.subjectFalse Positivesen
dc.subjectLiving off the Land (LotL)en
dc.subjectSIEMen
dc.subjectSOCen
dc.subjectAlert Fatigueen
dc.subjectконтекстно-орієнтованийаналізuk
dc.subjectінформаційна безпекаuk
dc.subjectFalse Positivesen
dc.subjectLiving off the Land (LotL)en
dc.subjectSIEMen
dc.subjectSOCen
dc.subjectAlert Fatigueen
dc.subjectcontext-aware analysisen
dc.subjectinformation securityen
dc.titleМетод зниження рівня хибних спрацювань (False Positives) при моніторингу технік Living off The Land у корпоративних мережахuk
dc.typeThesis
dc.identifier.udc004.056
dc.relation.references2. Lateral Movement, Tactic TA0008 Enterprise | MITRE ATT&CK. MITRE ATT&CK. URL: https://attack.mitre.org/tactics/TA0008/ (дата звернення: 02.03.2026). SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations | CSRC. NIST Computer Security Resource Center | CSRC. URL: https://csrc.nist.gov/pubs/sp/800/137/final (дата звернення: 02.03.2026). 3 3. Rapid7. Rapid7. URL: https://www.rapid7.com/fundamentals/living-off-the-land-attack/ (дата звернення: 02.03.2026). Артем Вячеславовичen


Файли в цьому документі

Thumbnail

Даний документ включений в наступну(і) колекцію(ї)

Показати скорочену інформацію