<link rel="stylesheet" href="styles.f3b1fba60ec7970c.css">

Метод зниження рівня хибних спрацювань (False Positives) при моніторингу технік Living off The Land у корпоративних мережах

dc.contributor.authorКондратюк, А. В.uk
dc.contributor.authorKondratiuk, A. V.en
dc.titleМетод зниження рівня хибних спрацювань (False Positives) при моніторингу технік Living off The Land у корпоративних мережахuk
dc.date.issued2026
dc.publisherВінницький національний технічний університетuk
dc.identifier.citationКондратюк А. В. Метод зниження рівня хибних спрацювань (False Positives) при моніторингу технік Living off The Land у корпоративних мережах // Матеріали Міжнародної науково-практичної інтернет-конференції «Молодь в науці: дослідження, проблеми, перспективи (МН-2026)», м. Вінниця, 22-26 червня 2026 р. Електрон. текст. дані. 2026. URI: https://conferences.vntu.edu.ua/index.php/mn/mn2026/paper/view/29014.uk
dc.relation.ispartofМатеріали Міжнародної науково-практичної інтернет-конференції «Молодь в науці: дослідження, проблеми, перспективи (МН-2026)», м. Вінниця, 22-26 червня 2026 р.uk
dc.relation.urihttps://conferences.vntu.edu.ua/index.php/mn/mn2026/paper/view/29014
dc.identifier.udc004.056
dc.identifier.urihttps://ir.lib.vntu.edu.ua/handle/123456789/53306
dc.description.abstractУ роботі досліджується проблема критичного перевантаження центрів моніторингу безпеки (SOC) хибними спрацюваннями (False Positives), що виникають під час спроб виявлення атак типу «Living off the Land» (LotL).uk
dc.description.abstractThe paper investigates the critical problem of Security Operations Centers (SOC) being overloaded with false positives during attempts to detect "Living off the Land" (LotL) attacks. Since attackers utilize legitimate system tools (PowerShell, WMI, PsExec), classic signature-based SIEM rules cannot distinguish malicious activity from the routine work of system administrators. This leads to the phenomenon of "alert fatigue" and the missing of actual incidents. To address this issue, a method of contextual security data enrichment is proposed, which integrates technical events with organizational metadata (user role, behavioral profile, asset criticality). The application of this method automates the filtering of legitimate activity and significantly reduces the level of information noise.en
dc.subjectFalse Positivesen
dc.subjectLiving off the Land (LotL)en
dc.subjectSIEMen
dc.subjectSOCen
dc.subjectAlert Fatigueen
dc.subjectконтекстно-орієнтованийаналізuk
dc.subjectінформаційна безпекаuk
dc.subjectcontext-aware analysisen
dc.subjectinformation securityen
dc.typeThesis
dc.language.isoukuk
dc.relation.references2. Lateral Movement, Tactic TA0008 Enterprise | MITRE ATT&CK. MITRE ATT&CK. URL: https://attack.mitre.org/tactics/TA0008/ (дата звернення: 02.03.2026). SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations | CSRC. NIST Computer Security Resource Center | CSRC. URL: https://csrc.nist.gov/pubs/sp/800/137/final (дата звернення: 02.03.2026). 3 3. Rapid7. Rapid7. URL: https://www.rapid7.com/fundamentals/living-off-the-land-attack/ (дата звернення: 02.03.2026). Артем Вячеславовичen
dc.date.accessioned2026-09-03T10:38:56Z
dc.date.available2026-09-03T10:38:56Z

Файли

Контейнер файлів

Зараз показуємо 1 - 1 з 1
Вантажиться...
Ескіз
Назва:
29014.pdf
Розмір:
459,69 KB
Формат:
Adobe Portable Document Format

Ліцензійна угода

Зараз показуємо 1 - 1 з 1
Вантажиться...
Ескіз
Назва:
license.txt
Розмір:
17 B
Формат:
Plain Text
Опис: