Метод зниження рівня хибних спрацювань (False Positives) при моніторингу технік Living off The Land у корпоративних мережах
| dc.contributor.author | Кондратюк, А. В. | uk |
| dc.contributor.author | Kondratiuk, A. V. | en |
| dc.title | Метод зниження рівня хибних спрацювань (False Positives) при моніторингу технік Living off The Land у корпоративних мережах | uk |
| dc.date.issued | 2026 | |
| dc.publisher | Вінницький національний технічний університет | uk |
| dc.identifier.citation | Кондратюк А. В. Метод зниження рівня хибних спрацювань (False Positives) при моніторингу технік Living off The Land у корпоративних мережах // Матеріали Міжнародної науково-практичної інтернет-конференції «Молодь в науці: дослідження, проблеми, перспективи (МН-2026)», м. Вінниця, 22-26 червня 2026 р. Електрон. текст. дані. 2026. URI: https://conferences.vntu.edu.ua/index.php/mn/mn2026/paper/view/29014. | uk |
| dc.relation.ispartof | Матеріали Міжнародної науково-практичної інтернет-конференції «Молодь в науці: дослідження, проблеми, перспективи (МН-2026)», м. Вінниця, 22-26 червня 2026 р. | uk |
| dc.relation.uri | https://conferences.vntu.edu.ua/index.php/mn/mn2026/paper/view/29014 | |
| dc.identifier.udc | 004.056 | |
| dc.identifier.uri | https://ir.lib.vntu.edu.ua/handle/123456789/53306 | |
| dc.description.abstract | У роботі досліджується проблема критичного перевантаження центрів моніторингу безпеки (SOC) хибними спрацюваннями (False Positives), що виникають під час спроб виявлення атак типу «Living off the Land» (LotL). | uk |
| dc.description.abstract | The paper investigates the critical problem of Security Operations Centers (SOC) being overloaded with false positives during attempts to detect "Living off the Land" (LotL) attacks. Since attackers utilize legitimate system tools (PowerShell, WMI, PsExec), classic signature-based SIEM rules cannot distinguish malicious activity from the routine work of system administrators. This leads to the phenomenon of "alert fatigue" and the missing of actual incidents. To address this issue, a method of contextual security data enrichment is proposed, which integrates technical events with organizational metadata (user role, behavioral profile, asset criticality). The application of this method automates the filtering of legitimate activity and significantly reduces the level of information noise. | en |
| dc.subject | False Positives | en |
| dc.subject | Living off the Land (LotL) | en |
| dc.subject | SIEM | en |
| dc.subject | SOC | en |
| dc.subject | Alert Fatigue | en |
| dc.subject | контекстно-орієнтованийаналіз | uk |
| dc.subject | інформаційна безпека | uk |
| dc.subject | context-aware analysis | en |
| dc.subject | information security | en |
| dc.type | Thesis | |
| dc.language.iso | uk | uk |
| dc.relation.references | 2. Lateral Movement, Tactic TA0008 Enterprise | MITRE ATT&CK. MITRE ATT&CK. URL: https://attack.mitre.org/tactics/TA0008/ (дата звернення: 02.03.2026). SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations | CSRC. NIST Computer Security Resource Center | CSRC. URL: https://csrc.nist.gov/pubs/sp/800/137/final (дата звернення: 02.03.2026). 3 3. Rapid7. Rapid7. URL: https://www.rapid7.com/fundamentals/living-off-the-land-attack/ (дата звернення: 02.03.2026). Артем Вячеславович | en |
| dc.date.accessioned | 2026-09-03T10:38:56Z | |
| dc.date.available | 2026-09-03T10:38:56Z |
Файли
Контейнер файлів
1 - 1 з 1
Вантажиться...
- Назва:
- 29014.pdf
- Розмір:
- 459,69 KB
- Формат:
- Adobe Portable Document Format
Ліцензійна угода
1 - 1 з 1