Please use this identifier to cite or link to this item: http://hdl.handle.net/10609/117846
Title: Desplegar la herramienta "Zeek IDS" y su posterior explotación para el análisis de actividades sospechosas en la red
Author: Galván Vitas, Ignacio
Director: Rifà-Pous, Helena  
Tutor: Guaita Pérez, Borja
Abstract: The main objective was to assess the ability of an IDS tool like Zeek combined with a data visualization and exploitation environment like ELK Stack to analyze suspicious activity on the network. Additionally, different sources of threat intelligence have been integrated and correlated through ELK Stack with the data obtained from Zeek IDS. This document describes the entire process carried out to design, plan, deploy the solution and then analyze the results obtained. It also includes the source code of the different scripts, Ansible playbooks and configuration files of the different applications used. The waterfall project management methodology has allowed to maintain a constant control of the project while facilitating its management. The main conclusions obtained are that it is totally possible and viable to have an intrusion detection system using Zeek IDS and the ELK Stack as a base. It has also been confirmed that this type of solution can be developed using open source tools and maintaining a low budget. Finally, it has also been concluded that it is easy to integrate sources of information on threats and that they are correlated with the information obtained from Zeek.
Keywords: malware
Zeek IDS
Elastic
Document type: info:eu-repo/semantics/masterThesis
Issue Date: Jun-2020
Publication license: http://creativecommons.org/licenses/by-nc-nd/3.0/es/  
Appears in Collections:Trabajos finales de carrera, trabajos de investigación, etc.

Files in This Item:
File Description SizeFormat 
igalvitTFM0620memoria.pdfMemoria del TFM5,59 MBAdobe PDFThumbnail
View/Open
igalvitTFM0620presentación.pdfPresentación del TFM719,76 kBAdobe PDFThumbnail
View/Open