Original title:
Metodika a implementace nástrojů pro řízení kybernetických incidentů
Translated title:
Methodology and implementation of cyber incident management tools
Authors:
Sedlák, Jakub ; Šťovíček, Petr (referee) ; Sedlák, Petr (advisor) Document type: Master’s theses
Year:
2025
Language:
cze Publisher:
Vysoké učení technické v Brně. Fakulta podnikatelská Abstract:
[cze][eng]
Tato diplomová práce se zabývá návrhem systému pro zpracování a agregaci síťových záznamů s cílem minimalizovat jejich objem při zachování vysoké informační hodnoty pro potřeby threat huntingu a forenzní analýzy. První část práce se zaměřuje na teoretická východiska, konkrétně na technologie používané v návrhové části. Druhá část práce popisuje výchozí stav existujícího řešení a definuje problémy spojené s objemem a redundancí síťových záznamů. Třetí část podrobně popisuje návrh a implementaci nového systému v kontejnerizovaném prostředí Podman, a to včetně jednotlivých komponent pro příjem, transport, normalizaci a agregaci dat pomocí nástroje Apache Spark a Apache Kafka. V závěru jsou shrnuty přínosy navrhovaného řešení z provozního i ekonomického hlediska.
This master thesis focuses on the design of a system for processing and aggregation of network records in order to minimize their volume while maintaining high information value for threat hunting and forensic analysis. The first part of the thesis focuses on the theoretical background, specifically the technologies used in the design part. The second part of the thesis describes the initial state of the current solution and defines the problems associated with the volume and redundancy of network records. The third part details the design and implementation of the new system in the containerized Podman environment, including the individual components for data ingestion, transport, normalization, and aggregation using Apache Spark and Apache Kafka. It concludes with a summary of the benefits of the proposed solution from an operational and economic perspective.
Keywords:
Apache Kafka; Apache Spark; data processing; network security; Splunk; threat detection; Apache Kafka; Apache Spark; detekce hrozeb; Splunk; síťová bezpečnost; zpracování dat
Institution: Brno University of Technology
(web)
Document availability information: Fulltext is available in the Brno University of Technology Digital Library. Original record: http://hdl.handle.net/11012/254070