Dario Simone Leone
Remediation procedures and automated cybersecurity incident response.
Rel. Cataldo Basile, Francesco Settanni. Politecnico di Torino, Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering), 2025
|
|
PDF (Tesi_di_laurea)
- Tesi
Licenza: Creative Commons Attribution Non-commercial No Derivatives. Download (1MB) |
| Abstract: |
Digital transformation in recent years has fostered the adoption of interconnected technologies such as scalable cloud services, the pervasive internet of things, and artificial intelligence, altering the approach organizations take to their routine operations. While these advancements bring benefits, they also expand the attack surface, exposing organizations to more frequent and sophisticated cybersecurity threats. Attackers leverage emerging technologies to orchestrate targeted campaigns, highlighting the need for automated and standardized Incident Response processes. Despite efforts to improve automation, the diversity of attack types and environments spanning traditional information technology, cloud platforms, and industrial control system, makes one-size-fits-all solutions impractical. There is thus a growing need to abstract response procedures from specific technologies and encode them for interoperability without constant manual adaptation. Standardized formats for representing incident response actions facilitate automation, integration, and transformation of heterogeneous procedures into homogeneous playbooks. This enables teams to focus on strategic decision making while routine actions are handled automatically, reducing response times. This thesis presents a framework for procedural and automated remediation based on security playbooks, designed within the Security Orchestration, Automation, and Response (SOAR) paradigm. This approach also enables the subsequent sharing of remediation strategies, similarly to Cyber Threat Intelligence (CTI). The proposed tool maps alerts to corrective actions defined in structured playbooks and translates them into executable instances, preserving complex logical structures such as conditions, loops, and parallel actions. A novelty of this work is the design and implementation of a security automation framework tailored for modern cloud-native environments, such as Kubernetes clusters, in addition to traditional on-premises infrastructure. |
|---|---|
| Relatori: | Cataldo Basile, Francesco Settanni |
| Anno accademico: | 2025/26 |
| Tipo di pubblicazione: | Elettronica |
| Numero di pagine: | 96 |
| Soggetti: | |
| Corso di laurea: | Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering) |
| Classe di laurea: | Nuovo ordinamento > Laurea magistrale > LM-32 - INGEGNERIA INFORMATICA |
| Aziende collaboratrici: | Politecnico di Torino |
| URI: | http://webthesis.biblio.polito.it/id/eprint/37719 |
![]() |
Modifica (riservato agli operatori) |



Licenza Creative Commons - Attribuzione 3.0 Italia