polito.it
Politecnico di Torino (logo)

Study on Implementation and Optimization of Security Operation Center Using Open-source Tools

Roberto Ferrareis

Study on Implementation and Optimization of Security Operation Center Using Open-source Tools.

Rel. Fulvio Valenza. Politecnico di Torino, Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering), 2024

[img]
Preview
PDF (Tesi_di_laurea) - Tesi
Licenza: Creative Commons Attribution Non-commercial No Derivatives.

Download (2MB) | Preview
Abstract:

As organizations increasingly rely on complex IT infrastructures, the security of sensitive data remains at high risk due to diverse security domains, varying trust levels, and the wide array of IT tools in use. Cyber threats, including data breaches and ransomware attacks, can result in financial losses, reputational damage, and privacy violations, posing significant challenges to businesses and individual users. To mitigate these risks, organizations employ a variety of security measures, including access controls, encryption, and continuous monitoring solutions. Among these strategies, establishing a Security Operations Center (SOC) has proven to be a pivotal approach for many organizations, as it enables both proactive and reactive responses to security incidents. This thesis examines effective strategies, workflows, and tools for implementing and enhancing SOC capabilities, with a specific focus on QiNet’s SOC service. The study begins with a comprehensive analysis of QiNet's existing SOC, documenting and mapping its workflows to identify strengths, weaknesses, and opportunities for improvement. This initial assessment lays the foundation for investigating how specific open-source tools can enhance SOC functionalities. Open-source solutions offer substantial advantages, including flexibility, cost-effectiveness, and adaptability, making them particularly beneficial for dynamic SOC environments. The research deepens the usage of open-source tools, emphasizing their ability to enhance SOC operations in terms of detection accuracy, efficiency, and responsiveness to incidents. Furthermore, the study explores strategies designed to streamline response workflows and improve incident handling times. By analyzing real-world SOC operations and incorporating automation, this thesis seeks to develop a framework that can be broadly applied to improve security posture, optimize resource allocation, and enhance cybersecurity resilience within organizations facing complex threat landscapes.

Relatori: Fulvio Valenza
Anno accademico: 2024/25
Tipo di pubblicazione: Elettronica
Numero di pagine: 101
Soggetti:
Corso di laurea: Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering)
Classe di laurea: Nuovo ordinamento > Laurea magistrale > LM-32 - INGEGNERIA INFORMATICA
Aziende collaboratrici: Qinet srl
URI: http://webthesis.biblio.polito.it/id/eprint/33794
Modifica (riservato agli operatori) Modifica (riservato agli operatori)