polito.it
Politecnico di Torino (logo)

A Novel User Behavior Emulation System for Cloud Applications and its Applicability to Adversary Emulation.

Marco Cavenati

A Novel User Behavior Emulation System for Cloud Applications and its Applicability to Adversary Emulation.

Rel. Cataldo Basile. Politecnico di Torino, UNSPECIFIED, 2024

Abstract:

In recent years, cyberattacks targeting cloud applications have significantly increased in both frequency and financial damage. To help secure cloud deployments, different vendors, including Cisco, have started proposing Cloud Native Application Protection Platforms. One of the most advanced features of these platforms is the automatic detection of threats based on behavior analysis and telemetry collection from different sources. In this context, the ability of automatically generating realistic workload on cloud applications becomes paramount for the development, enhancement, and testing of these data-driven functionalities. For this purpose, a system able to emulate a significant number of legitimate users and a malicious actor is required. However, current solutions either scale well or accurately reproduce user behavior but fail to do both. Furthermore, they only slightly address the intended purpose. The goal of this thesis work is to develop a general-purpose solution to model the behavior of legitimate users interacting with a cloud application. Subsequently, it proposes an accurate and scalable system to perform emulation. Finally, the project assesses the emulator’s ability to also mimic the actions of a malicious actor.

Relators: Cataldo Basile
Academic year: 2023/24
Publication type: Electronic
Number of Pages: 83
Additional Information: Tesi secretata. Fulltext non presente
Subjects:
Corso di laurea: UNSPECIFIED
Classe di laurea: New organization > Master science > LM-32 - COMPUTER SYSTEMS ENGINEERING
Ente in cotutela: INSTITUT EURECOM (FRANCIA)
Aziende collaboratrici: Cisco Systems France
URI: http://webthesis.biblio.polito.it/id/eprint/31105
Modify record (reserved for operators) Modify record (reserved for operators)