Abdeljabbar Ennajadi
An OpenC2-Based Framework for Infrastructure Discovery and Kernel-Level Security Enforcement.
Rel. Daniele Bringhenti, Fulvio Valenza. Politecnico di Torino, Corso di laurea magistrale in Cybersecurity, 2026
|
Preview |
PDF (Tesi_di_laurea)
- Tesi
Licenza: Creative Commons Attribution Non-commercial No Derivatives. Download (1MB) | Preview |
Abstract
The increasing complexity of modern cloud-native and hybrid environments has led to a fragmented landscape of security tools, complicating the orchestration of policies across diverse infrastructures. To address this challenge, this thesis explores the application of OpenC2 (Open Command and Control)—a standardized language for the command and control of security functions—as a unified interface for both infrastructure discovery and security enforcement. The research presents two independent but complementary contributions . The first part is concentrated on Context Discovery, developing specialized modules for Azure Kubernetes Service (AKS) and Proxmox VE. This component operates as a standalone service tasked with the automated identification of network topology, node identities, and IP addressing schemes, translating platform-specific metadata into a standardized architectural view.
In the second half I have implemented an OpenC2 Actuator profile for eBPF (extended Berkeley Packet Filter)
Relatori
Anno Accademico
Tipo di pubblicazione
Numero di pagine
Corso di laurea
Classe di laurea
URI
![]() |
Modifica (riservato agli operatori) |
