Davide Abate
Extending Security Orchestration Automation and Response to the Cloud.
Rel. Cataldo Basile, Francesco Settanni. Politecnico di Torino, Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering), 2026
|
Preview |
PDF (Tesi_di_laurea)
- Tesi
Licenza: Creative Commons Attribution Non-commercial No Derivatives. Download (1MB) | Preview |
Abstract
Public cloud platforms host the bulk of modern enterprise workloads. As organisations continue to migrate identity, compute, storage and data services from on-premise data centres to managed cloud offerings, the security incidents that reach a Security Operations Centre (SOC) have followed them there: identity-centric attacks, control-plane abuse and supply-chain compromises now dominate the alerts that an analyst must triage in a cloud-first deployment. Analysts face high alert volumes and short response budgets, while the SOAR products that have traditionally driven their automation rely on hand-authored, vendor-specific playbooks that scale poorly as the cloud surface evolves. Two parallel developments offer a way forward: the OASIS CACAO 2.0 specification, which defines a vendor-neutral playbook format with precise execution semantics, and the maturation of the MITRE ATT&CK Cloud and Identity Provider matrices as a common taxonomy for the threats SOC analysts actually face in cloud-native deployments.
This thesis builds on a CACAO 2.0 playbook-driven remediator developed within the TORSEC research group at Politecnico di Torino
Relatori
Anno Accademico
Tipo di pubblicazione
Numero di pagine
Corso di laurea
Classe di laurea
URI
![]() |
Modifica (riservato agli operatori) |
