YValidator: a flexible tool for fetching and validating Indicators of Compromise

DSpace/Manakin Repository

Show simple item record

dc.contributor.advisor Focardi, Riccardo it_IT
dc.contributor.author Narder, Davide <1996> it_IT
dc.date.accessioned 2021-06-27 it_IT
dc.date.accessioned 2021-10-07T12:38:22Z
dc.date.available 2021-10-07T12:38:22Z
dc.date.issued 2021-07-16 it_IT
dc.identifier.uri http://hdl.handle.net/10579/19923
dc.description.abstract The tool developed is an attempt to automate and speed up the collection and verification of IOCs and to limit manual intervention. It is desiged to regularly fetch data from selected sources that share IOCs such as Github repositories, Twitter profiles, security blogs, etc. Indicators have to go through a series of verification steps where a partial score and weight is generated for every step and at the end a decision is made on the validity and maliciousness of every indicator. Then, as a final check, the last validation step consists of searching the malicious indicators in various QRadar servers to gather additional information on the frequency or absence of the searched IOC in the systems monitored. Finally a sequence of events is generated, grouping indicators based on source, and is written in a MISP feed format for easy ingestion in MISP instances. it_IT
dc.language.iso en it_IT
dc.publisher Università Ca' Foscari Venezia it_IT
dc.rights © Davide Narder, 2021 it_IT
dc.title YValidator: a flexible tool for fetching and validating Indicators of Compromise it_IT
dc.title.alternative YValidator: a flexible tool for fetching and validating Indicators of Compromise it_IT
dc.type Master's Degree Thesis it_IT
dc.degree.name Informatica - computer science it_IT
dc.degree.level Laurea magistrale it_IT
dc.degree.grantor Dipartimento di Scienze Ambientali, Informatica e Statistica it_IT
dc.description.academicyear 2020/2021-Sessione Estiva it_IT
dc.rights.accessrights openAccess it_IT
dc.thesis.matricno 865983 it_IT
dc.subject.miur INF/01 INFORMATICA it_IT
dc.description.note it_IT
dc.degree.discipline it_IT
dc.contributor.co-advisor it_IT
dc.date.embargoend it_IT
dc.provenance.upload Davide Narder (865983@stud.unive.it), 2021-06-27 it_IT
dc.provenance.plagiarycheck Riccardo Focardi (focardi@unive.it), 2021-07-12 it_IT


Files in this item

This item appears in the following Collection(s)

Show simple item record