Riassunto analitico
This thesis goal is the analysis and improvement of the open Proofpoint Emerging Threats Intellice rules, the project's expectation was, in addition to develop strong and robusts rules, to establish the validity and coverage provided by the ones already existing. Futhermore the elaborate is a little insight in the role of a purple teamer, which is a relatively new term for an hybrid team in the cyber defense world, his goal is to improve blue team detection mechanisms by studying and replicating cyber attacks, so with an approach similar to the one that you will find in a red team. In particular the book will cover the techniques applied for analysis and development of pattern matching rules for Network-based IDS, showing technical achievements with real life examples on attacks like zerologon, shellshock and others.
|