UTFacultiesEEMCSDisciplines & departmentsSCSResearchRunning ProjectsSeReNity: Evidence-based Security Response Centers

SeReNity: Evidence-based Security Response Centers

running project Semantics, Cybersecurity & Services (SCS)

SeRenity: Evidence-based security response centers

Funded by: NWO

Period: Jun, 2021 - May, 2024

Contact:

Partners: Eindhoven University of Technology, Siemens AG, TNO

Description:

Prompt and timely response to incoming cyber-attacks and incidents is a core requirement for business continuity and safe operations for organizations operating at all levels (commercial, governmental, military). The effectiveness of these measures is significantly limited (and oftentimes defeated altogether) by the inefficiency of the attack identification and response process which is, effectively, a show-stopper for all attack prevention and reaction activities. The cognitive-intensive, human-driven alarm analysis procedures currently employed by Security Operation Centres are made ineffective (as opposed to only inefficient) by the sheer amount of alarm data produced, and the lack of mechanisms to automatically and soundly evaluate the arriving evidence to build operable risk-based metrics for incident response. This project will build foundational technologies to achieve Security Response Centres (SRC) based on three key components: (1) risk-based systems for alarm prioritization, (2) real-time, human-centric procedures for alarm operationalization, and (3) technology integration in response operations.