
This thesis included an in-depth analysis on how to tackle each stage of the Cyber Kill Chain in a lab environment. The hypothesis of this project includes mapping the CIS v8 Controls to the MITRE ATT&CK techniques and implement the mitigation inspired from CIS Controls to provide a mitigation to break the kill chain. The implementation has been performed using a lab setup which server as a generic and secure ecosystem/environment which will demonstrate several security solutions such as SIEM, NIDS, HIDS, Proxy, Firewall, Malware Scanning. By using one or more implemented security solutions, we have created a lab to safeguard itself from attacks by tailoring it specifically to tackle every stage of the Cyber Kill Chain. The lab is setup using a type-2 hypervisor: Oracle Virtual Box. Where the victim machine is a Windows 10 VM and Linux serves as a gateway for security solutions. Wherever possible, we have made use of cloud services such as ELK in the Cloud to reduce the workload on the underlying hardware and provide us high availability of the SIEM service.
000, Electronic computers. Computer science, Computer Security, 004
000, Electronic computers. Computer science, Computer Security, 004
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
