PROTECTIVE - Proactive Risk Management through Improved Cyber Situational Awareness

Date: 
01/09/2016 to 31/08/2019

Introduction

PROTECTIVE is a system for proactive risk management through improved situational awareness. The system is intended for National Research Education Network (NREN) Computer Security Incident Response Teams (CSIRTs) initially to understand, correlate, prioritize and share cyber threat intelligence for enhanced decision-making capabilities.

We aim to provide NRENs with improved security alert management capabilities, through uses of meta alerts, alerts that summarise a plethora of threats and incidents in order to understand the bigger picture of the threat landscape, provide better context awareness and enhance existing cyber threat intelligence sharing capabilities through automation while remaining General Data Protection Regulation (GDPR) compliant.

Who is the project designed for?

- Public Computer Security Incident Response Teams (CSIRTs), initially targeting NRENs.
- Managed Security Service Providers (MSSPs).

The end-users are security operation centre operators and analysts that make decisions based on cyber threat intelligence and alerts generated internally.

How is your project benefitting the end-user?

Enhancing cyber threat intelligence sharing through:

  • Applying Correlation and Prioritization methods w.r.t. your own constituency.
  • Computational Trust, being able to score confidence about the data received.
  • Automation, by moving away from solely relying on email ticket systems to share cyber threat intelligence.
  • GDPR compliance through development of run-time monitoring.
  • MSSPs will be able to benefit CTI from NRENs in order to protect SMEs from the latest observed threats.

Please briefly describe the results your project achieved so far

We have created an early instance of the tool running, and are currently developing and enhancing its performance and usability.

What are the next steps for your project?

We are running two pilots to test the tool in live NREN environments in which we collect performance and usability data.

Week: 
Tuesday, 13 February, 2018

Project type:

Events

27/11/2018 to 28/11/2018
Cyber Investor Days

On 27th and 28th November in Berlin, Germany, ECSO is organizing in collaboration with Secunet and TeleTrusT, the Cyber Investor Days.

The most promising European cyber security start-ups and SMEs will have an opportunity to pitch their solution and meet the influential German and international investors during strategic business matchmaking sessions.

CYBER INVESTOR DAYS will be officially opened by Andreas Koenen, Director General of the Cyber and Information Security Directorate at the German Ministry of Interior, and Clemens Kabel, Investment Director at IBB Investment.

13/12/2018 to 14/12/2018
Call for Papers: Halfway Through the Digital Single Market Strategy: “Bedrock of Trust” or illusion?

Call for Papers

The Law Faculty of the University of Lille cordially invites junior and senior researchers to participate in a conference held as part of the Horizon 2020 project “TRUESSEC.eu”, on the 13th and 14th December 2018. The conference will be hosted by the Law Faculty.