PROTECTIVE - Proactive Risk Management through Improved Cyber Situational Awareness

Date: 
01/09/2016 to 31/08/2019

Introduction

PROTECTIVE is a system for proactive risk management through improved situational awareness. The system is intended for National Research Education Network (NREN) Computer Security Incident Response Teams (CSIRTs) initially to understand, correlate, prioritize and share cyber threat intelligence for enhanced decision-making capabilities.

We aim to provide NRENs with improved security alert management capabilities, through uses of meta alerts, alerts that summarise a plethora of threats and incidents in order to understand the bigger picture of the threat landscape, provide better context awareness and enhance existing cyber threat intelligence sharing capabilities through automation while remaining General Data Protection Regulation (GDPR) compliant.

Who is the project designed for?

- Public Computer Security Incident Response Teams (CSIRTs), initially targeting NRENs.
- Managed Security Service Providers (MSSPs).

The end-users are security operation centre operators and analysts that make decisions based on cyber threat intelligence and alerts generated internally.

How is your project benefitting the end-user?

Enhancing cyber threat intelligence sharing through:

  • Applying Correlation and Prioritization methods w.r.t. your own constituency.
  • Computational Trust, being able to score confidence about the data received.
  • Automation, by moving away from solely relying on email ticket systems to share cyber threat intelligence.
  • GDPR compliance through development of run-time monitoring.
  • MSSPs will be able to benefit CTI from NRENs in order to protect SMEs from the latest observed threats.

Please briefly describe the results your project achieved so far

We have created an early instance of the tool running, and are currently developing and enhancing its performance and usability.

What are the next steps for your project?

We are running two pilots to test the tool in live NREN environments in which we collect performance and usability data.

Week: 
Tuesday, 13 February, 2018

News

Share your view to identify EU-US priorities on cybersecurity and privacy R&I

The AEGIS project is working to promote cybersecurity and privacy dialogue and cooperation between the US and the EU.

As part of its activities AEGIS is conducting an online survey to identify R&I priorities for EU-US cooperation in cybersecurity and privacy.

Events

28/06/2018
Free Live Cybersecurity Webinar – Cyberwatching.eu: opportunities for CS&P clusters

Cyberwatching.eu launch the first webinar for clusters that are actively working in Cybersecurity and Privacy, in order to share experiences and information on how they can help their members to keep up to date in these sectors.

One of the main goals of cyberwatching.eu project is to take advantage of the results of previous European R&D projects to build new product and services, fostering synergies among different European clusters. In this webinar we will give you an overview of:

10/10/2018 to 11/10/2018
Transatlantic ICT Forum 2018