PROTECTIVE is a system for proactive risk management through improved situational awareness. The system is intended for National Research Education Network (NREN) Computer Security Incident Response Teams (CSIRTs) initially to understand, correlate, prioritize and share cyber threat intelligence for enhanced decision-making capabilities.
We aim to provide NRENs with improved security alert management capabilities, through uses of meta alerts, alerts that summarise a plethora of threats and incidents in order to understand the bigger picture of the threat landscape, provide better context awareness and enhance existing cyber threat intelligence sharing capabilities through automation while remaining General Data Protection Regulation (GDPR) compliant.
Who is the project designed for?
- Public Computer Security Incident Response Teams (CSIRTs), initially targeting NRENs.
- Managed Security Service Providers (MSSPs).
The end-users are security operation centre operators and analysts that make decisions based on cyber threat intelligence and alerts generated internally.
How is your project benefitting the end-user?
Enhancing cyber threat intelligence sharing through:
- Applying Correlation and Prioritization methods w.r.t. your own constituency.
- Computational Trust, being able to score confidence about the data received.
- Automation, by moving away from solely relying on email ticket systems to share cyber threat intelligence.
- GDPR compliance through development of run-time monitoring.
- MSSPs will be able to benefit CTI from NRENs in order to protect SMEs from the latest observed threats.
Please briefly describe the results your project achieved so far
We have created an early instance of the tool running, and are currently developing and enhancing its performance and usability.
What are the next steps for your project?
We are running two pilots to test the tool in live NREN environments in which we collect performance and usability data.