PROTECTIVE - Proactive Risk Management through Improved Cyber Situational Awareness

Date: 
01/09/2016 to 31/08/2019

Introduction

PROTECTIVE is a system for proactive risk management through improved situational awareness. The system is intended for National Research Education Network (NREN) Computer Security Incident Response Teams (CSIRTs) initially to understand, correlate, prioritize and share cyber threat intelligence for enhanced decision-making capabilities.

We aim to provide NRENs with improved security alert management capabilities, through uses of meta alerts, alerts that summarise a plethora of threats and incidents in order to understand the bigger picture of the threat landscape, provide better context awareness and enhance existing cyber threat intelligence sharing capabilities through automation while remaining General Data Protection Regulation (GDPR) compliant.

Who is the project designed for?

- Public Computer Security Incident Response Teams (CSIRTs), initially targeting NRENs.
- Managed Security Service Providers (MSSPs).

The end-users are security operation centre operators and analysts that make decisions based on cyber threat intelligence and alerts generated internally.

How is your project benefitting the end-user?

Enhancing cyber threat intelligence sharing through:

  • Applying Correlation and Prioritization methods w.r.t. your own constituency.
  • Computational Trust, being able to score confidence about the data received.
  • Automation, by moving away from solely relying on email ticket systems to share cyber threat intelligence.
  • GDPR compliance through development of run-time monitoring.
  • MSSPs will be able to benefit CTI from NRENs in order to protect SMEs from the latest observed threats.

Please briefly describe the results your project achieved so far

We have created an early instance of the tool running, and are currently developing and enhancing its performance and usability.

What are the next steps for your project?

We are running two pilots to test the tool in live NREN environments in which we collect performance and usability data.

Week: 
Tuesday, 13 February, 2018

Project type:

News

Europol - Internet Organised Crime Threat Assessment 2018

Europol has just released its fifth annual Internet Organised Crime Threat Assessment (IOCTA).

The report offers a unique law enforcement view of the emerging threats and key developments in the field of cybercrime over the last year and warns of 15 ways in which people can fall prey to cyber criminals.

Events

29/09/2018 to 05/10/2018
Cryptology And Network Security - 30th September/ 3rd October 2018 - Naples (Italy)

The International Conference on Cryptology And Network Security (CANS) is a recognized annual conference, focusing on all aspects of cryptology, and of data, network, and computer security. CANS 2018 will be held in Naples from the next 30th September until the 3rd October.

06/10/2018 to 11/10/2018
Security of Personal Data Processing Event - 8th October - Athens (Greece)

ENISA and Cyberwatching.eu co-organize in October 8, 2018 a workshop on security measures (article 32 GDPR) in Athens.