The Benefits of an Early Warning System in the Brazilian Academic Network

No ratings

Presented at FirstConferenceKualaLumpur 2018 by

Preliminary studies conducted by University of San Paulo(USP) during the last two years confirm that sources of open information, such as social networks provide relevant security data information[1],[2],[3]. These same studies confirm the utility of virtual networks as both sensors and actuators for EWS[4]. The RNP uses a variety of data sources to identify incidents involving its clients, so the use of social networks was necessary to identify a possible incident before it even occurred, based on these surveys and needs there was a need to create a tool to monitor social networks in search of incidents or future possible incidents involving our customers.The Horus system is a tool for monitoring malicious activity and detecting security events and incidents through the correlation and analysis of data provided by sensors from traditional networks and other sources such as social networks(Facebook,Twitter), forums, IRC and virtual network registries. This tool is also used to monitor the use of institutional names in forums and social networks, alerting possible malicious activities.As a contribution to RNP and its clients, this tool has aided in information security processes, especially security incident detection and response. It is also important to highlight the scientific contribution of this work, which is the evaluation of new sensors and the provision of empirical evidence of the use of information retrieval techniques to support new architectures of EWS (Early Warning Systems).Anticipation of events / incidents is done through a Web system and social media messaging collectors. At the moment the tool is successfully integrated with the SGIS, an incident management system used by CAIS and its clients. In more detail, the tool is able to monitor Twitter, Facebook, and IRC alerts; classify alerts into several classes to facilitate the work of administrators; provide important information for the investigation of attacks, such as screen captures of page disfigurements; manage the sensors through the system's own web interface; producing a timeline of alerts; calculate the risk index of different institutions from the captured alerts; allow manual categorization of alerts as they are processed manually by the administrator; display georeferenced information about captured alerts and manage multiple system core configurations in the web interface itself.