Project management for open port analysis and attack detection using Zeek

Loading...
Thumbnail Image

Date

DOI

item.page.thesis.degree.name

item.page.thesis.degree.level

item.page.thesis.degree.discipline

item.page.thesis.degree.department

item.page.thesis.degree.grantor

item.page.thesis.degree.advisor

item.page.thesis.degree.committeeMember

Journal Title

Journal ISSN

Volume Title

Publisher

Abstract

A Zeek-based project for open port analysis and attack detection is presented. The methodology combines Waterfall with short MVP cycles and formal metrics. Zeek logs (conn, dns, notice) are correlated by UID, providing traceability and forensic reconstruction. The project's novelty lies in integrating an MVP into the Waterfall, with metric-based thresholds and replicated telemetry. We note that Zeek's extensive logging and built-in detection mechanisms make it a powerful network monitoring tool. We recommend that practitioners integrate Zeek with centralized log analysis systems (ELK/SIEM) for event correlation and automated alerts. Even a minimal Zeek configuration has been shown to reliably detect open port scans. These results highlight the value of structured project management for the rapid and predictable development of cybersecurity solutions. The prototype achieved F1 = 0.78 and MTTD ≈ 3 min, confirming measurable improvement within a hybrid Waterfall–MVP framework.

Description

Citation

Project Management for Open Port Analysis and Attack Detection Using Zeek / R. Lisnevskyi, M. Mirzhakup, S. Biloshchytska, M. Kostikov, V. Lisnevskyi // Cybersecurity, Infocommunication Systems and Networks 2025 (CISN 2025) : Proceedings of the Workshop on, Almaty, Kazakhstan, November 19–20, 2025. – CEUR, 2025. – Vol. 4180.

Collections

Endorsement

Review

Supplemented By

Referenced By