Project management for open port analysis and attack detection using Zeek

dc.contributor.authorLisnevskyi, Rostyslav
dc.contributor.authorMirzhakup, Madi
dc.contributor.authorBiloshchytska, Svitlana
dc.contributor.authorKostikov, Mykola
dc.contributor.authorLisnevskyi, Vitalii
dc.date.accessioned2026-04-17T10:12:05Z
dc.date.issued2025
dc.description.abstractA Zeek-based project for open port analysis and attack detection is presented. The methodology combines Waterfall with short MVP cycles and formal metrics. Zeek logs (conn, dns, notice) are correlated by UID, providing traceability and forensic reconstruction. The project's novelty lies in integrating an MVP into the Waterfall, with metric-based thresholds and replicated telemetry. We note that Zeek's extensive logging and built-in detection mechanisms make it a powerful network monitoring tool. We recommend that practitioners integrate Zeek with centralized log analysis systems (ELK/SIEM) for event correlation and automated alerts. Even a minimal Zeek configuration has been shown to reliably detect open port scans. These results highlight the value of structured project management for the rapid and predictable development of cybersecurity solutions. The prototype achieved F1 = 0.78 and MTTD ≈ 3 min, confirming measurable improvement within a hybrid Waterfall–MVP framework.
dc.identifier.citationProject Management for Open Port Analysis and Attack Detection Using Zeek / R. Lisnevskyi, M. Mirzhakup, S. Biloshchytska, M. Kostikov, V. Lisnevskyi // Cybersecurity, Infocommunication Systems and Networks 2025 (CISN 2025) : Proceedings of the Workshop on, Almaty, Kazakhstan, November 19–20, 2025. – CEUR, 2025. – Vol. 4180.
dc.identifier.orcidhttps://orcid.org/0000-0002-9006-6366
dc.identifier.orcidhttps://orcid.org/0009-0004-5160-4952
dc.identifier.orcidhttps://orcid.org/0000-0002-0856-5474
dc.identifier.orcidhttps://orcid.org/0000-0002-1569-8179
dc.identifier.orcidhttps://orcid.org/0009-0000-1678-5621
dc.identifier.urihttps://dspace.nuft.edu.ua/handle/123456789/51129
dc.language.isoen
dc.subjectopen port scanning
dc.subjectnetwork security monitoring
dc.subjectZeek (Bro)
dc.subjectintrusion detection
dc.subjectwaterfall project management
dc.subjectMVP
dc.subjectкафедра інформаційних технологій, штучного інтелекту і кібербезпеки
dc.subjectмоніторинг безпеки мережі
dc.subjectсканування відкритих портів
dc.subjectвиявлення вторгнень
dc.subjectкаскадний проєт
dc.titleProject management for open port analysis and attack detection using Zeek
dc.typeArticle

Файли

Контейнер файлів

Зараз показуємо 1 - 1 з 1
Вантажиться...
Ескіз
Назва:
2025-11_Lisnevskyi_Mirzhakup_Biloshchytska_Kostikov.pdf
Розмір:
759.72 KB
Формат:
Adobe Portable Document Format

Ліцензійна угода

Зараз показуємо 1 - 1 з 1
Вантажиться...
Ескіз
Назва:
license.txt
Розмір:
2.95 KB
Формат:
Item-specific license agreed upon to submission
Опис:

Колекції