Project management for open port analysis and attack detection using Zeek
| dc.contributor.author | Lisnevskyi, Rostyslav | |
| dc.contributor.author | Mirzhakup, Madi | |
| dc.contributor.author | Biloshchytska, Svitlana | |
| dc.contributor.author | Kostikov, Mykola | |
| dc.contributor.author | Lisnevskyi, Vitalii | |
| dc.date.accessioned | 2026-04-17T10:12:05Z | |
| dc.date.issued | 2025 | |
| dc.description.abstract | A Zeek-based project for open port analysis and attack detection is presented. The methodology combines Waterfall with short MVP cycles and formal metrics. Zeek logs (conn, dns, notice) are correlated by UID, providing traceability and forensic reconstruction. The project's novelty lies in integrating an MVP into the Waterfall, with metric-based thresholds and replicated telemetry. We note that Zeek's extensive logging and built-in detection mechanisms make it a powerful network monitoring tool. We recommend that practitioners integrate Zeek with centralized log analysis systems (ELK/SIEM) for event correlation and automated alerts. Even a minimal Zeek configuration has been shown to reliably detect open port scans. These results highlight the value of structured project management for the rapid and predictable development of cybersecurity solutions. The prototype achieved F1 = 0.78 and MTTD ≈ 3 min, confirming measurable improvement within a hybrid Waterfall–MVP framework. | |
| dc.identifier.citation | Project Management for Open Port Analysis and Attack Detection Using Zeek / R. Lisnevskyi, M. Mirzhakup, S. Biloshchytska, M. Kostikov, V. Lisnevskyi // Cybersecurity, Infocommunication Systems and Networks 2025 (CISN 2025) : Proceedings of the Workshop on, Almaty, Kazakhstan, November 19–20, 2025. – CEUR, 2025. – Vol. 4180. | |
| dc.identifier.orcid | https://orcid.org/0000-0002-9006-6366 | |
| dc.identifier.orcid | https://orcid.org/0009-0004-5160-4952 | |
| dc.identifier.orcid | https://orcid.org/0000-0002-0856-5474 | |
| dc.identifier.orcid | https://orcid.org/0000-0002-1569-8179 | |
| dc.identifier.orcid | https://orcid.org/0009-0000-1678-5621 | |
| dc.identifier.uri | https://dspace.nuft.edu.ua/handle/123456789/51129 | |
| dc.language.iso | en | |
| dc.subject | open port scanning | |
| dc.subject | network security monitoring | |
| dc.subject | Zeek (Bro) | |
| dc.subject | intrusion detection | |
| dc.subject | waterfall project management | |
| dc.subject | MVP | |
| dc.subject | кафедра інформаційних технологій, штучного інтелекту і кібербезпеки | |
| dc.subject | моніторинг безпеки мережі | |
| dc.subject | сканування відкритих портів | |
| dc.subject | виявлення вторгнень | |
| dc.subject | каскадний проєт | |
| dc.title | Project management for open port analysis and attack detection using Zeek | |
| dc.type | Article |
Файли
Контейнер файлів
1 - 1 з 1
Вантажиться...
- Назва:
- 2025-11_Lisnevskyi_Mirzhakup_Biloshchytska_Kostikov.pdf
- Розмір:
- 759.72 KB
- Формат:
- Adobe Portable Document Format
Ліцензійна угода
1 - 1 з 1
Вантажиться...
- Назва:
- license.txt
- Розмір:
- 2.95 KB
- Формат:
- Item-specific license agreed upon to submission
- Опис:
