Approaching Cyber Situational Awareness Through Digital Services Availability Monitoring and Threat Intelligence: The MonSys Platform Experience
摘要
The security community has long identified cyber situational awareness as a critical component of effective cyber defense on a national, sectoral, and international scale. Additionally, in recent years, and particularly as the online operations of many sectors of daily life have become increasingly interdependent, the need to safeguard individual services to protect entire economic sectors has become increasingly apparent. Intrusion detection and prevention systems (IDS/IPS) are widely recognized as a critical component of an organization’s cyber resilience and situational awareness skills, as they are an excellent tool for preventing and detecting malicious activity directed at business operations. The extensive majority of scientific and commercial advances in the field, however, remain widely focused on the development of complex solutions for large enterprises or specific infrastructures, rendering them inaccessible to small and medium-sized enterprises (SMEs), academic institutions, and non-profit organizations that are unable to afford, administer, manage, or even consider employing IDS/IPS in their organizational frame of reference. This article is a revised and extended version of the “MonSys: A Scalable Platform for Monitoring Digital Services Availability, Threat Intelligence, and Cyber Resilience Situational Awareness” article, published in Information & Security: An International Journal vol. 46, 2020, and proposes an approach to making monitoring systems more widely accessible and shares the lessons learned, and the key findings from the pilot implementation of a platform, specifically designed to address those needs – MonSys. MonSys is a flexible, robust, and scalable monitoring platform, implemented as a cloud-based service and an on-premise solution, which is specifically designed at addressing the need for ensuring digital service availability. It includes customized and standard service integrity and availability checks. Furthermore, this contribution will present some achievements, findings, and ongoing efforts concerning the planned integration of this platform, with the Early Warning System of the ECHO project, while ensuring long-term data storage, custom tests, and alerts, behavior analysis, and information sharing with very little limitations, while preserving excellent scalability with thousands of ad-hoc tests for online services and devices, such as IoT and IIoT.