Global cyberattacks, orchestrated by diverse actors, continually exploit system vulnerabilities, with Remote Desktop Protocol (RDP) as a preferred entry point. This research introduces an innovative, proactive approach using Microsoft Azure Sentinel, a cloud-based SIEM solution. It employs a Vulnerable Windows Virtual Machine (Honeypot) for attack monitoring, leverages Network Security Groups (NSGs) for traffic management, and centralizes event logs in Log Analytics Workspaces (LAW). PowerShell enriches logs with geographical context through IPGeolocation.io. Microsoft Sentinel, configured with custom rules, detects global cyber threats. Results highlight the approach’s effectiveness in understanding and responding to global cyberattacks, including brute force attack analysis, distribution across countries, and username targeting. This research emphasizes the importance of proactive strategies in addressing evolving challenges in cybersecurity.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Mapping Cyberattack Patterns and Detection: An Azure Sentinel Approach

  • Chidozie Stanley Odigbo,
  • Hayden Wimmer,
  • Jongyeop Kim

摘要

Global cyberattacks, orchestrated by diverse actors, continually exploit system vulnerabilities, with Remote Desktop Protocol (RDP) as a preferred entry point. This research introduces an innovative, proactive approach using Microsoft Azure Sentinel, a cloud-based SIEM solution. It employs a Vulnerable Windows Virtual Machine (Honeypot) for attack monitoring, leverages Network Security Groups (NSGs) for traffic management, and centralizes event logs in Log Analytics Workspaces (LAW). PowerShell enriches logs with geographical context through IPGeolocation.io. Microsoft Sentinel, configured with custom rules, detects global cyber threats. Results highlight the approach’s effectiveness in understanding and responding to global cyberattacks, including brute force attack analysis, distribution across countries, and username targeting. This research emphasizes the importance of proactive strategies in addressing evolving challenges in cybersecurity.