Subject

Cyber-Threat Analysis

1. Course Title Cyber-Threat Analysis
Cyber threats analysis
2. Code IT-Z-01
3. Study Programme Internet technologies and cybersecurity
4. Organizer of the study programme (unit, institute, department or division) Faculty of Computer Science and Engineering
5. Degree level (first, second, third cycle) Second cycle
6. Academic year / semester 9 / Winter
7. Number of ECTS credits 6
8. Teacher Anastas Mishov, Sonja Filiposka
9. Prerequisites for enrolling in the course
10. Objectives of the course programme (competences) Курсот ќе им овозможи на студентите да се запознаат со фундаменталните концепти и алатки на модерната анализа на сајбер закани. Студентите ќе се здобијат со знаења за животниот циклус на анализата на сајбер закани, идентификацијата, собирањето и интеграцијата на информации за закани и формати на запишување на информацијата.
11. Course content Разбирање на анализата на закани. Традиционален животен циклус и структурирани аналитички техники. SIEM. Дефинирање на закани, разбирање на поврзаните ризици. Методи за детекција на закани. Конзумација на информации за закани за различни цели. Градење на тим за анализа на сајбер закани, планирање, насочување, развој на барања и цели. Kill chain модел. Дијамант модел. Извори за собирање информации:: домени, надворешни податочни множества, TLS/SSL сертификати, open source intelligence. Зачувување и структурирање на податоците. Структурирани техники за анализа. Истражување на хипотези. Градење кампањи. Тактичка и оперативна дисеминација. Стандардни технологии за анализа на сајбер закани (пр., CIF сервери, TAXII сервери, SIEM и други). Откривање на виновникот.
12. Learning methods Lectures supported by slide presentations, interactive lectures, exercises (using equipment and software packages), teamwork, case studies, guest lecturers, independent preparation and defense of a project assignment and seminar paper, learning in an electronic environment (forums, consultations).
13. Total available time 6 ECTS x 30 hours = 180 hours
14. Distribution of available time 45 + 15 + 30 + 50 + 40 = 180 hours
15. Forms of teaching activities
15.1. Lectures - theoretical instruction 45 hours
15.2. Exercises (laboratory, auditory), seminars, teamwork 15 hours
16. Other forms of activities
16.1. Project assignments 50 hours
16.2. Independent assignments 30 hours
16.3. Home study 40 hours
17. Assessment method
17.1. Tests 45 points
17.2. Seminar paper / project (presentation: written and oral) 50 points
17.3. Activities and learning 10 points
17.4. Final exam 0 points
18. Grading criteria (points / grade)
up to 50 points5 (five) (F)
from 51 to 60 points6 (six) (E)
from 61 to 70 points7 (seven) (D)
from 71 to 80 points8 (eight) (C)
from 81 to 90 points9 (nine) (B)
from 91 to 100 points10 (ten) (A)
19. Requirement for obtaining a signature and taking the final exam completed activities
20. Language of instruction Macedonian and English
21. Method for monitoring the quality of teaching Internal evaluation and survey mechanism
22. Literature
22.1. Required literature
1. Kyle Wilhoit, Joseph Opacki | Operationalizing Threat Intelligence: A guide to developing and operationalizing cyber threat intelligence programs | Packt Publishing | 2022
2. Aaron Roberts | Cyber Threat Intelligence: The No-Nonsense Guide for CISOs and Security Managers | Apress | 2021
3. Valentina Costa-Gazcón | Practical Threat Intelligence and Data-Driven Threat Hunting: A hands-on guide to threat hunting with the ATT&CK™ Framework and open source tools | Packt Publishing | 2021
22.2. Additional literature
No. Author Title Publisher Year