ASSESS IDENTIFIED SECURITY BREACHES AND DEVELOP RECOMMENDATIONS FOR THEIR PREVENTION

ASSESS IDENTIFIED SECURITY BREACHES AND DEVELOP RECOMMENDATIONS FOR THEIR PREVENTION

Authors

  • Narzikulova Sevinch Aktamovna Faculty of Computer Engineering Student of Information Systems and Technologies

Keywords:

log files, log analysis, information security, cybersecurity, security breach, SSH, authentication, brute-force attack, unauthorized access, failed password, accepted password, root account, Fail2ban, firewall, SSH keys, IP address, SIEM, security monitoring, Linux, Ubuntu Server.

Abstract

This thesis project is devoted to the study of methods for detecting security breaches through the analysis of log files in information systems. The research examines the role of log files in identifying unauthorized access, brute-force attacks, repeated authentication failures, suspicious IP addresses, and attempts to access privileged accounts. Particular attention is paid to the analysis of SSH authentication logs in Ubuntu Server, including “Failed password” and “Accepted password” events recorded in the /var/log/auth.log file.

References

Theis, M. C., Trzeciak, R. F., Costa, D., Moore, A. P., Miller, S., Cassidy, T., Claycomb, W. R. Common Sense Guide to Mitigating Insider Threats, Sixth Edition. Carnegie Mellon University, Software Engineering Institute, 2019.

IBM Security, Ponemon Institute. Cost of a Data Breach Report 2025. IBM, 2025.

Ponemon Institute / DTEX Systems. 2025 Cost of Insider Risks Report bo‘yicha tahliliy ma’lumotlar.

Kent, K., Souppaya, M. NIST SP 800-92: Guide to Computer Security Log Management. National Institute of Standards and Technology, 2006.

NIST CSRC. Security Information and Event Management - Glossary. National Institute of Standards and Technology.

IETF. RFC 5424: The Syslog Protocol. Internet Engineering Task Force.

Microsoft Learn. Sysmon - Sysinternals. Microsoft documentation

NIST. Cybersecurity Framework 2.0, 2024.

NIST. SP 800-207: Zero Trust Architecture, 2020.

CISA. Zero Trust Maturity Model Version 2.0, 2023.

CISA. More than a Password: Multifactor Authentication.

MITRE. MITRE ATT&CK: Lateral Movement, TA0008.

Labor Code of the Republic of Uzbekistan. RU-798, 28.10.2022.

Law of the Republic of Uzbekistan "On Labor Protection". RU-410, September 22, 2016.

Law of the Republic of Uzbekistan "On Fire Safety". RU-226 No. 30.09.2009.

ISO 45001:2018. Occupational health and safety management systems — Requirements with guidance for use. International Organization for Standardization, 2018.

National Institute for Occupational Safety and Health (NIOSH). Hierarchy of Controls. Centers for Disease Control and Prevention.

Occupational Safety and Health Administration (OSHA). Computer Workstations eTool. United States Department of Labor.

Downloads

Published

2026-08-01
Loading...