About
Background & Motivation
As small and medium-sized enterprises (SMEs) pursue digital transformation, their demand for security, privacy, and awareness of cyber threats increases dramatically. SMEs, unlike larger corporations, often lack the resources for implementing robust long-term cybersecurity measures, making them appealing targets for cybercriminals seeking lower-risk options. In addition, with the constant adoption of new technologies and resources, SMEs create numerous entry points for potential cyber-attacks. Each new addition to their systems becomes a potential target for cyber threats, expanding the scope for security breaches. Furthermore, contemporary architectures, often reliant on distributed services, exposed API endpoints, microservices, and containers, present a significantly larger attack surface. Protecting these intricate systems becomes a daunting task as the attack vectors multiply and become harder to safeguard. Finally, SMEs often lack access to frameworks that help them classify risks effectively and ensure compliance with existing regulations. This deficiency can leave them exposed to unforeseen vulnerabilities due to inadequate risk assessment.
Despite the continuously shifting cyber threat landscape, many SMEs lack a systematic approach to ensuring cybersecurity and when faced with cyber-attacks, struggle to recover and ultimately cease operations within six months, while very few have cyber insurance. The impact of these incidents on SMEs is substantial, leading to financial losses, reputational damage, client losses, recruitment challenges, and difficulties in securing new business.
CyberSuite’s vision is to tackle prevailing challenges in cybersecurity services by simplifying the intricacies involved. This involves streamlining the design, configuration, deployment, and management of these services, specifically catering to SMEs lacking dedicated cybersecurity resources. The overarching goal is to bridge market gaps by establishing an easily accessible marketplace for cybersecurity services tailored to SMEs, fostering simplicity and accessibility in high-level security, privacy, and trust. Another key aspect of the vision is to ensure seamless integration and interoperability among diverse cybersecurity tools and services within a unified platform, creating an ecosystem where these solutions collaborate effectively. Support measures for both supply and demand are included, encompassing a maturity and integration phase for solutions and a large-scale demonstration involving four end-users from different sectors. This approach, utilizing a hybrid online and in-person strategy, aims to engage commercial partners and customers. Lastly, the project intends to leverage past EU-funded research outcomes to enhance both the marketplace and the solutions, drawing on previous knowledge and innovations.
Maturity of services/tools
The project is set up with services and tools that have already reached TRL7-8 and by end of the project will be ready for the market or nearly so (TRL9). The services/tools and commercially available products leveraged by CyberSuite are presented in the following table:
CyberSuite Marketplace
From TRL 7 to TRL 9
The CyberSuite Marketplace is the main entry point for the end-users (i.e., cybersecurity service providers or customers) for the onboarding, management, and exploration of the provided cybersecurity services to be deployed to the infrastructures of the consuming organizations. The marketplace supports a set of functionalities, including the on-boarding of cybersecurity services on behalf of cybersecurity solutions providers and the consumption of such services by SMEs. The marketplace implementation is based on Open APIs, facilitating their adoption and usage by external stakeholders and the easy on-boarding of new cybersecurity services from third parties and vendors. A set of views are available for registration of the assets of each SMEs, the selection of set of services to be deployed in the SME infrastructure, where as a guidance in terms of configuration aspects as well as of risk analysis and assessment outcomes is provided along with the provision of cybersecurity analytics results (Relative Projects: PUZZLE, FutureTPM, 5G-INDUCE).
MAESTRO
From TRL 7 to TRL 9
MAESTRO is a product designed and developed by UBITECH that helps with the orchestration of cloud and edge applications and their whole lifecycle. MAESTRO uses a Kubernetes compatible and proprietary orchestration logic that can also integrate with 5G telco and cloud providers. Furthermore, it uses a secure overly mesh network, embeds security features, and provides an innovative and extensible user interface that supports application management, monitoring, and automated scaling. It is accompanied by an automated Security Operation Center that monitors security incidents, system vulnerabilities, and based on user-defined policies, applies countermeasures or preventive actions using various techniques. It uses tools such as Arkime, Wazuh, Starboard, eBPF, and Kafka Streams for real-time monitoring of devices and services. It has been designed and developed by UBITECH to integrate with the OLISTIC risk assessment framework product of UBITECH (Relative Projects: PUZZLE, SecureIoT, Rainbow).
ACAS
From TRL 7 to TRL 9
Advanced Cybersecurity Analytics Services (ACAS) is an open-source analytics tool and service based on a machine learning module for the analysis of encrypted traffic and network behaviour for the detection of zero-day attacks, developed in the PUZZLE project. It consists of two modules: a) the Feature Engineering module responsible for extraction and calculation of flow features is utilizing and extending an industrial tool MMT-Probe provided by MI, and b) the Deep Learning module that does the classification with the use of a Machine Learning model that is trained using the state-of-the-art Deep Learning techniques. The ACAS will be enacted to dynamically perform intrusion detection, extract analytics from encrypted network traffic, identify and correlate anomalous communication at networking and endpoint level, support threat intelligence in the CyberSuite Marketplace and infer knowledge from the programmable devices, discover new patterns by building incremental models that can be federated or parallelized (Relative Projects: GEIGER, PUZZLE, SANCUS, AI4CYBER).
SASTer
From TRL 7 to TRL 8
SASTer is an extensive tool for examining source code that performs comprehensive quality and security checks. It utilizes deep static code analysis and incorporates multiple code analysis and checking tools, such as a source code metric calculator, code duplication detector, vulnerability detector, and coding error detection. Its key modules are specifically designed to identify potential runtime exceptions and security vulnerabilities. By employing sophisticated symbolic execution, it detects runtime exceptions that could be exploited for Denial of Service (DoS) attacks. Additionally, it conducts control-flow and data-flow analysis to detect user inputs and data sinks that may contain unvalidated input, enabling the detection of security threats like OWASP vulnerabilities (e.g., Command Injection, Cross-Site Scripting, HTTP Response Splitting, LDAP Injection, Path Traversal, and SQL Injection). Furthermore, SASTer supports multiple programming languages, including Java, C/C++, C#, Python, JS, and RPG. It seamlessly integrates with the SonarQube platform through a plug-in and can be easily incorporated into CI/CD pipelines. By utilizing state-of-the-art deep static code analysis and symbolic execution techniques, it reduces false positives. The tool identifies issues in the source code and presents them in a structured text format, accessible through a web-based dashboard or compatible third-party open-source tools such as SonarQube. SASTer integrates with various well-known open-source SAST tools like SonarQube and Coverity Scan, providing precise file, path, line, and column information for all identified issues. Integrating SASTer into the CI/CD pipeline empowers software developers to identify potential issues prior to code release, thereby allowing them to proactively mitigate security threats early in the software development lifecycle. (Relative Projects: aerOS, TRUSTEE, OASSES).
Seer Box
From TRL 8 to TRL 9
Seer Box is a cutting-edge solution that ensures the security of web applications and services. Unlike traditional web application firewalls that only rely on known signatures, Seer Box reconstructs the logic of web applications from user-generated traffic. This innovative approach facilitates communication and cooperation between development, operations, and security teams, making it easier to secure web applications. Powered by Pluribus One’s proprietary analysis engine, Seer Box not only detects ongoing attacks, but also detects anomalous behaviours that could lead to future threats. It then provides feedback to developers about any vulnerabilities it identifies in the application. Seer Box seamlessly integrates with the existing IT infrastructure and can read data from various sources such as servers, traffic balancers, and application delivery controllers. It has even been certified by NGINX, the world’s most widely used web server and reverse proxy (https://www.nginx.com/products/nginx/modules/seerbox-pluribus-one/). By constantly monitoring web traffic, Seer Box keeps an updated list of web services and applications and provides real-time insight into the attack surface. It offers comprehensive protection against malicious traffic, including detection modules for common web application attacks and bot detection capabilities. Additionally, Seer Box integrates with SIEM solutions and has extensive automated reporting capabilities (Relative Projects: AIDA, AssureMOSS).
CyberSuite Dashboard
From TRL 6 to TRL 8
CyberSuite Dashboard is a personalized SMEs monitoring dashboard which provides an easily understandable interface that presents the analytics and interpreted results in an accessible, relevant and actionable form to the various end users, also capable of providing information on cyber threats that have already been identified with geo-spatial representation of network traffic (locations, areas, frequency & duration of attacks). The CyberSuite Dashboard communicates in real-time the dimensions of risks to the several identified user groups, and aid information in the direction of the efficient security risk management, advanced assurance and decision making. It also includes a Collective Interactive Data Visualizer (CIDV) provided as a service that fosters security exposure awareness and expose shared knowledge among SMEs in a userfriendly way. Its functionalities include the visualisation of attack vectors identified by the system, realtime log analysis, threat hunting, patterns and correlations between events and actions taking place among the infrastructures anonymously. By using CIDV, data that when examined individually might seem normal, will be combined with shared knowledge gained by the blockchain-enabled collective threat intelligence and reveal patterns or correlations between them, which could possibly identify security threats (Relative Projects: SANCUS, HERMES).
CyberSuite BC-based CTI
From TRL 6 to TRL 8
CyberSuite BlockChain-based Collective Threat Intelligence (CTI) service offered by COMPELLIO enables the secure information exchange about cyber-incidents, and detected vulnerabilities, which can be shared among different stakeholders, end users and SME/MEs, with access to the provided Hyperledger Fabric infrastructure. The CTI data can be exchanged instantly with flexible and extensible platforms for the efficient communication between the collaborated organizations or interested parties (Relative Projects: TRUSTYFOOD).
Kartos
From TRL 8 to TRL 9
Kartos is an in-house cybersecurity risk rating platform based on Artificial Intelligence that analyses the risk and cybersecurity level of an enterprise combining different independent metrics based on the information that is publicly accessible to cybercriminals in Internet, the Deep Web and the Dark Web. The weighted value of each one of these metrics builds a series of global scores that are presented on an interactive dashboard that shows how the organization is seen by bad actors from outside the corporate IT perimeter. Kartos changes the paradigm of the cybersecurity and risk assessment with an outside-in approach that completes the current deep protection framework for a 360o view of the real risk level of the company.
GEIGER
From TRL 7 to TRL 8
CGeiger develops with GEIGER a toolbox, educational support, and smart virtual assistant for assessing cyber-vulnerabilities and offering cyber-protection of SMEs with the specific focus on small businesses without ICT expertise. GEIGER is operational decentrally with datareplication capabilities across the devices it is installed on and connects on-demand to the cloud. GEIGER and any connected tools are easy to download and install on any kind of device (smart phone, tablet, laptop, etc.). It provides a high level of user experience, in an affordable, easy customizable and intuitive way for individuals with low IT background. The cybersecurity hardware devices are plugand-play, making them easily integrated by non-IT professionals. GEIGER provides a high level of user experience, in an affordable, easy customizable and intuitive way for individuals with low IT background. CGeiger’s cybersecurity educational program is organized for various target groups, from basic users to certified cybersecurity defenders, and is based on experiential methods (e.g., games). (Relative Projects: GEIGER).
Implementation plan and efficient use of resources
In order to make the flow of project activities more effective, efficient and agile, 6 interconnected macro areas of intervention were identified:
i) Analysis (cyber treat landscape analysis, services/tools maturity, unique characteristics identification)
ii) Implementation of (gap closing, integration)
iii) Use cases requirements and demonstration
iv) Awareness and Knowledge raising v) Building CyberSuite Ecosystem vi) Promote and Go to market.
In the table below, the CyberSuite DevSecOps paradigm that will be followed is presented. Upon the finalization of the first iteration, the proposed solution will be demonstrated in 4 real world use case scenarios and will be further evaluated and tested during the first CyberSuite hackathon organized. The second iteration will be focus mainly on enhancing the overall Cybersuite solution effectiveness based on any bugs or inconsistencies identified during the evaluation, after the 1st phase of the solutions uptake, and the comments/feedback received by the engaged the end-users. This will lead to the final integrated CyberSuite version, which will be further evaluated and tested (second hackathon) and demonstrated not only by the 4 use cases but also by the cross-sector SMEs/MEs registered within the cluster. To that end, the OpenAPIs of the solutions will be available throughout the project website and the open repositories Zenodo and GitHub, while the full versions and tailored services could be provided via an affordable subscription to the SMEs/MEs interested, based on the business model developed in the project.
It has to be noted that the CyberSuite solution reference architecture will be based on the existing work performed in the context of the PUZZLE project. In the figure below CyberSuite’s reference architecture is depicted. It is composed of six distinct “swimlanes”. These swimlanes include:
The Logically Centralized CyberSuite Orchestrator swimlane which incorporates all components that are considered “central” i.e., agnostic to the running services
The Orchestration Worker swimlane which incorporates the “local control plane” components of CyberSuite i.e., the components that materialize the business logic that is “close” to the running service
The Edge Analytics swimlane which incorporates all components that undertake “offline analytics” tasks i.e., tasks that are not considered near real-time
The Risk Assessment swimlane which incorporates the components and flows related to the real-time calculation of risk
The Blockchain-based Threat Intelligence swimlane which incorporates all components that materialize a secure and trustworthy data sharing environment regarding threat intelligence information
The CyberSuite Marketplace swimlane which encapsulates a central reference point where “templated” security services are packaged and advertised
