ELTE-OTP KIBERLAB TOPICS 2026/2027 Semester 1

1. Incident Management

1.1. Designing a Honeypot

The goal is to analyze the architectures of state-of-the-art Honeypot systems in order to investigate potential internet attacks, and to design and validate new solutions best suited for banking applications.

To validate the research results, the student designs an implementable honeypot system and develops its prototype. A related task is implementing logging and preparing the processing of the results.

A further goal, in order to observe attacker behavior as thoroughly as possible, is to simulate the banking environment within the honeypot as accurately and in as much detail as possible.

1.2. Attacker Profiling

The goal of graph-based modeling is to make the activities, tools, infrastructures, TTPs, and relationships of an attacker (or attacker group) analyzable as an interconnected network.

The student’s task is to create a visual system that displays information based on relationships. The task includes collecting and normalizing entities, mapping relationships, graph-based behavior analysis, identifying infrastructural connections, temporal analysis, and anomaly and pattern detection.

1.3. Detection and Monitoring of Phishing Websites

Developing new methods for searching for and detecting phishing or potentially phishing sites using internet sources and search engines, and examining the effectiveness of these new methods by identifying sites that abuse the OTP brand and pose a potential threat to OTP customers.

Monitoring the detected potentially phishing sites, tracking and analyzing changes on them, and recognizing phishing content affecting OTP. Developing new methods capable of effectively detecting and categorizing potentially phishing sites and logging their activity.

1.4. Combating Phishing using AI Agents

Researching AI agent-based defense solutions against phishing websites. The student’s task is to research the applicability of AI agents in combating phishing websites and the fraud carried out through them.

1.5. Detection of Artificial Intelligence Generated Content

The student analyzes, evaluates, and compares different AI systems and the systems created to detect them, with a special focus on voice- and image-based “deep fake” solutions. The student’s task is also to search for and become familiar with AI systems capable of facial recognition and fraud detection.

1.6. Automated Incident Analysis using Artificial Intelligence

The goal of the research is to examine the automated processing of large amounts of data from various cybersecurity systems and the possibilities of AI-based analysis.

During the research, the student examines how artificial intelligence and large language models (LLMs) can be applied to analyzing heterogeneous cybersecurity datasets, uncovering connections between events, and supporting the identification of potential security incidents. The goal is to research solutions capable of automatically normalizing, correlating, and prioritizing data from various sources.

2. Research on Defense Solutions Against Financial Fraud

2.1. Research on Tools for Automated Attacks

The goal of the research is to investigate the capabilities of automated, AI-based tools that enable the exploitation of vulnerabilities found on an organization’s external attack surface. The purpose of this is to better understand the nature of largely automated external attacks, thereby supporting defense efforts.

2.2. Analysis of Web Dependencies

Creating new methods and procedures for testing websites from a security perspective, with a special focus on external dependencies and embedded code.

2.3. Evaluating the Reliability of Account Numbers

The task of the research is to determine how reliable a given account number is. It is also particularly important to recognize and mark as reliable even unique account numbers belonging to well-known, large organizations or companies (e.g., NAV, MÁK, service providers). The goal of the research is to create new methods that combine the analysis of databases and web content with the application of artificial intelligence algorithms.

2.4. Transaction Fraud Detection using AI

The goal is to create new methods based on artificial intelligence that enable the development of an effective transaction fraud monitoring system.

3. Risk Management

3.1. Testing the Hungarian Language Proficiency of LLMs

Researching testing methods for the language knowledge of LLMs. Testing various LLMs based on their Hungarian language proficiency and their ability to solve problems in Hungarian.

Researching to what extent and how the language in which a question is asked affects the quality of the answer.

3.2. Examining Shadow IT Detection Possibilities and Analyzing Its Risks

Corporate users increasingly rely on SaaS, cloud-based, or web services that are not officially approved or registered by the IT and security organization. This phenomenon is known as Shadow IT. The goal of the research is to examine which data sources, technologies, and analytical methods can be used in a modern corporate environment to identify unapproved applications and services.

The student’s task is to produce a study that presents the possible technical approaches to Shadow IT detection, their advantages, limitations, and integration requirements, and that enables the assessment of the related risks (allow, block, tolerate, review, or onboard decisions).

3.3. Examining Remote Browser Isolation Technologies and Their Applicability in Corporate Environments

Web browsing remains one of the most important attack surfaces in corporate environments. The goal of Remote Browser Isolation, or RBI for short, is to ensure that web content is not processed directly on the user’s endpoint but in an isolated, remote environment. This can reduce the risk posed by malicious websites, drive-by download attacks, exploits, and phishing sites.

The goal of the research is to analyze the operating models, security value, limitations, and corporate applicability of RBI technologies, taking into account the functional, security, operational, integration, and user experience aspects of RBI.

3.4. Local Transcription and Analysis of Hungarian Speech

The goal is to research a system capable of using artificial intelligence to produce a transcript of spoken audio. The system should also be able to identify the speaker and record this in the transcript. An important requirement is that the solution run locally, so that no data is transmitted to external systems during its use.

3.5. Evaluating the Reliability of Source Code Libraries

Numerous source code repositories and libraries are available on the internet, but their reliability, maintainability, language, and legal status all vary. The student’s task is to research search methods and solutions that allow searching based on specified criteria (e.g., language, legal status, purpose), and that also evaluate the results from a security perspective (e.g., number of commits, number of maintainers, CVEs, number of downloads, code analysis).

3.6. Federated Learning

Training AI systems requires a huge amount of data. For security and legal reasons, centralized training is not always feasible.

4. Other

4.1. News Crawler

The main goal of the project is to develop an AI news analysis system that downloads, evaluates, and classifies news relevant from an IT security perspective, and then displays the most important ones.

4.2. Building a Simulated Banking Environment

The goal of the research is to build an environment within the Kiberlab that simulates the operation of a bank’s systems. This environment makes it possible to test and answer a range of research questions that cannot be addressed on a live system.

4.3. Freely Chosen Topics

Students who have an interesting cyber defense research idea of their own should feel free to contact us; we are happy to launch topics other than those listed above as well.