Securing systems,
one log at a time.
Hands-on SIEM monitoring (Wazuh, KUMA), incident response automation with n8n, and data engineering for SDN log anomaly detection.
Nguyễn Văn Tiến Phát
SOC Analyst / Security Engineer
Passionate about information security monitoring, log analysis, and incident response automation (SOAR).
Focus
Security & Systems
Academic
GPA: 3.12/4.0
Senior Year, HUFLIT
ABOUT ME
Behind the screens
Hi there, I am Nguyen Van Tien Phat, a senior Cybersecurity student at HUFLIT, currently working as a SOC Intern.
My primary passion lies in log analysis, threat detection, and incident response automation (SOAR). I have hands-on experience deploying and operating SIEM platforms like Wazuh and KUMA, as well as building automated playbooks using n8n.
Currently, I am focusing on my graduation thesis on "Data Engineering & Log Anomaly Detection in SDN Networks" — an exciting intersection of Software-Defined Networking and Artificial Intelligence.
guest@portfolio: ~
nguyen_van_tien_phat
21 years up, studying cybersecurity
[INFO] SIEM Architecture & Rules
[INFO] Incident Response Automation
[INFO] ML applied in SDN Security
EXPERTISE
Technical Skills
SIEM & Log Analysis
Deploy, configure, and monitor security events on Wazuh and KUMA SIEM platforms.
SOAR Automation
Build automated Incident Response workflows using n8n and REST API integrations.
AI in Security
Research machine learning applications for SDN log anomaly detection and fault classification.
Network Security
SDN architecture, firewall configuration, network traffic monitoring, and packet analysis.
❯ tech_stack.json
PROJECTS
Featured Work
A collection of featured projects built during my studies and practical experience
SOC Monitoring & Security Automation
Built a practical SOC laboratory environment to monitor network events, centralize logs, detect threats, and automate incident alerts using pfSense, Suricata, Wazuh SIEM, and n8n.
WHAT I BUILT
- 01VLAN SegmentationSegmented monitored network zones and routed traffic between isolated VLANs.
- 02pfSense Firewall RulesConfigured rules controlling Ingress, Egress, and inter-subnet internal traffic flows.
- 03Suricata IDS AlertsCaptured network packets and generated signature-based threat detection telemetry.
- 04Wazuh Centralized LogsCollected and centralized logs from host agents and network devices for log correlation.
- 05n8n Alert WorkflowAutomated real-time Telegram alert notifications and incident response playbooks.
Kaspersky KUMA SIEM & SOAR Integration
Practical Experience (SOC Intern @ DTG): Configured KUMA Agent to collect Nginx & auditd logs on Linux, practiced Wazuh FIM; translated, customized & fine-tuned Correlation Rules for Web Shell/SQLi detection based on vendor PoC Guides; built automated alert workflows (n8n) & integrated DFIR-IRIS following NIST SP 800-61r2 standards.
Ablation-Aware Operational Anomaly Detection in Controlled SDN Logs Using Temporal Neural Models
Accepted conference paper in AI-driven log intelligence, temporal neural modeling, and operational anomaly detection.
Authors: ThS. Cao Tiến Thành, Phạm Quốc Huy, Nguyễn Văn Tiến Phát, PGS.TS. Trần Mạnh Hà, TS. Trần Thị Minh Khoa
WHAT I BUILT (DATA ENGINEERING)
- 01SDN Network SimulationDesigned a Tree Topology (depth=3, fanout=2) on Mininet connected to POX Controller, simulating complex network traffic environments.
- 02Fault Injection ScenariosConstructed automated injection scripts simulating 7 failure scenarios: DDoS, hardware failure, controller disconnect, flow table overflow, link failure...
- 03Log Normalization & CleaningDeveloped scripts for noise filtering, log anti-spamming, and network feature extraction from raw Open vSwitch logs to standardized formats.
- 04Dataset PublicationProduced standardized datasets of ~300,000 samples (Multi-class and Binary CSV/JSON) for deep learning (TCN) model training.
PUBLICATIONS
Research & Publications
Academic research contributions, conference proceedings, and cybersecurity intelligence.
Ablation-Aware Operational Anomaly Detection in Controlled SDN Logs Using Temporal Neural Models
Authors: ThS. Cao Tiến Thành, Phạm Quốc Huy, Nguyễn Văn Tiến Phát, PGS.TS. Trần Mạnh Hà, TS. Trần Thị Minh Khoa
Proposes an end-to-end operational framework for software-defined networking (SDN) log collection, feature extraction, and temporal neural model inference to detect network anomalies and system fault scenarios.
CONNECT
Get In Touch
I am always open to discussing new career opportunities, security projects, or simply chatting about Cybersecurity. Feel free to reach out!