SOC Intern & Cybersecurity Student

Securing systems,
one log at a time.

Hands-on SIEM monitoring (Wazuh, KUMA), incident response automation with n8n, and data engineering for SDN log anomaly detection.

Nguyễn Văn Tiến Phát

SOC Analyst / Security Engineer

Passionate about information security monitoring, log analysis, and incident response automation (SOAR).

Focus

Security & Systems

Academic

GPA: 3.12/4.0

Senior Year, HUFLIT

ABOUT ME

Behind the screens

Hi there, I am Nguyen Van Tien Phat, a senior Cybersecurity student at HUFLIT, currently working as a SOC Intern.

My primary passion lies in log analysis, threat detection, and incident response automation (SOAR). I have hands-on experience deploying and operating SIEM platforms like Wazuh and KUMA, as well as building automated playbooks using n8n.

Currently, I am focusing on my graduation thesis on "Data Engineering & Log Anomaly Detection in SDN Networks" — an exciting intersection of Software-Defined Networking and Artificial Intelligence.

guest@portfolio: ~

whoami

nguyen_van_tien_phat

uptime

21 years up, studying cybersecurity

cat /var/log/interests.log

[INFO] SIEM Architecture & Rules

[INFO] Incident Response Automation

[INFO] ML applied in SDN Security

EXPERTISE

Technical Skills

SIEM & Log Analysis

Deploy, configure, and monitor security events on Wazuh and KUMA SIEM platforms.

SOAR Automation

Build automated Incident Response workflows using n8n and REST API integrations.

AI in Security

Research machine learning applications for SDN log anomaly detection and fault classification.

Network Security

SDN architecture, firewall configuration, network traffic monitoring, and packet analysis.

tech_stack.json

LinuxBashPythonWazuhKUMAn8nMachine LearningWiresharkDocker

PROJECTS

Featured Work

A collection of featured projects built during my studies and practical experience

PROJECT 01 // SYSTEM & SECURITYBuilt / In Progress

SOC Monitoring & Security Automation

Built a practical SOC laboratory environment to monitor network events, centralize logs, detect threats, and automate incident alerts using pfSense, Suricata, Wazuh SIEM, and n8n.

pfSenseSuricataWazuh SIEMn8n SOAR
ARCHITECTURE
INGRESSInternet
FIREWALLpfSense
IDSSuricata
SIEMWazuh
SOARn8n
ACTIONResponse

WHAT I BUILT

  • 01
    VLAN SegmentationSegmented monitored network zones and routed traffic between isolated VLANs.
  • 02
    pfSense Firewall RulesConfigured rules controlling Ingress, Egress, and inter-subnet internal traffic flows.
  • 03
    Suricata IDS AlertsCaptured network packets and generated signature-based threat detection telemetry.
  • 04
    Wazuh Centralized LogsCollected and centralized logs from host agents and network devices for log correlation.
  • 05
    n8n Alert WorkflowAutomated real-time Telegram alert notifications and incident response playbooks.
CYBERSECURITY / SOC INTERNPRIVATE

Kaspersky KUMA SIEM & SOAR Integration

Practical Experience (SOC Intern @ DTG): Configured KUMA Agent to collect Nginx & auditd logs on Linux, practiced Wazuh FIM; translated, customized & fine-tuned Correlation Rules for Web Shell/SQLi detection based on vendor PoC Guides; built automated alert workflows (n8n) & integrated DFIR-IRIS following NIST SP 800-61r2 standards.

Kaspersky KUMAWazuh FIMn8n SOARDFIR-IRISNIST
EIDT
26

Ablation-Aware Operational Anomaly Detection in Controlled SDN Logs Using Temporal Neural Models

Accepted conference paper in AI-driven log intelligence, temporal neural modeling, and operational anomaly detection.
Authors: ThS. Cao Tiến Thành, Phạm Quốc Huy, Nguyễn Văn Tiến Phát, PGS.TS. Trần Mạnh Hà, TS. Trần Thị Minh Khoa

SDN LogsData EngineeringAnomaly Detection
ARCHITECTURE
INFRASTRUCTUREMininet & POX
NETWORK NODEOpen vSwitch
COLLECTIONsdn_collector
PREPROCESSINGLog Normalization
OUTPUTSDN Datasets

WHAT I BUILT (DATA ENGINEERING)

  • 01
    SDN Network SimulationDesigned a Tree Topology (depth=3, fanout=2) on Mininet connected to POX Controller, simulating complex network traffic environments.
  • 02
    Fault Injection ScenariosConstructed automated injection scripts simulating 7 failure scenarios: DDoS, hardware failure, controller disconnect, flow table overflow, link failure...
  • 03
    Log Normalization & CleaningDeveloped scripts for noise filtering, log anti-spamming, and network feature extraction from raw Open vSwitch logs to standardized formats.
  • 04
    Dataset PublicationProduced standardized datasets of ~300,000 samples (Multi-class and Binary CSV/JSON) for deep learning (TCN) model training.

PUBLICATIONS

Research & Publications

Academic research contributions, conference proceedings, and cybersecurity intelligence.

CONFERENCE
EIDT 2026
Accepted PaperPeer-Reviewed Academic Conference

Ablation-Aware Operational Anomaly Detection in Controlled SDN Logs Using Temporal Neural Models

Authors: ThS. Cao Tiến Thành, Phạm Quốc Huy, Nguyễn Văn Tiến Phát, PGS.TS. Trần Mạnh Hà, TS. Trần Thị Minh Khoa

Proposes an end-to-end operational framework for software-defined networking (SDN) log collection, feature extraction, and temporal neural model inference to detect network anomalies and system fault scenarios.

SDN SecurityLog Anomaly DetectionData EngineeringDeep Learning

CONNECT

Get In Touch

I am always open to discussing new career opportunities, security projects, or simply chatting about Cybersecurity. Feel free to reach out!