Cyber Attacks Protecting National Infrastructure, 1st ed.
2
Incident response process is the most familiar component of any cyber security program
A cyber security program will contain at least the following Incident trigger
Expert gathering
Incident analysis
Response activities
Copyright © 2012, Elsevier Inc.
All rights Reserved
C h a p te
r 1 1
R e s p o n s e
Introduction
3
Copyright © 2012, Elsevier Inc.
All rights Reserved
C h a p te
r 1 1
R e s p o n s e
Fig. 11.1 General incident response process schema
4
There are two fundamental types of triggers Tangible, visible effects of an attack
Early warning and indications information
Thus, two approaches to incident response processes Front-loaded prevention
Back-loaded recovery
The two approaches should be combined for comprehensive response picture
Protecting national assets is worth suffering a high number of false positives
Copyright © 2012, Elsevier Inc.
All rights Reserved
C h a p te
r 1 1
R e s p o n s e
Pre- Versus Post-Attack Response
5
Copyright © 2012, Elsevier Inc.
All rights Reserved
C h a p te
r 1 1
R e s p o n s e
Fig. 11.2 Comparison of front-loaded and back-loaded response processes
6
Front-loaded prevention critical to national infrastructure protection
Taxonomy of early warning process triggers Vulnerability information
Changes in profiled behavioral metrics
Match on attack metric pattern
Component anomalies
External attack information
Front-loaded prevention have a high sensitivity to triggers
Copyright © 2012, Elsevier Inc.
All rights Reserved
C h a p te
r 1 1
R e s p o n s e
Indications and Warning








Recent Comments