Dynamic Cyber-Incident Response

被引:0
|
作者
Mepham, Kevin [1 ]
Louvieris, Panos [1 ]
Ghinea, Gheorghita [1 ]
Clewley, Natalie [1 ]
机构
[1] Brunel Univ, Def & Cyber Secur Res Grp, London, England
关键词
Cyber Incident Response Active Passive Risk;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Traditional cyber-incident response models have not changed significantly since the early days of the Computer Incident Response with even the most recent incident response life cycle model advocated by the US National Institute of Standards and Technology (Cichonski, Millar, Grance, & Scarfone, 2012) bearing a striking resemblance to the models proposed by early leaders in the field e.g. Carnegie-Mellon University (West-Brown, et al., 2003) and the SANS Institute (Northcutt, 2003). Whilst serving the purpose of producing coherent and effective response plans, these models appear to be created from the perspectives of Computer Security professionals with no referenced academic grounding. They attempt to defend against, halt and recover from a cyber-attack as quickly as possible. However, other actors inside an organisation may have priorities which conflict with these traditional approaches and may ultimately better serve the longer-term goals and objectives of an organisation. Shortcomings of traditional approaches in cyber-incident response and ideas for a more dynamic approach are discussed including balancing the requirements to defend against an incident with those of gaining more intelligence about an attack or those behind it. To support this, factors are described which have been identified as being relevant to cyber-incident response. These factors were derived from a literature review comprising material from academic and best-practice sources in the computer security, intelligence and command and control fields. Results of a PhD research survey conducted across military, government and commercial organisations are discussed; this assesses the importance of the aforementioned factors. The surveyed participants include (but were not limited to) respondents from areas such as Intelligence and Operations, as well as the more conventional computer security areas. Situational awareness and decision-making aspects of incident response are examined as well as other factors such as intelligence value, intelligence gathering, asset value, collaboration and Intelligence Cycle factors.
引用
收藏
页码:121 / 136
页数:16
相关论文
共 50 条
  • [31] How integration of cyber security management and incident response enables organizational learning
    Ahmad, Atif
    Desouza, Kevin C.
    Maynard, Sean B.
    Naseer, Humza
    Baskerville, Richard L.
    JOURNAL OF THE ASSOCIATION FOR INFORMATION SCIENCE AND TECHNOLOGY, 2020, 71 (08) : 939 - 953
  • [32] Efficient Incident Response System on Shared Cyber Threat Information Using SDN and STIX
    Okada, Satoshi
    Fujiwara, Yoshiki
    Fujimoto, Mariko
    Matsuda, Wataru
    Mitsunaga, Takuho
    2021 IEEE INTERNATIONAL CONFERENCE ON COMPUTING (ICOCO), 2021, : 109 - 114
  • [33] Mitigating Global Cyber Risk Through Bridging the National Incident Response Capacity Gap
    Dubois, Elisabeth
    Tatar, Unal
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2022), 2022, : 527 - 531
  • [34] Saudi Arabia's Response to Cyber Conflict: A case study of the Shamoon malware incident
    Dehlawi, Zakariya
    Abokhodair, Norah
    2013 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS: BIG DATA, EMERGENT THREATS, AND DECISION-MAKING IN SECURITY INFORMATICS, 2013, : 73 - 75
  • [35] Development of a Cyber Incident Information Crawler
    Ikegami, Kazuki
    Yamada, Michihiro
    Kikuchi, Hiroaki
    Inui, Koji
    INNOVATIVE MOBILE AND INTERNET SERVICES IN UBIQUITOUS COMPUTING, IMIS-2019, 2020, 994 : 447 - 455
  • [36] Risks of Sharing Cyber Incident Information
    Albakri, Adham
    Boiten, Eerke
    De Lemos, Rogerio
    13TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2018), 2019,
  • [37] Cyber Incident Classification: Issues and Challenges
    Ibrishimova, Marina Danchovsky
    ADVANCES ON P2P, PARALLEL, GRID, CLOUD AND INTERNET COMPUTING, 3PGCIC-2018, 2019, 24 : 469 - 477
  • [38] Dynamic risk management response system to handle cyber threats
    Gonzalez-Granadillo, G.
    Dubus, S.
    Motzek, A.
    Garcia-Alfaro, J.
    Alvarez, E.
    Merialdo, M.
    Papillon, S.
    Debar, H.
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 83 : 535 - 552
  • [39] Data Analytics for Cyber Risk Analysis Utilizing Cyber Incident Datasets
    Portalatin, Melissa
    Keskin, Omer
    Malneedi, Sneha
    Raza, Owais
    Tatar, Unal
    2021 SYSTEMS AND INFORMATION ENGINEERING DESIGN SYMPOSIUM (IEEE SIEDS 2021), 2021, : 164 - 169
  • [40] Dynamic response of a group of flexible foundations to incident seismic waves
    Tham, LG
    Qian, J
    Cheung, YK
    SOIL DYNAMICS AND EARTHQUAKE ENGINEERING, 1998, 17 (02) : 127 - 137