错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Practical Application of the Information Security Incident Handling Regulation

  • Anastasia Iakovleva,
  • Marina Zhukova

摘要

Incident specialists often do not have universal recommendations or algorithms for their investigation and are guided by assumptions based on previous experience. The previous study of the authors presented in the article “Information Security Incident Handling Regulation” contains a theoretical description of a unified approach to the investigation of information security incidents. This article provides a practical approbation of the proposed approach on the example of a particular incident. The possibility of using the developed approach is described by demonstrating its applicability on the example of the task of the information security case championship formed by the RISC community team. It is shown that the proposed algorithm can be used to work with an incident from receiving an incident message to finding an entry point, building a timeline and describing the attacker’s profile. The profile of the attacker is described with partial reliance on the research described in the article “On Attacker Models and Profiles for Cyber-Physical Systems”.