Operations-informed incident response playbooks

Operations-informed incident response playbooks
复制标题

以运营为依据的事件响应手册

DOI:
10.1016/j.cose.2023.103454
复制
发表时间:
2023
影响因子:
5.6
通讯作者:
Shaked A
Shaked A
中科院分区:
计算机科学3区
文献类型:
--
作者:
Shaked A

文献摘要

参考文献

被引文献

相似文献

网络安全事件响应手册对于在组织内建立有效的事件响应能力至关重要。我们在网络安全手册设计的当前研究和实践中发现了一个重大的概念缺口:缺乏沟通事件的运营影响和事件响应对组织的能力。在本文中,我们提出了一种通过在事件响应剧本中引入操作上下文来解决这一差距的机制。这种概念性的贡献要求从仅由流程模型组成的剧本转变为由与操作模型紧密相连的流程模型组成的剧本。我们描述了一种新的方法,将操作模型嵌入到事件响应剧本中,并将其与剧本的事件响应活动联系起来。这使得能够准确和系统地反映事件应对活动对业务的相互依存和相互影响,反之亦然。该方法包括使用一种新的指标来评估与关键阈值相协调的操作变化,以支持网络安全事件应对期间的决策。我们使用一个新开发的开源工具,在勒索软件攻击事件响应的上下文中演示了所提出的方法在剧本设计中的应用。
Cyber security incident response playbooks are critical for establishing an effective incident response capability within organizations. We identify a significant conceptual gap in the current research and practice of cyber security playbook design: the lack of ability to communicate the operational impact of an incident and of incident response on an organization. In this paper, we present a mechanism to address the gap by introducing the operational context into an incident response playbook. This conceptual contribution calls for a shift from playbooks that consist only of process models to playbooks that consist of process models closely linked with a model of operations. We describe a novel approach to embed a model of operations into the incident response playbook and link it with the playbook's incident response activities. This allows to reflect, in an accurate and systematic way, the interdependencies and mutual influences of incident response activities on operations and vice versa. The approach includes the use of a new metric for evaluating the change in operations in coordination with critical thresholds, supporting decision-making during cyber security incident response. We demonstrate the application of the proposed approach to playbook design in the context of a ransomware attack incident response, using a newly developed open-source tool.
结构化网络弹性分析方法 (SCRAM)
DOI: --
发表时间: 2016
期刊:
影响因子: --
作者:
D. Bodeau
通讯作者: D. Bodeau
DOI: 10.3390/app12104880
发表时间: 2022-05
期刊: Applied Sciences
影响因子: --
作者:
Yulia Cherdantseva;P. Burnap;S. Nadjm-Tehrani;Kevin Jones
通讯作者: Yulia Cherdantseva;P. Burnap;S. Nadjm-Tehrani;Kevin Jones
LockerGoga勒索软件分析
DOI: --
发表时间: 2019
期刊: East-West Design & Test Symposium
影响因子: --
作者:
A. Adamov;Anders Carlsson;T. Surmacz
通讯作者: T. Surmacz
Jack pandemus – 大流行期间的网络事件和紧急响应
DOI: --
发表时间: 2021
影响因子: 1.8
作者:
Erik B. Korn;Douglas M. Fletcher;Erica M. Mitchell;Aryn A. Pyke;Steven M. Whitham
通讯作者: Steven M. Whitham
计算机安全事件响应团队的有效性:需求评估
DOI: --
发表时间: 2017
影响因子: 3.8
作者:
Rick van der Kleij;G. Kleinhuis;Heather Young
通讯作者: Heather Young