Cybersecurity Evaluation with PowerShell

Cybersecurity Evaluation with PowerShell
复制标题

使用 PowerShell 进行网络安全评估

DOI:
10.1109/isdfs49300.2020.9116258
复制
发表时间:
2020
期刊:
2020 8th International Symposium on Digital Forensics and Security (ISDFS)
影响因子:
--
通讯作者:
C. Varol
C. Varol
中科院分区:
--
文献类型:
--
作者:
Steven Zavala;N. Shashidhar;C. Varol

文献摘要

被引文献

相似文献

组织的网络安全态势正成为最受关注的关注领域之一。随着越来越多的公司成为漏洞和漏洞的受害者,我们发现更多企业成为受害者的案例,我们发现它们归因于不正确的安全实践定义、未能制定解决漏洞的策略,甚至没有遵守其现有策略。毫不奇怪,数据泄露和最终泄露的影响继续影响从大公司到个人的各个层面。因此,必须为个人提供一种比较方法,以检索其网络安全态势的共同基线与可接受的既定标准。现有的审计措施相当繁琐,并且存在出错的空间。使用 PowerShell 提供了一种自动将信息解析到公司现有策略并暴露任何网络安全漏洞的方法。此处使用的 PowerShell 审核流程将为组织提供自我检查的方法,而无需使用第三方工具的软件。由于 PowerShell 可以灵活地从操作系统环境解析信息。 CSET 由国土安全部 (DHS) 和国家网络安全和通信集成中心 (NCCIC) 共同设计,提供了一种非常全面的方法来评估组织的网络安全态势。他们的工具通过各种方式实现这一点,这可能需要审计参与者通过手动提取值来生成必要的信息,例如是否启用软件防火墙规则。这里完成的研究将集中于执行查询命令和自动化大部分收集数据的手动过程,以消除人为因素。我们通过结合 PowerShell 功能来实现这一目标,这可以为审核员提供另一种方法,根据他们关注的领域的相关内容定制他们的审核体验。
An organization’s cybersecurity posture is trending as one of the most highly regarded areas of focus. As more companies fall victim to breaches and exploits, we find more cases where corporations are falling victim to this and we find they attribute to improper defined security practices, failure to have a policy to address breaches or even comply with their existing strategies. It comes as no surprise that the effects of breaches and the eventual compromise of data continues to impact every level from large corporations down to the individuals. Therefore, it is imperative to provide individuals with a comparative method to retrieve a common baseline of their cybersecurity posture versus an acceptable established standard. Existing audit measures are quite cumbersome and introduce room for errors. Using PowerShell provides a method to automate parsing information into a company’s existing policy and expose any cybersecurity vulnerabilities. PowerShell audit process used here will provide an organization with the method to self-check without having to incorporate the use of software from third-party tools. Because of PowerShell’s flexibility of parsing information using from the OS environment. CSET as designed by the collaborative efforts from Department Homeland Security (DHS) and the National Cybersecurity and Communications Integration Center (NCCIC) provides a very thorough method of producing an evaluation of the organization’s Cybersecurity posture. Their tool achieves this through various means which may require an auditor participant to produce the necessary information by manually extracting values, such as whether software firewall rules are enabled or not. The research done here will focus on executing query commands and automating much of the manual process of gathering data to eliminate the human component. We achieve this by combining PowerShell functions which can give the auditor another method to tailor their audit experience to what is relevant in their area of concern.