System for Continuous Collection of Contextual Information for Network Security Management and Incident Handling

Logo poskytovatele
Autoři

HUSÁK Martin LAŠTOVIČKA Martin TOVARŇÁK Daniel

Rok publikování 2021
Druh Článek ve sborníku
Konference ARES 2021: The 16th International Conference on Availability, Reliability and Security
Fakulta / Pracoviště MU

Ústav výpočetní techniky

Citace
www https://dl.acm.org/doi/abs/10.1145/3465481.3470037
Doi http://dx.doi.org/10.1145/3465481.3470037
Klíčová slova Cybersecurity;Network monitoring;Cyber situational awareness;Incident response;Incident handling
Přiložené soubory
Popis In this paper, we describe a system for the continuous collection of data for the needs of network security management. When a cybersecurity incident occurs in the network, the contextual information on the involved assets facilitates estimating the severity and impact of the incident and selecting an appropriate incident response. We propose a system based on the combination of active and passive network measurements and the correlation of the data with third-party systems. The system enumerates devices and services in the network and their vulnerabilities via fingerprinting of operating systems and applications. Further, the system pairs the hosts in the network with contacts on responsible administrators and highlights critical infrastructure and its dependencies. The system concentrates all the information required for common incident handling procedures and aims to speed up incident response, reduce the time spent on the manual investigation, and prevent errors caused by negligence or lack of information.
Související projekty:

Používáte starou verzi internetového prohlížeče. Doporučujeme aktualizovat Váš prohlížeč na nejnovější verzi.

Další info