【24h】

Palantir

机译:帕兰蒂尔

获取原文

摘要

Organizations owning cyber-infrastructure assets face large scale distributed attacks on a regular basis. In the face of increasing complexity and frequency of such attacks, we argue that it is insufficient to rely on organizational incident response teams or even trusted coordinating response teams. Instead, there is need to develop a framework that enables responders to establish trust and achieve an effective collaborative response and investigation process across multiple organizations and legal entities to track the adversary, eliminate the threat and pursue prosecution of the perpetrators. In this work we develop such a framework for effective collaboration. Our approach is motivated by our experiences in dealing with a large-scale distributed attack that took place in 2004 known as Incident 216. Based on our approach we present the Palantir system that comprises conceptual and technological capabilities to adequately respond to such attacks. To the best of our knowledge this is the first work proposing a system model and implementation for a collaborative multi-site incident response and investigation effort.
机译:拥有网络基础设施资产的组织会定期面临大规模的分布式攻击。面对此类攻击的复杂性和频率越来越高,我们认为仅依靠组织事件响应团队甚至信任的协调响应团队是不够的。相反,需要开发一个框架,使响应者能够在多个组织和法人实体之间建立信任并实现有效的协作响应和调查过程,以跟踪对手,消除威胁并起诉肇事者。在这项工作中,我们为有效的协作开发了这样一个框架。我们的方法是由我们在处理2004年发生的称为事件216的大规模分布式攻击方面的经验所激发的。基于我们的方法,我们介绍了Palantir系统,该系统具有足以对此类攻击做出响应的概念和技术能力。据我们所知,这是为协同多站点事件响应和调查工作提出系统模型和实现的第一项工作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号