首页> 外文会议>コンピュータセキュリティシンポジウム >On Automation and Orchestration of an Initial Computer Security Incident Response Using Centralized Incident Tracking System
【24h】

On Automation and Orchestration of an Initial Computer Security Incident Response Using Centralized Incident Tracking System

机译:初步计算机安全事件响应的自动化和编排利用集中事件跟踪系统

获取原文

摘要

A critical computer security incident may cause great damage on an organization such as confidential databreach or malware pandemic. In order to avoid or mitigate such damage, a quick and accurate response against acomputer security incident has been then getting more important. In order to realize these quickness and accuracy,this paper presents the Incident Tracking System (ITS) that orchestrates several information systems and automate aninitial incident response. The ITS automatically locates and isolates a suspicious host, and sends a mail notificationto a person in charge of handling an incident. The ITS can also identify or suggest a user of the suspicious host bynetwork authentication logs or other service logs.
机译:关键的计算机安全事件可能对诸如机密数据等组织造成巨大损害违规或恶意软件大流行。为了避免或减轻这种损坏,对A的快速和准确的响应计算机安全事件已经变得更加重要。为了实现这些速度和准确性,本文介绍了若干信息系统的事件跟踪系统(其)并自动化初始事件响应。它自动定位并隔离可疑主机,并发送邮件通知对负责处理事件的人。它还可以识别或建议可疑主机的用户网络身份验证日志或其他服务日志。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号