首页> 外文会议>コンピュータセキュリティシンポジウム2018論文集 >On Automation and Orchestration of an Initial Computer Security Incident Response Using Centralized Incident Tracking System
【24h】

On Automation and Orchestration of an Initial Computer Security Incident Response Using Centralized Incident Tracking System

机译:基于集中事件跟踪系统的初始计算机安全事件响应的自动化和编排

获取原文
获取原文并翻译 | 示例

摘要

A critical computer security incident may cause great damage on an organization such as confidential databreach or malware pandemic. In order to avoid or mitigate such damage, a quick and accurate response against acomputer security incident has been then getting more important. In order to realize these quickness and accuracy,this paper presents the Incident Tracking System (ITS) that orchestrates several information systems and automate aninitial incident response. The ITS automatically locates and isolates a suspicious host, and sends a mail notificationto a person in charge of handling an incident. The ITS can also identify or suggest a user of the suspicious host bynetwork authentication logs or other service logs.
机译:严重的计算机安全事件可能会对组织造成严重损害,例如机密数据\ r \ nbreach或恶意软件大流行。为了避免或减轻这种损害,针对计算机安全事件的快速而准确的响应已变得越来越重要。为了实现这些快速性和准确性,本文提出了事件跟踪系统(ITS),该系统可以协调多个信息系统并自动执行初始事件响应。 ITS会自动定位并隔离可疑主机,并向负责处理事件的人员发送邮件通知。 ITS还可以通过网络身份验证日志或其他服务日志来识别或建议可疑主机的用户。

著录项

  • 来源
  • 会议地点
  • 作者单位

    Tottori University, Koyama-minami, Tottori Japan, 680–8550 Japan ohmori@tottori-u.ac.jp;

    Tottori University, Koyama-minami, Tottori Japan, 680–8550 Japan higashino@tottori-u.ac.jp;

    Tottori University, Koyama-minami, Tottori Japan, 680–8550 Japan t.kawato@tottori-u.ac.jp;

    Tottori University, Koyama-minami, Tottori Japan, 680–8550 Japan miyata@tottori-u.ac.jp;

    Tottori University, Koyama-minami, Tottori Japan, 680–8550 Japan takahashi@eecs.tottori-u.ac.jp;

    Tottori University, Koyama-minami, Tottori Japan, 680–8550 Japan kawamura@tottori-u.ac.jp;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

  • 入库时间 2022-08-26 14:32:26

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号