Security Planning Susan Lincke Planning for
Description: Security Planning Susan Lincke Planning for Incident Response Objectives Students should be able to: Define and describe an incident response plan and business continuity plan Describe incident management team, incident response team,
Related Topics
Download Presentation
"Security Planning Susan Lincke Planning for" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
slide1. Security Planning
Susan Lincke Planning for Incident Response<br>
slide2. Objectives Students should be able to:
Define and describe an incident response plan and business continuity plan
Describe incident management team, incident response team, proactive detection, triage
Define and describe computer forensics: authenticity, continuity, forensic copy, chain of custody, root cause,
Define external test, internal test, blind test, double blind test, targeted test.
Develop a high-level incident response plan.
Describe steps to obtain computer forensic information during an investigation.
Describe general capabilities of a forensic tool.
Describe steps to copy a disk.
Define discovery, e-discovery, deposition, declaration, affidavit, fact witness, expert consultant, expert witness.<br>
slide3. How to React to…? Viruses Denial of Service Hacker Intrusion Accidents System Failure Theft of Proprietary Information Social Engineering Lost Backup Tape Stolen Laptop Ransom!<br>
slide4. Criminal:
Stolen data: financial, Point of sale, medical
Regulation & liability
Espionage:
Stolen engineering or marketing plans, trade secrets
Stolen government data
Warfare:
Denial of service
Destruction Business Impact<br>
slide5. Incident Response vs. Business Continuity Incident Response Planning (IRP)
Security-related threats to systems, networks & data
Data confidentiality
Non-repudiable transactions Business Continuity Planning
Disaster Recovery Plan
Continuity of Business Operations
BCP and can be the first step for Incident Response NIST SP 800-61 defines an incident as “a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices.”<br>
slide6. Incident Response Costs: IBM 2022 Cost of a Data Breach Report<br>
slide7. IBM’s statistics on breaches indicates the global average cost per breach is
$4.87 million when the lifecycle exceeds 200 days; and
$3.61 million otherwise [IBM21].
To reduce the total data breach cost if an organization has:
an incident response team and performs testing (reduces by: $2.46 million),
a strong emphasis on regulatory compliance ($2.3 million),
a mature implementation of zero trust ($1.76 million),
a high standard of encryption ($1.25 million), and
security automation ($3.81 million) reduces time to find and contain an incident.
use of artificial intelligence, and security analytics.
Factors raising the cost of a breach > $5 million average includes:
a high level of cloud migration,
a large majority (81-100%) of employees working remotely; also caused delay in discovering and containing a breach. The IBM’s Cost of Data Breach 2021<br>
slide8. Review: Business Continuity Recovery Terms Interruption Window: Time duration organization can wait between point of failure and Alternate Mode startup.
Service Delivery Objective (SDO): Level of service in Alternate Mode
Maximum Tolerable Outage: Max time allowed for downtime and time in Alternate Mode Regular Service Alternate Mode Regular
Service (Acceptable)
Interruption
Window Maximum Tolerable Outage Service
Delivery
Objective Interruption Time… Disaster
Recovery
Plan Implemented Restoration
Plan Implemented<br>
slide9. Attack vectors = source methods = root cause: Can include
Email link and/or attachment (word doc)
Direct install (bad judgment)
Web drive-by or download
Web app or other vulnerability
Removable media, flash drive
Improper use, loss or theft,
Physical access or abuse
Incident: “A security event that compromises the integrity, confidentiality or availability of an information asset.”
Breach: “An incident that results in the confirmed disclosure—not just potential exposure—of data to an unauthorized party.” Vocabulary<br>
slide10. Vocabulary IMT: Incident Management Team
IS Mgr leads, includes steering committee, IRT members
Develop strategies & design plan for Incident Response,
integrating business, IT, BCP, and risk management
Obtain funding, Review postmortems
Meet performance & reporting requirements IRT: Incident Response Team
Handles the specific incident. Has specific knowledge relating to:
Security, network protocols, operating systems, physical
security issues, malicious code, etc.
Permanent (Full Time) Members: IT security specialists,
incident handlers, investigator
Virtual (Part Time) Members: Business (middle mgmt), legal,
public relations, human resources, physical security, risk, IT<br>
slide11. Stages in Incident Response Preparation Identification Containment
& Escalation Analysis &
Eradication Recovery Lessons
Learned Plan PRIOR to Incident Determine what is/has happened Limit incident Determine and remove
root cause Return operations
to normal Process improvement:
Plan for the future Notification Ex-Post
Response Notify any data
breach victims [If data breach] Establish call center,
reparation activities<br>
slide12. It can become chaotic: too many events too fast
Management may attempt to micromanage and need to be trained
Staff need to record all they do
Evidence cannot be altered to be admissible in court of law
Public Relations person interfaces with public Challenges during an Incident<br>
slide13. Why is incident response important? Average Cost of Data Breach:
Global $3.86M; U.S. $7.91M for 31,465 records
Mega Breach: 1 M records: $40 million 50 M records: $350 million
Mean Time to Identify (MTTI): Days to find, confirm breach
Mean Time to Contain (MTTC): Days to resolve breach and restore service 2018 Cost of a Data Breach Study: Global Report (IBM/Ponemon)<br>
slide14. Summary of Stages Step 1: Preparation: Plan before the attack
Step 2: Identification: recognition of attack
prioritize the symptoms to go after first.
Step 3: Containment: the attacker can not proceed further
you have halted but not cleared the attack.
Step 4: Analysis and Eradication: The network is cleared of the attack
you have found the root cause: what enabled the attacker entry into network
Step 5: Recovery: retest system and restore normal operations
Step 6: Lessons Learned: review what happened;
how can you improve next time?<br>
slide15. Stage 1: Preparation What shall we do if different types of incidents occur? (BIA helps)
When is the incident management team called?
How can governmental agencies or law enforcement help?
When do we involve law enforcement?
What equipment do we need to handle an incident?
What shall we do to prevent or discourage incidents from occurring? (e.g. banners, policies)
Where on-site & off-site shall we keep the IRP?<br>
slide16. (1) Detection Technologies Organization must have sufficient detection & monitoring capabilities to detect incidents in a timely manner
Proactive Detection includes:
Network Intrusion Detection/Prevention System (NIDS/NIPS)
Host Intrusion Detection/Prevention System (HIDS/HIPS)
Antivirus, Endpoint Security Suite
Security Information and Event Management (Logs)
Vulnerability/audit testing
System Baselines, Sniffer
Centralized Incident Management System
Input: Server, system logs
Coordinates & co-relates logs from many systems
Tracks status of incidents to closure
Reactive Detection: Reports of unusual or suspicious activity<br>
slide17. Logs to Collect & Monitor<br>
slide18. Incidents may include… IT Detects a device (firewall, router or server) issues serious alarm(s)
change in configuration
an IDS/IPS recognizes an irregular pattern:
unusually high traffic,
inappropriate file transfer
changes in protocol use
unexplained system crashes or
unexplained connection terminations Employees Reports Malware
Violations of policy
Data breach:
stolen laptop, memory
employee mistake
Social engineering/fraud:
caller, e-mail, visitors
Unusual event:
inappropriate login
unusual system aborts
server slow
deleted files
defaced website<br>
slide19. (1) Management Participation Management makes final decision
As always, senior management has to be convinced that this is worth the money.<br>
slide20. Planning for Incident Detection & Handling Security Workbook<br>
slide21. Planning for Incident Detection & Handling Security Workbook<br>
slide22. Planning for Incident Detection & Handling Security Workbook<br>
slide23. An Incident is Now Occurring The planning is done and…<br>
slide24. Stage 2: Identification Triage: Categorize, prioritize and assign events and incidents
What type of incident just occurred?
What is the severity of the incident?
Severity may increase if recovery is delayed
Who should be called?
Establish chain of custody for evidence<br>
slide25. (2) Triage Snapshot of the known status of all reported incident activity
Sort, Categorize, Correlate, Prioritize & Assign
Categorize: DoS, Malicious code, Unauthorized access, Inappropriate usage, Multiple components
Prioritize: Limited resources requires prioritizing response to minimize impact
Assign: Who is free/on duty, competent in this area?<br>
slide26. (2) Chain of Custody Evidence must follow Chain of Custody law to be admissible/acceptable in court
Include: specially trained staff, 3rd party specialist, law enforcement, security response team
System administrator can:
Retrieve info to confirm an incident
Identify scope and size of affected environment (system/network)
Determine degree of loss/alteration/damage
Identify possible path of attack<br>
slide27. Stage 3: Containment Activate Incident Response Team to contain threat
IT/security, public relations, mgmt, business
Isolate the problem
Disable server or network zone communications
Disable user access
Change firewall configurations to halt connection
Obtain & preserve evidence<br>
slide28. (3) Containment - Response Technical
Collect data
Analyze log files
Obtain further technical assistance
Deploy patches & workarounds Managerial
Business impacts result in mgmt intervention, notification, escalation, approval
Legal
Issues related to: investigation, prosecution, liability, privacy, laws & regulation, nondisclosure<br>
slide29. Image affected devices: MasterCard recommends that their PCI Forensic Investigators do this step first.
Halt connections: This is a temporary fix, since most attackers can easily change their IP address. The Internet Service Provider may be able to help in filtering an attack pattern.
Disable server communications or network zone: Potentially break access to a zone, by disconnecting network connections or powering down routers. Alternatively, safely power down a server or virtual machine.
Disabling user access: Revoke privileges to internal users who violate policy; change passwords; enable 2-factor authentication; prohibit an executable.
Alert related entities: Notify organizations whose data or systems may be affected (financial, payment card). Internet service provider can help to contain the attack.
Continue to monitor: Closely monitor any continued progress in the attack
Patch vulnerable software: After obtaining images, patch vulnerable software, when vulnerabilities detected. Potential Containment Actions<br>
slide30. Stage 4: Analysis & Eradication Determine how the attack occurred: who, when, how, and why?
What is impact & threat? What damage occurred?
Remove root cause: initial vulnerability(s)
Talk to ISP to get more information
Rebuild System
Improve defenses with enhanced protection techniques
Perform vulnerability analysis
Discuss recovery with management, who must make decisions on handling affecting other areas of business<br>
slide31. (4) Analysis It is important to discover…
What happened?
Who was involved?
What was the reason for the attack?
Where did attack originate from?
When did the initial attack occur?
How did it happen?
What vulnerability enabled the attack?<br>
slide32. (4) Remove root cause If Admin or Root compromised, rebuild system
Implement recent patches & recent antivirus
Change all passwords
Fortify defenses with enhanced security controls
Retest with vulnerability analysis tools<br>
slide33. Stage 5: Recovery Restore operations to normal
Ensure that restore is fully tested and operational<br>
slide34. WorkbookIncident Handling Response Procedure<br>
slide35. Workbook<br>
slide36. Stage 6: Lessons Learned Follow-up includes:
Writing an Incident Report
What went right or wrong in the incident response?
How can process improvement occur?
How much did the incident cost (in loss & handling & time)
Present report to relevant stakeholders<br>
slide37. Planning Processes Risk & Business Impact Assessment
Response & Recovery Strategy Definition
Document IRP and DRP
Train for response & recovery
Update IRP & DRP
Test response & recovery
Audit IRP & DRP<br>
slide38. Training Introductory Training: First day as IMT
Mentoring: Buddy system with longer-term member
Formal Training
On-the-job-training
Training due to changes in IRP/DRP<br>
slide39. Types of Penetration Tests External Testing: Tests from outside network perimeter
Internal Testing: Tests from within network
Blind Testing: Penetration tester knows nothing in advance and must do web research on company
Double Blind Testing: System and security administrators also are not aware of test
Targeted Testing: Have internal information about a target. May have access to an account.
Written permission must always be obtained first<br>
slide40. Incident Management Metrics # of Reported Incidents
# of Detected Incidents
Average time to respond to incident
Average time to resolve an incident
Total number of incidents successfully resolved
Proactive & Preventative measures taken
Total damage from reported or detected incidents
Total damage if incidents had not been contained in a timely manner<br>
slide41. Challenges Management buy-in: Management does not allocate time/staff to develop IRP
Top reason for failure
Organization goals/structure mismatch: e.g., National scope for international organization
IMT Member Turnover
Communication problems: Too much or too little
Plan is too complex and wide<br>
slide42. Question The MAIN challenge in putting together an IRP is likely to be:
Getting management and department support
Understanding the requirements for chain of custody
Keeping the IRP up-to-date
Ensuring the IRP is correct<br>
slide43. Question The PRIMARY reason for Triage is:
To coordinate limited resources
To disinfect a compromised system
To determine the reasons for the incident
To detect an incident<br>
slide44. Question When a system has been compromised at the administrator level, the MOST IMPORTANT action is:
Ensure patches and anti-virus are up-to-date
Change admin password
Request law enforcement assistance to investigate incident
Rebuild system<br>
slide45. Question The BEST method of detecting an incident is:
Investigating reports of discrepancies
NIDS/HIDS technology
Regular vulnerability scans
Job rotation<br>
slide46. Question The person or group who develops strategies for incident response includes:
CISO
CRO
IRT
IMT<br>
slide47. Question The FIRST thing that should be done when you discover an intruder has hacked into your computer system is to:
Disconnect the computer facilities from the computer network to hopefully disconnect the attacker
Power down the server to prevent further loss of confidentiality and data integrity
Call the police
Follow the directions of the Incident Response Plan<br>
slide48. Planning is necessary
Without preparation, no incident will be detected
Incident handlers should not decide what needs to be done.
Stages:
Identification: Determine what has happened
Containment & Escalation: Limit incident
Analysis & Eradication: Analyze root cause, repair
Restore: Test and return to normal
Process Improvement
(Possibly) Breach Notification
If case is to be prosecuted:
Evidence must be carefully handled: Authenticity & Continuity
Expert testimony must be qualified, accurate, bullet-proof Summary<br>
slide49. Health First Case Study Designing Incident Response Jamie Ramon MD
Doctor Chris Ramon RD
Dietician Terry
Licensed
Practicing Nurse Pat
Software Consultant<br>
slide50. Workbook: Table of Incident Types<br>
slide51. Planning for Incident Detection & Handling Security Workbook<br>
slide52. Stages in Incident Response Preparation Identification Containment
& Escalation Analysis &
Eradication Recovery Lessons
Learned Plan PRIOR to Incident Determine what is/has happened Limit incident Determine and remove
root cause Return operations
to normal Process improvement:
Plan for the future Notification Ex-Post
Response Notify any data
breach victims [If data breach] Establish call center,
reparation activities<br>
slide53. Step 1: Detection Technologies Organization must have sufficient detection & monitoring capabilities to detect incidents in a timely manner
Proactive Detection includes:
Network Intrusion Detection/Prevention System (NIDS/NIPS)
Host Intrusion Detection/Prevention System (HIDS/HIPS)
Antivirus, Endpoint Security Suite
Security Information and Event Management (Logs)
Vulnerability/audit testing
System Baselines, Sniffer
Centralized Incident Management System
Input: Server, system logs
Coordinates & co-relates logs from many systems
Tracks status of incidents to closure
Reactive Detection: Reports of unusual or suspicious activity<br>
slide54. Stage 2: Identification Triage: Categorize, prioritize and assign events and incidents
What type of incident just occurred?
What is the severity of the incident?
Severity may increase if recovery is delayed
Who should be called?
Establish chain of custody for evidence<br>
slide55. Stage 3: Containment Activate Incident Response Team to contain threat
IT/security, public relations, mgmt, business
Isolate the problem
Disable server or network zone comm.
Disable user access
Change firewall configurations to halt connection
Obtain & preserve evidence<br>
slide56. Stage 4: Analysis & Eradication Determine how the attack occurred: who, when, how, and why?
What is impact & threat? What damage occurred?
Remove root cause: initial vulnerability(s)
Talk to ISP to get more information
Rebuild System
Improve defenses with enhanced protection techniques
Perform vulnerability analysis
Discuss recovery with management, who must make decisions on handling affecting other areas of business<br>
slide57. Workbook<br>
Susan Lincke Planning for Incident Response<br>
slide2. Objectives Students should be able to:
Define and describe an incident response plan and business continuity plan
Describe incident management team, incident response team, proactive detection, triage
Define and describe computer forensics: authenticity, continuity, forensic copy, chain of custody, root cause,
Define external test, internal test, blind test, double blind test, targeted test.
Develop a high-level incident response plan.
Describe steps to obtain computer forensic information during an investigation.
Describe general capabilities of a forensic tool.
Describe steps to copy a disk.
Define discovery, e-discovery, deposition, declaration, affidavit, fact witness, expert consultant, expert witness.<br>
slide3. How to React to…? Viruses Denial of Service Hacker Intrusion Accidents System Failure Theft of Proprietary Information Social Engineering Lost Backup Tape Stolen Laptop Ransom!<br>
slide4. Criminal:
Stolen data: financial, Point of sale, medical
Regulation & liability
Espionage:
Stolen engineering or marketing plans, trade secrets
Stolen government data
Warfare:
Denial of service
Destruction Business Impact<br>
slide5. Incident Response vs. Business Continuity Incident Response Planning (IRP)
Security-related threats to systems, networks & data
Data confidentiality
Non-repudiable transactions Business Continuity Planning
Disaster Recovery Plan
Continuity of Business Operations
BCP and can be the first step for Incident Response NIST SP 800-61 defines an incident as “a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices.”<br>
slide6. Incident Response Costs: IBM 2022 Cost of a Data Breach Report<br>
slide7. IBM’s statistics on breaches indicates the global average cost per breach is
$4.87 million when the lifecycle exceeds 200 days; and
$3.61 million otherwise [IBM21].
To reduce the total data breach cost if an organization has:
an incident response team and performs testing (reduces by: $2.46 million),
a strong emphasis on regulatory compliance ($2.3 million),
a mature implementation of zero trust ($1.76 million),
a high standard of encryption ($1.25 million), and
security automation ($3.81 million) reduces time to find and contain an incident.
use of artificial intelligence, and security analytics.
Factors raising the cost of a breach > $5 million average includes:
a high level of cloud migration,
a large majority (81-100%) of employees working remotely; also caused delay in discovering and containing a breach. The IBM’s Cost of Data Breach 2021<br>
slide8. Review: Business Continuity Recovery Terms Interruption Window: Time duration organization can wait between point of failure and Alternate Mode startup.
Service Delivery Objective (SDO): Level of service in Alternate Mode
Maximum Tolerable Outage: Max time allowed for downtime and time in Alternate Mode Regular Service Alternate Mode Regular
Service (Acceptable)
Interruption
Window Maximum Tolerable Outage Service
Delivery
Objective Interruption Time… Disaster
Recovery
Plan Implemented Restoration
Plan Implemented<br>
slide9. Attack vectors = source methods = root cause: Can include
Email link and/or attachment (word doc)
Direct install (bad judgment)
Web drive-by or download
Web app or other vulnerability
Removable media, flash drive
Improper use, loss or theft,
Physical access or abuse
Incident: “A security event that compromises the integrity, confidentiality or availability of an information asset.”
Breach: “An incident that results in the confirmed disclosure—not just potential exposure—of data to an unauthorized party.” Vocabulary<br>
slide10. Vocabulary IMT: Incident Management Team
IS Mgr leads, includes steering committee, IRT members
Develop strategies & design plan for Incident Response,
integrating business, IT, BCP, and risk management
Obtain funding, Review postmortems
Meet performance & reporting requirements IRT: Incident Response Team
Handles the specific incident. Has specific knowledge relating to:
Security, network protocols, operating systems, physical
security issues, malicious code, etc.
Permanent (Full Time) Members: IT security specialists,
incident handlers, investigator
Virtual (Part Time) Members: Business (middle mgmt), legal,
public relations, human resources, physical security, risk, IT<br>
slide11. Stages in Incident Response Preparation Identification Containment
& Escalation Analysis &
Eradication Recovery Lessons
Learned Plan PRIOR to Incident Determine what is/has happened Limit incident Determine and remove
root cause Return operations
to normal Process improvement:
Plan for the future Notification Ex-Post
Response Notify any data
breach victims [If data breach] Establish call center,
reparation activities<br>
slide12. It can become chaotic: too many events too fast
Management may attempt to micromanage and need to be trained
Staff need to record all they do
Evidence cannot be altered to be admissible in court of law
Public Relations person interfaces with public Challenges during an Incident<br>
slide13. Why is incident response important? Average Cost of Data Breach:
Global $3.86M; U.S. $7.91M for 31,465 records
Mega Breach: 1 M records: $40 million 50 M records: $350 million
Mean Time to Identify (MTTI): Days to find, confirm breach
Mean Time to Contain (MTTC): Days to resolve breach and restore service 2018 Cost of a Data Breach Study: Global Report (IBM/Ponemon)<br>
slide14. Summary of Stages Step 1: Preparation: Plan before the attack
Step 2: Identification: recognition of attack
prioritize the symptoms to go after first.
Step 3: Containment: the attacker can not proceed further
you have halted but not cleared the attack.
Step 4: Analysis and Eradication: The network is cleared of the attack
you have found the root cause: what enabled the attacker entry into network
Step 5: Recovery: retest system and restore normal operations
Step 6: Lessons Learned: review what happened;
how can you improve next time?<br>
slide15. Stage 1: Preparation What shall we do if different types of incidents occur? (BIA helps)
When is the incident management team called?
How can governmental agencies or law enforcement help?
When do we involve law enforcement?
What equipment do we need to handle an incident?
What shall we do to prevent or discourage incidents from occurring? (e.g. banners, policies)
Where on-site & off-site shall we keep the IRP?<br>
slide16. (1) Detection Technologies Organization must have sufficient detection & monitoring capabilities to detect incidents in a timely manner
Proactive Detection includes:
Network Intrusion Detection/Prevention System (NIDS/NIPS)
Host Intrusion Detection/Prevention System (HIDS/HIPS)
Antivirus, Endpoint Security Suite
Security Information and Event Management (Logs)
Vulnerability/audit testing
System Baselines, Sniffer
Centralized Incident Management System
Input: Server, system logs
Coordinates & co-relates logs from many systems
Tracks status of incidents to closure
Reactive Detection: Reports of unusual or suspicious activity<br>
slide17. Logs to Collect & Monitor<br>
slide18. Incidents may include… IT Detects a device (firewall, router or server) issues serious alarm(s)
change in configuration
an IDS/IPS recognizes an irregular pattern:
unusually high traffic,
inappropriate file transfer
changes in protocol use
unexplained system crashes or
unexplained connection terminations Employees Reports Malware
Violations of policy
Data breach:
stolen laptop, memory
employee mistake
Social engineering/fraud:
caller, e-mail, visitors
Unusual event:
inappropriate login
unusual system aborts
server slow
deleted files
defaced website<br>
slide19. (1) Management Participation Management makes final decision
As always, senior management has to be convinced that this is worth the money.<br>
slide20. Planning for Incident Detection & Handling Security Workbook<br>
slide21. Planning for Incident Detection & Handling Security Workbook<br>
slide22. Planning for Incident Detection & Handling Security Workbook<br>
slide23. An Incident is Now Occurring The planning is done and…<br>
slide24. Stage 2: Identification Triage: Categorize, prioritize and assign events and incidents
What type of incident just occurred?
What is the severity of the incident?
Severity may increase if recovery is delayed
Who should be called?
Establish chain of custody for evidence<br>
slide25. (2) Triage Snapshot of the known status of all reported incident activity
Sort, Categorize, Correlate, Prioritize & Assign
Categorize: DoS, Malicious code, Unauthorized access, Inappropriate usage, Multiple components
Prioritize: Limited resources requires prioritizing response to minimize impact
Assign: Who is free/on duty, competent in this area?<br>
slide26. (2) Chain of Custody Evidence must follow Chain of Custody law to be admissible/acceptable in court
Include: specially trained staff, 3rd party specialist, law enforcement, security response team
System administrator can:
Retrieve info to confirm an incident
Identify scope and size of affected environment (system/network)
Determine degree of loss/alteration/damage
Identify possible path of attack<br>
slide27. Stage 3: Containment Activate Incident Response Team to contain threat
IT/security, public relations, mgmt, business
Isolate the problem
Disable server or network zone communications
Disable user access
Change firewall configurations to halt connection
Obtain & preserve evidence<br>
slide28. (3) Containment - Response Technical
Collect data
Analyze log files
Obtain further technical assistance
Deploy patches & workarounds Managerial
Business impacts result in mgmt intervention, notification, escalation, approval
Legal
Issues related to: investigation, prosecution, liability, privacy, laws & regulation, nondisclosure<br>
slide29. Image affected devices: MasterCard recommends that their PCI Forensic Investigators do this step first.
Halt connections: This is a temporary fix, since most attackers can easily change their IP address. The Internet Service Provider may be able to help in filtering an attack pattern.
Disable server communications or network zone: Potentially break access to a zone, by disconnecting network connections or powering down routers. Alternatively, safely power down a server or virtual machine.
Disabling user access: Revoke privileges to internal users who violate policy; change passwords; enable 2-factor authentication; prohibit an executable.
Alert related entities: Notify organizations whose data or systems may be affected (financial, payment card). Internet service provider can help to contain the attack.
Continue to monitor: Closely monitor any continued progress in the attack
Patch vulnerable software: After obtaining images, patch vulnerable software, when vulnerabilities detected. Potential Containment Actions<br>
slide30. Stage 4: Analysis & Eradication Determine how the attack occurred: who, when, how, and why?
What is impact & threat? What damage occurred?
Remove root cause: initial vulnerability(s)
Talk to ISP to get more information
Rebuild System
Improve defenses with enhanced protection techniques
Perform vulnerability analysis
Discuss recovery with management, who must make decisions on handling affecting other areas of business<br>
slide31. (4) Analysis It is important to discover…
What happened?
Who was involved?
What was the reason for the attack?
Where did attack originate from?
When did the initial attack occur?
How did it happen?
What vulnerability enabled the attack?<br>
slide32. (4) Remove root cause If Admin or Root compromised, rebuild system
Implement recent patches & recent antivirus
Change all passwords
Fortify defenses with enhanced security controls
Retest with vulnerability analysis tools<br>
slide33. Stage 5: Recovery Restore operations to normal
Ensure that restore is fully tested and operational<br>
slide34. WorkbookIncident Handling Response Procedure<br>
slide35. Workbook<br>
slide36. Stage 6: Lessons Learned Follow-up includes:
Writing an Incident Report
What went right or wrong in the incident response?
How can process improvement occur?
How much did the incident cost (in loss & handling & time)
Present report to relevant stakeholders<br>
slide37. Planning Processes Risk & Business Impact Assessment
Response & Recovery Strategy Definition
Document IRP and DRP
Train for response & recovery
Update IRP & DRP
Test response & recovery
Audit IRP & DRP<br>
slide38. Training Introductory Training: First day as IMT
Mentoring: Buddy system with longer-term member
Formal Training
On-the-job-training
Training due to changes in IRP/DRP<br>
slide39. Types of Penetration Tests External Testing: Tests from outside network perimeter
Internal Testing: Tests from within network
Blind Testing: Penetration tester knows nothing in advance and must do web research on company
Double Blind Testing: System and security administrators also are not aware of test
Targeted Testing: Have internal information about a target. May have access to an account.
Written permission must always be obtained first<br>
slide40. Incident Management Metrics # of Reported Incidents
# of Detected Incidents
Average time to respond to incident
Average time to resolve an incident
Total number of incidents successfully resolved
Proactive & Preventative measures taken
Total damage from reported or detected incidents
Total damage if incidents had not been contained in a timely manner<br>
slide41. Challenges Management buy-in: Management does not allocate time/staff to develop IRP
Top reason for failure
Organization goals/structure mismatch: e.g., National scope for international organization
IMT Member Turnover
Communication problems: Too much or too little
Plan is too complex and wide<br>
slide42. Question The MAIN challenge in putting together an IRP is likely to be:
Getting management and department support
Understanding the requirements for chain of custody
Keeping the IRP up-to-date
Ensuring the IRP is correct<br>
slide43. Question The PRIMARY reason for Triage is:
To coordinate limited resources
To disinfect a compromised system
To determine the reasons for the incident
To detect an incident<br>
slide44. Question When a system has been compromised at the administrator level, the MOST IMPORTANT action is:
Ensure patches and anti-virus are up-to-date
Change admin password
Request law enforcement assistance to investigate incident
Rebuild system<br>
slide45. Question The BEST method of detecting an incident is:
Investigating reports of discrepancies
NIDS/HIDS technology
Regular vulnerability scans
Job rotation<br>
slide46. Question The person or group who develops strategies for incident response includes:
CISO
CRO
IRT
IMT<br>
slide47. Question The FIRST thing that should be done when you discover an intruder has hacked into your computer system is to:
Disconnect the computer facilities from the computer network to hopefully disconnect the attacker
Power down the server to prevent further loss of confidentiality and data integrity
Call the police
Follow the directions of the Incident Response Plan<br>
slide48. Planning is necessary
Without preparation, no incident will be detected
Incident handlers should not decide what needs to be done.
Stages:
Identification: Determine what has happened
Containment & Escalation: Limit incident
Analysis & Eradication: Analyze root cause, repair
Restore: Test and return to normal
Process Improvement
(Possibly) Breach Notification
If case is to be prosecuted:
Evidence must be carefully handled: Authenticity & Continuity
Expert testimony must be qualified, accurate, bullet-proof Summary<br>
slide49. Health First Case Study Designing Incident Response Jamie Ramon MD
Doctor Chris Ramon RD
Dietician Terry
Licensed
Practicing Nurse Pat
Software Consultant<br>
slide50. Workbook: Table of Incident Types<br>
slide51. Planning for Incident Detection & Handling Security Workbook<br>
slide52. Stages in Incident Response Preparation Identification Containment
& Escalation Analysis &
Eradication Recovery Lessons
Learned Plan PRIOR to Incident Determine what is/has happened Limit incident Determine and remove
root cause Return operations
to normal Process improvement:
Plan for the future Notification Ex-Post
Response Notify any data
breach victims [If data breach] Establish call center,
reparation activities<br>
slide53. Step 1: Detection Technologies Organization must have sufficient detection & monitoring capabilities to detect incidents in a timely manner
Proactive Detection includes:
Network Intrusion Detection/Prevention System (NIDS/NIPS)
Host Intrusion Detection/Prevention System (HIDS/HIPS)
Antivirus, Endpoint Security Suite
Security Information and Event Management (Logs)
Vulnerability/audit testing
System Baselines, Sniffer
Centralized Incident Management System
Input: Server, system logs
Coordinates & co-relates logs from many systems
Tracks status of incidents to closure
Reactive Detection: Reports of unusual or suspicious activity<br>
slide54. Stage 2: Identification Triage: Categorize, prioritize and assign events and incidents
What type of incident just occurred?
What is the severity of the incident?
Severity may increase if recovery is delayed
Who should be called?
Establish chain of custody for evidence<br>
slide55. Stage 3: Containment Activate Incident Response Team to contain threat
IT/security, public relations, mgmt, business
Isolate the problem
Disable server or network zone comm.
Disable user access
Change firewall configurations to halt connection
Obtain & preserve evidence<br>
slide56. Stage 4: Analysis & Eradication Determine how the attack occurred: who, when, how, and why?
What is impact & threat? What damage occurred?
Remove root cause: initial vulnerability(s)
Talk to ISP to get more information
Rebuild System
Improve defenses with enhanced protection techniques
Perform vulnerability analysis
Discuss recovery with management, who must make decisions on handling affecting other areas of business<br>
slide57. Workbook<br>