Další formáty:
BibTeX
LaTeX
RIS
@inproceedings{45326, author = {Husák, Martin and Laštovička, Martin and Tovarňák, Daniel}, address = {Virtual Event}, booktitle = {ARES 2021: The 16th International Conference on Availability, Reliability and Security}, doi = {http://dx.doi.org/10.1145/3465481.3470037}, keywords = {Cybersecurity;Network monitoring;Cyber situational awareness;Incident response;Incident handling}, howpublished = {elektronická verze "online"}, language = {eng}, location = {Virtual Event}, isbn = {978-1-4503-9051-4}, pages = {1-8}, publisher = {Association for Computing Machinery}, title = {System for Continuous Collection of Contextual Information for Network Security Management and Incident Handling}, url = {https://dl.acm.org/doi/abs/10.1145/3465481.3470037}, year = {2021} }
TY - JOUR ID - 45326 AU - Husák, Martin - Laštovička, Martin - Tovarňák, Daniel PY - 2021 TI - System for Continuous Collection of Contextual Information for Network Security Management and Incident Handling PB - Association for Computing Machinery CY - Virtual Event SN - 9781450390514 KW - Cybersecurity;Network monitoring;Cyber situational awareness;Incident response;Incident handling UR - https://dl.acm.org/doi/abs/10.1145/3465481.3470037 N2 - In this paper, we describe a system for the continuous collection of data for the needs of network security management. When a cybersecurity incident occurs in the network, the contextual information on the involved assets facilitates estimating the severity and impact of the incident and selecting an appropriate incident response. We propose a system based on the combination of active and passive network measurements and the correlation of the data with third-party systems. The system enumerates devices and services in the network and their vulnerabilities via fingerprinting of operating systems and applications. Further, the system pairs the hosts in the network with contacts on responsible administrators and highlights critical infrastructure and its dependencies. The system concentrates all the information required for common incident handling procedures and aims to speed up incident response, reduce the time spent on the manual investigation, and prevent errors caused by negligence or lack of information. ER -
HUSÁK, Martin, Martin LAŠTOVIČKA a Daniel TOVARŇÁK. System for Continuous Collection of Contextual Information for Network Security Management and Incident Handling. Online. In \textit{ARES 2021: The 16th International Conference on Availability, Reliability and Security}. Virtual Event: Association for Computing Machinery, 2021, s.~1-8. ISBN~978-1-4503-9051-4. Dostupné z: https://dx.doi.org/10.1145/3465481.3470037.
|