<?xml version="1.0" encoding="UTF-8"?><rdf:RDF xmlns="http://purl.org/rss/1.0/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel rdf:about="http://dl.gi.de/handle/20.500.12116/23452">
<title>P097 - IMF 2006 - IT-Incident Management &amp; IT-Forensics</title>
<link>http://dl.gi.de/handle/20.500.12116/23452</link>
<description/>
<items>
<rdf:Seq>
<rdf:li rdf:resource="http://dl.gi.de/handle/20.500.12116/23461"/>
<rdf:li rdf:resource="http://dl.gi.de/handle/20.500.12116/23462"/>
<rdf:li rdf:resource="http://dl.gi.de/handle/20.500.12116/23464"/>
<rdf:li rdf:resource="http://dl.gi.de/handle/20.500.12116/23465"/>
</rdf:Seq>
</items>
<dc:date>2026-07-23T20:12:14Z</dc:date>
</channel>
<item rdf:about="http://dl.gi.de/handle/20.500.12116/23461">
<title>CarmentiS: A Co-Operative Approach Towards Situation Awareness and Early Warning for the Internet</title>
<link>http://dl.gi.de/handle/20.500.12116/23461</link>
<description>CarmentiS: A Co-Operative Approach Towards Situation Awareness and Early Warning for the Internet
Grobauer, Bernd; Mehlau, Jens Ingo; Sander, Jürgen
Göbel, Oliver; Schadt, Dirk; Frings, Sandra; Hase, Hardo; Günther, Detlef; Nedon, Jens
Abstract. Although plenty of organizations collect sensor data such as IDS alerts or darknet flows, local analysis has its definite limits when it comes to derive conclusions about happenings and trends within the Internet as a whole.
CarmentiS, a joint effort of the early warning working group within the German CERT association, provides an infrastructure and organizational framework for sharing, correlating and cooperatively analyzing sensor data. The infrastructure allows organizations to submit sensor data – at the moment, net flows and IDS alerts are treated – over a secure channel to a central database. Cooperative analysis of the data is made possible via a secure web front end allowing analysts of participating CERTs to create and execute analysis profiles as well as share and discuss analysis results. Thus correlating sensor data and pooling know how and resources for analysis from different sites, CarmentiS provides a framework for a co-operative approach towards situation awareness and early warning for the Internet. This article gives an overview of the CarmentiS infrastructure and organizational framework, and describes the current status of the project. It also addresses open questions that can only be solved by experimenting with co-operative analysis and gives an outlook of possible further developments of the CarmentiS approach towards improved situation awareness and early warning.
</description>
<dc:date>2006-01-01T00:00:00Z</dc:date>
</item>
<item rdf:about="http://dl.gi.de/handle/20.500.12116/23462">
<title>Effectiveness of Proactive CSIRT Services</title>
<link>http://dl.gi.de/handle/20.500.12116/23462</link>
<description>Effectiveness of Proactive CSIRT Services
Wiik, Johannes; Gonzalez, Jose J.; Kossakowski, Klaus-Peter
Göbel, Oliver; Schadt, Dirk; Frings, Sandra; Hase, Hardo; Günther, Detlef; Nedon, Jens
Many authors have suggested that Computer Security Incident Response Teams (CSIRTs) need to deliver more proactive services to stay effective, but there are hardly any studies investigating to what extent existing proactive services are indeed effective or how to make them more effective. We view the proactive services as cross-organisational learning processes, where CSIRTs facilitate learning between information providers (i. e. vendors of commercial off-the-shelf- software) and users of these information (i. e. users of such products) in the CSIRT constituency. Cross-organisational learning processes carry the promise of avoiding incidents and the hope of saving considerable resources, but only if the constituents are enabled to learn from the experiences of the past and from others effectively.
</description>
<dc:date>2006-01-01T00:00:00Z</dc:date>
</item>
<item rdf:about="http://dl.gi.de/handle/20.500.12116/23464">
<title>Automated resolving of security incidents as a key mechanism to fight massive infections of malicious software</title>
<link>http://dl.gi.de/handle/20.500.12116/23464</link>
<description>Automated resolving of security incidents as a key mechanism to fight massive infections of malicious software
Kaiser, Jochen; Vitzthum, Alexander; Holleczek, Peter; Dressler, Falko
Göbel, Oliver; Schadt, Dirk; Frings, Sandra; Hase, Hardo; Günther, Detlef; Nedon, Jens
Today, many end systems are infected with malicious software (malware). Often, infections will last for a long time due to missing (auto- mated) detection or insufficient user knowledge. Even large organizations usually do not have the necessary security staff to handle all affected computers. Obviously, automated infections with malicious software cannot be handled by manual repair; new approaches are needed. One way to encounter automatic mass infections is to semi-automate the incident management. Less important security incidents should be handled by the user himself while serious incidents should be forwarded to qualified personal. To enable the end user resolving his own security incidents, both organizational and technical information have to be provided in a comprehensible way. This paper describes PRISM (Portal for Reporting Incidents and Solution Management), which consists of several components addressing the goal: a unit receiving security incidents in the IDMEF format, a component containing the logic for handling security incidents and corresponding remedies, and a component generating dynamic web pages presenting adequate solutions for recorded security incidents. PRISM was verified using case studies for universities, companies and end-user/provider scenarios.
</description>
<dc:date>2006-01-01T00:00:00Z</dc:date>
</item>
<item rdf:about="http://dl.gi.de/handle/20.500.12116/23465">
<title>Pool Allocations as an Information Source in Windows Memory Forensics</title>
<link>http://dl.gi.de/handle/20.500.12116/23465</link>
<description>Pool Allocations as an Information Source in Windows Memory Forensics
Schuster, Andreas
Göbel, Oliver; Schadt, Dirk; Frings, Sandra; Hase, Hardo; Günther, Detlef; Nedon, Jens
The Microsoft Windows kernel provides a heap-like memory management, called "pools". Whenever some kernel-mode code requires an amount of memory, it is allocated from a pool. Ignoring the documented interface and searching the whole dump of physical memory for signatures of pool allocations allows the forensic examiner to gain information not only from currently active but also from freed and not yet overwritten allocations. Understanding the inner mechanics of memory pools enables an examiner to connect certain finds in memory to the originating piece of code. As an example this articles describes the steps necessary to detect traces of network activity in a memory dump.
</description>
<dc:date>2006-01-01T00:00:00Z</dc:date>
</item>
</rdf:RDF>
