Automated resolving of security incidents as a key mechanism to fight massive infections of malicious software
Autor(en):
Zusammenfassung
Today, many end systems are infected with malicious software (malware). Often, infections will last for a long time due to missing (auto- mated) detection or insufficient user knowledge. Even large organizations usually do not have the necessary security staff to handle all affected computers. Obviously, automated infections with malicious software cannot be handled by manual repair; new approaches are needed. One way to encounter automatic mass infections is to semi-automate the incident management. Less important security incidents should be handled by the user himself while serious incidents should be forwarded to qualified personal. To enable the end user resolving his own security incidents, both organizational and technical information have to be provided in a comprehensible way. This paper describes PRISM (Portal for Reporting Incidents and Solution Management), which consists of several components addressing the goal: a unit receiving security incidents in the IDMEF format, a component containing the logic for handling security incidents and corresponding remedies, and a component generating dynamic web pages presenting adequate solutions for recorded security incidents. PRISM was verified using case studies for universities, companies and end-user/provider scenarios.
- Vollständige Referenz
- BibTeX
Kaiser, J., Vitzthum, A., Holleczek, P. & Dressler, F.,
(2006).
Automated resolving of security incidents as a key mechanism to fight massive infections of malicious software.
In:
Göbel, O., Schadt, D., Frings, S., Hase, H., Günther, D. & Nedon, J.
(Hrsg.),
IT-Incident Management & IT-Forensics - IMF 2006.
Bonn:
Gesellschaft für Informatik e. V..
(S. 92-103).
@inproceedings{mci/Kaiser2006,
author = {Kaiser, Jochen AND Vitzthum, Alexander AND Holleczek, Peter AND Dressler, Falko},
title = {Automated resolving of security incidents as a key mechanism to fight massive infections of malicious software},
booktitle = {IT-Incident Management & IT-Forensics - IMF 2006},
year = {2006},
editor = {Göbel, Oliver AND Schadt, Dirk AND Frings, Sandra AND Hase, Hardo AND Günther, Detlef AND Nedon, Jens} ,
pages = { 92-103 },
publisher = {Gesellschaft für Informatik e. V.},
address = {Bonn}
}
author = {Kaiser, Jochen AND Vitzthum, Alexander AND Holleczek, Peter AND Dressler, Falko},
title = {Automated resolving of security incidents as a key mechanism to fight massive infections of malicious software},
booktitle = {IT-Incident Management & IT-Forensics - IMF 2006},
year = {2006},
editor = {Göbel, Oliver AND Schadt, Dirk AND Frings, Sandra AND Hase, Hardo AND Günther, Detlef AND Nedon, Jens} ,
pages = { 92-103 },
publisher = {Gesellschaft für Informatik e. V.},
address = {Bonn}
}
Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken
Mehr Information
ISBN: 978-3-88579-191-1
ISSN: 1617-5468
Datum: 2006
Sprache:
(en)
(en)
Typ: Text/Conference Paper

