02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

service managers or customers. Such emergency situations need to be addressed in any response<br />

plans and in any authority given to <strong>the</strong> CSIRT.<br />

The speed with which such malicious attacks spread have reinforced <strong>the</strong> need for a good incident<br />

response plan to be in place, including established channels <strong>of</strong> communication, identified<br />

response staff, notification lists, and established recovery policies and procedures. Involvement<br />

<strong>of</strong> <strong>the</strong> CSIRT in <strong>the</strong> configuration <strong>of</strong> <strong>the</strong> constituency infrastructure is also<br />

important, as <strong>the</strong> only response is <strong>of</strong>ten to stop <strong>the</strong> incident from happening at your site, by<br />

ensuring your site is not vulnerable or has good perimeter defenses and host configurations.<br />

O<strong>the</strong>r trends previously noted by <strong>the</strong> CERT/CC have warned <strong>of</strong> attacks against Windowsbased<br />

targets, especially in DoS attacks, 110 as well as attackers increasingly targeting home<br />

users’ systems because <strong>of</strong> <strong>the</strong>ir wide availability, high bandwidth, and relative lack <strong>of</strong> security.<br />

The CERT/CC has created a section on <strong>the</strong>ir web site for home users, 111 containing a<br />

number <strong>of</strong> articles, as well as a document titled “Home Network <strong>Security</strong>.” 112<br />

These trends outlined by <strong>the</strong> CERT/CC indicate that organizations relying on <strong>the</strong> Internet face<br />

significant challenges to ensure that <strong>the</strong>ir networks operate safely and that <strong>the</strong>ir systems continue<br />

to provide critical services even in <strong>the</strong> face <strong>of</strong> attack.<br />

3.8.1 Impact on <strong>Incident</strong> <strong>Response</strong><br />

The growing threats caused by intruder attack trends have affected <strong>the</strong> way in which CSIRT<br />

staff must respond. The sheer number <strong>of</strong> attacks that are detected and reported continues to<br />

rise, with many CSIRTs typically seeing a doubling (or more) in <strong>the</strong> rate <strong>of</strong> new incident reports<br />

with each passing year. Annual incident statistics posted by <strong>the</strong> CERT/CC 113 and <strong>the</strong><br />

CSI/FBI <strong>Computer</strong> Crime and <strong>Security</strong> Surveys 114 are frequently cited as examples <strong>of</strong> <strong>the</strong><br />

growing rate <strong>of</strong> incident reports.<br />

110<br />

111<br />

112<br />

113<br />

114<br />

“Trends in Denial <strong>of</strong> Service Attack Technology”<br />

<br />

<br />

“Home Network <strong>Security</strong>” <br />

<br />

<br />

112 CMU/SEI-2003-TR-001

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!