02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

nisms for collecting, correlating, and syn<strong>the</strong>sizing incident data. Some <strong>of</strong> <strong>the</strong>se projects and<br />

tools are described below.<br />

3.10.3.1 AirCERT<br />

The AirCERT (Automated <strong>Incident</strong> Reporting) is a development project by <strong>the</strong> CERT/CC to<br />

automate <strong>the</strong> reporting <strong>of</strong> incident data in a manner so that data can easily be summarized and<br />

queried to provide a view <strong>of</strong> network activity. It involves <strong>the</strong> placement <strong>of</strong> Internet-based security<br />

event sensors on <strong>the</strong> networks <strong>of</strong> various organizations attached to <strong>the</strong> Internet. These<br />

sensors will log locally selected information on detected security events and anomalies to<br />

both a local database and a central database located at <strong>the</strong> CERT/CC. The local organization<br />

can decide what, if any, data is passed to <strong>the</strong> CERT/CC and can sanitize <strong>the</strong> data as desired.<br />

The CERT/CC has developed a prototype <strong>of</strong> this system using open source and low-cost<br />

components. The current prototype is based on collecting data using Snort, an open source<br />

IDS. Future prototypes will look at collecting data from o<strong>the</strong>r IDS, including <strong>of</strong>f-<strong>the</strong>-shelf<br />

products.<br />

The following components are available for download and use:<br />

• Snort XML plug-in<br />

• Analysis Console for Intrusion Databases (ACID). ACID is a PHP-based analysis engine<br />

for searching and processing a database <strong>of</strong> security events generated by various IDSes,<br />

firewalls, and network monitoring tools.<br />

For more information see:<br />

http://www.cert.org/kb/aircert/<br />

3.10.3.2 CERT/CC Current Activity<br />

The CERT/CC Current Activity web page is a regularly updated summary <strong>of</strong> <strong>the</strong> most frequent,<br />

high-impact types <strong>of</strong> security incidents currently being reported to <strong>the</strong> CERT/CC. Any<br />

security incidents can be reported to <strong>the</strong> CERT/CC via <strong>the</strong>ir incident reporting form located at<br />

http://www.cert.org/reporting/incident_form.txt or via email to cert@cert.org.<br />

CERT/CC also summarizes <strong>the</strong> scanning activity that is currently being reported to it. This<br />

information can be viewed at http://www.cert.org/current/scanning.html.<br />

Anyone submitting logs and data should ensure that <strong>the</strong> information has been appropriately<br />

sanitized or is submitted in a secure manner.<br />

For more information see:<br />

http://www.cert.org/current/<br />

http://www.cert.org/contact_cert/<br />

CMU/SEI-2003-TR-001 125

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!