02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

[Curry 03]<br />

Curry, D. & Debar, H. Intrusion Detection Message Exchange Format<br />

Data Model and Extensible Markup Language (XML).<br />

http://www.ietf.org/internet-drafts/draft-ietf-idwg-idmef-xml-10.txt<br />

(January 2003).<br />

[CXO 02]<br />

CXO Media. “Fundamentals <strong>of</strong> <strong>Security</strong>.” cso online.com.<br />

http://www.csoonline.com/fundamentals/security.html (2002).<br />

[CXO 03]<br />

CXO Media Inc. CIO Focus Guide, “Securing Information Assets:<br />

Planning, Prevention and <strong>Response</strong>.”<br />

http://www.<strong>the</strong>ciostore.com/guide_product.asp?id=84 (2003).<br />

[DHS 2003]<br />

U.S. Department <strong>of</strong> Homeland <strong>Security</strong>, Information Analysis Infrastructure<br />

Protection, http://www.nipc.gov/incident/cirr.htm. (2003)<br />

(previously available from <strong>the</strong> National Infrastructure Protection<br />

Center)<br />

[Dittrich 02]<br />

Dittrich, David A. “Developing an Effective <strong>Incident</strong> Cost Analysis<br />

Mechanism.” <strong>Security</strong>Focus.<br />

http://www.securityfocus.com/infocus/1592 (2002).<br />

[DShield 03]<br />

Distributed Intrusion Detection System, DShield.org.<br />

http://www.dshield.org/ (2003).<br />

[Duffy 01]<br />

Duffy, Daintry. “Don’t Press <strong>the</strong> Panic Button.” Darwin.<br />

http://www.darwinmag.com/read/090101/panic.html (2001).<br />

[eCSIRT 03] The European CSIRT Network. http://www.ecsirt.net/ (2004).<br />

[EISPP 03]<br />

European Information <strong>Security</strong> Prevention Programme (EISPP).<br />

http://www.eispp.org/ (2003).<br />

[FCC 01]<br />

“FCC <strong>Computer</strong> <strong>Security</strong> <strong>Incident</strong> <strong>Response</strong> Guide,” Federal Communications<br />

Commission,<br />

http://csrc.nist.gov/fasp/FASPDocs/incident-response/<strong>Incident</strong>-<br />

<strong>Response</strong>-Guide.pdf. (2001).<br />

250 CMU/SEI-2003-TR-001

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!