Cyberstudy
PDF p.301 In progress

Analysis

Open PDF at p.301 17 flashcards

Summary

PDF p.301

After detection, the analysis process involves investigating data to confirm if a genuine incident has occurred and determining its priority. This process may involve correlating multiple indicators and escalating complex events to senior CIRT members.

In plain words

Supplementary — not from your PDF

Analysis decides whether the event is a real incident (true positive) or not (false positive), and how serious it is. Impact is judged by data integrity, downtime, economic and publicity cost, scope, detection time and recovery time. Categorizing incidents (using threat intelligence and the Cyber Kill Chain) gives a shared language, and playbooks, data-driven SOPs for specific scenarios, guide each step.

Detailed explanation

PDF p.301

Incident Verification

  • True Positive: Confirmed incident based on multiple indicators.
  • False Positive: Dismissed report if no genuine incident is found.
  • Escalation: Complex or high-impact events may be escalated to senior CIRT members.

Impact Assessment

  • Data Integrity: Value of data at risk.
  • Downtime: Degree of disruption to business processes.
  • Economic/Publicity Impact: Short-term costs (incident response, lost business) and long-term costs (reputation damage).
  • Scope: Number of systems affected, not always indicative of priority.
  • Detection Time: Speed of detecting breaches.
  • Recovery Time: Length of remediation process.

Incident Categorization

  • Purpose: Ensures shared understanding among response team members.
  • Threat Intelligence: Provides insights into adversary tactics, techniques, and procedures (TTPs).
  • Cyber Kill Chain: Framework describing attack stages, useful for threat research.

Playbooks

  • Purpose: Guides investigators in determining priorities and remediation plans.
  • Content: Data-driven SOPs for specific cyber threat scenarios.
  • Process: Starts with an alert report and leads through analysis, containment, eradication, recovery, and lessons learned.

Important terms

taken from the text above
True Positive
Confirmed incident based on multiple indicators.
False Positive
Dismissed report if no genuine incident is found.
Escalation
Complex or high-impact events may be escalated to senior CIRT members.
Data Integrity
Value of data at risk.
Downtime
Degree of disruption to business processes.
Economic/Publicity Impact
Short-term costs (incident response, lost business) and long-term costs (reputation damage).
Detection Time
Speed of detecting breaches.
Recovery Time
Length of remediation process.
Threat Intelligence
Provides insights into adversary tactics, techniques, and procedures (TTPs).
Cyber Kill Chain
Framework describing attack stages, useful for threat research.

Examples & real-world scenarios

Supplementary — not from your PDF
  • Correlating a phishing report with a suspicious login to confirm an incident.
  • Escalating a possible data breach to senior CIRT members.
  • Following a ransomware playbook.

Scenario

Two incidents arrive together: 100 PCs with adware, and one database server with signs of data theft. Impact on data and the business makes the single server the higher priority, even though fewer systems are affected.

Common mistakes

Supplementary — not from your PDF
  • Prioritizing by number of affected systems alone.
  • Not documenting why a report was dismissed as a false positive.

Practical skills

Supplementary — not from your PDF
  • Prioritize incidents using impact factors.

What I should remember

Key Points PDF p.301
  • Incident Verification
    • True Positive: Confirmed incident.
    • False Positive: Dismissed report.
    • Escalation: For complex events.
  • Impact Assessment
    • Data Integrity: Value of data.
    • Downtime: Business disruption.
    • Economic/Publicity Impact: Short-term and long-term costs.
    • Scope: Number of systems affected.
    • Detection Time: Speed of detection.
    • Recovery Time: Length of remediation.
  • Incident Categorization
    • Purpose: Shared understanding.
    • Threat Intelligence: Insights into TTPs.
    • Cyber Kill Chain: Attack stages framework.
  • Playbooks
    • Purpose: Guides for incident response.
    • Content: SOPs for threat scenarios.
    • Process: Steps from alert to lessons learned.