Detection
Summary
PDF p.300Detection involves correlating events from various data sources to identify potential security incidents. Indicators can be recorded through multiple channels, and it's crucial to notify the appropriate person on the CIRT when a suspicious event is detected.
In plain words
Supplementary — not from your PDFDetection finds indicators through log and alert matching, deviations from baselines, manual inspection and threat hunting, reports from staff, customers and suppliers, public vulnerability reports, and confidential reporting channels for insider issues. The first responder on the CIRT takes charge when a suspicious event is reported. Everyone should be trained to recognize and report incidents.
Detailed explanation
PDF p.300Detection Channels
- Log Files and Alerts: Matching events in log files, error messages, IDS alerts, firewall alerts, and other data sources to known threat patterns.
- Baseline Deviations: Identifying deviations from baseline system metrics.
- Manual Inspection: Physically inspecting sites, premises, networks, and hosts. Proactive searches for signs of intrusion are known as threat hunting.
- Notifications: Reports from employees, customers, or suppliers.
- Public Reports: New vulnerabilities or threats reported by system vendors, regulators, media, or other outside parties.
- Confidential Reporting: Providing options for employees to report insider threats like fraud or misconduct without fear.
First Responder
- Role: The first responder is the person on the CIRT notified of a suspicious event. They take charge of the situation and formulate the appropriate response.
- Training: Employees at all levels must be trained to recognize and respond to security incidents.
Important terms
taken from the text above- Log Files and Alerts
- Matching events in log files, error messages, IDS alerts, firewall alerts, and other data sources to known threat patterns.
- Baseline Deviations
- Identifying deviations from baseline system metrics.
- Manual Inspection
- Physically inspecting sites, premises, networks, and hosts. Proactive searches for signs of intrusion are known as threat hunting.
- Notifications
- Reports from employees, customers, or suppliers.
- Public Reports
- New vulnerabilities or threats reported by system vendors, regulators, media, or other outside parties.
- Confidential Reporting
- Providing options for employees to report insider threats like fraud or misconduct without fear.
- Training
- Employees at all levels must be trained to recognize and respond to security incidents.
Examples & real-world scenarios
Supplementary — not from your PDF- An IDS alert matching a known malicious pattern.
- An employee reporting a suspicious email.
- A server's CPU far above its baseline at 3 a.m.
Scenario
A customer reports getting phishing emails that appear to come from the company. That external notification is a detection source that starts an investigation.
Common mistakes
Supplementary — not from your PDF- Relying only on automated alerts and ignoring human reports.
- Having no confidential way for staff to report misconduct.
Practical skills
Supplementary — not from your PDF- List detection channels and who acts first.
What I should remember
Key Points PDF p.300-
Detection Channels
- Log Files and Alerts: Match events to threat patterns.
- Baseline Deviations: Identify unusual metrics.
- Manual Inspection: Conduct threat hunting.
- Notifications: Receive reports from various sources.
- Public Reports: Monitor external vulnerability reports.
- Confidential Reporting: Encourage insider threat reporting.
-
First Responder
- Role: Takes charge of detected incidents.
- Training: Ensures all employees can recognize and respond to incidents.