Cyberstudy
PDF p.300 In progress

Detection

Open PDF at p.300 14 flashcards

Summary

PDF p.300

Detection involves correlating events from various data sources to identify potential security incidents. Indicators can be recorded through multiple channels, and it's crucial to notify the appropriate person on the CIRT when a suspicious event is detected.

In plain words

Supplementary — not from your PDF

Detection finds indicators through log and alert matching, deviations from baselines, manual inspection and threat hunting, reports from staff, customers and suppliers, public vulnerability reports, and confidential reporting channels for insider issues. The first responder on the CIRT takes charge when a suspicious event is reported. Everyone should be trained to recognize and report incidents.

Detailed explanation

PDF p.300

Detection Channels

  • Log Files and Alerts: Matching events in log files, error messages, IDS alerts, firewall alerts, and other data sources to known threat patterns.
  • Baseline Deviations: Identifying deviations from baseline system metrics.
  • Manual Inspection: Physically inspecting sites, premises, networks, and hosts. Proactive searches for signs of intrusion are known as threat hunting.
  • Notifications: Reports from employees, customers, or suppliers.
  • Public Reports: New vulnerabilities or threats reported by system vendors, regulators, media, or other outside parties.
  • Confidential Reporting: Providing options for employees to report insider threats like fraud or misconduct without fear.

First Responder

  • Role: The first responder is the person on the CIRT notified of a suspicious event. They take charge of the situation and formulate the appropriate response.
  • Training: Employees at all levels must be trained to recognize and respond to security incidents.

Important terms

taken from the text above
Log Files and Alerts
Matching events in log files, error messages, IDS alerts, firewall alerts, and other data sources to known threat patterns.
Baseline Deviations
Identifying deviations from baseline system metrics.
Manual Inspection
Physically inspecting sites, premises, networks, and hosts. Proactive searches for signs of intrusion are known as threat hunting.
Notifications
Reports from employees, customers, or suppliers.
Public Reports
New vulnerabilities or threats reported by system vendors, regulators, media, or other outside parties.
Confidential Reporting
Providing options for employees to report insider threats like fraud or misconduct without fear.
Training
Employees at all levels must be trained to recognize and respond to security incidents.

Examples & real-world scenarios

Supplementary — not from your PDF
  • An IDS alert matching a known malicious pattern.
  • An employee reporting a suspicious email.
  • A server's CPU far above its baseline at 3 a.m.

Scenario

A customer reports getting phishing emails that appear to come from the company. That external notification is a detection source that starts an investigation.

Common mistakes

Supplementary — not from your PDF
  • Relying only on automated alerts and ignoring human reports.
  • Having no confidential way for staff to report misconduct.

Practical skills

Supplementary — not from your PDF
  • List detection channels and who acts first.

What I should remember

Key Points PDF p.300
  • Detection Channels
    • Log Files and Alerts: Match events to threat patterns.
    • Baseline Deviations: Identify unusual metrics.
    • Manual Inspection: Conduct threat hunting.
    • Notifications: Receive reports from various sources.
    • Public Reports: Monitor external vulnerability reports.
    • Confidential Reporting: Encourage insider threat reporting.
  • First Responder
    • Role: Takes charge of detected incidents.
    • Training: Ensures all employees can recognize and respond to incidents.