• DocumentCode
    1616351
  • Title

    Towards Automated Incident Handling: How to Select an Appropriate Response against a Network-Based Attack?

  • Author

    Ossenbuhl, Sven ; Steinberger, Jessica ; Baier, Harald

  • Author_Institution
    da/sec - Biometrics & Internet Security Res. Group, Univ. of Appl. Sci., Darmstadt, Germany
  • fYear
    2015
  • Firstpage
    51
  • Lastpage
    67
  • Abstract
    The increasing amount of network-based attacks evolved to one of the top concerns responsible for network infrastructure and service outages. In order to counteract these threats, computer networks are monitored to detect malicious traffic and initiate suitable reactions. However, initiating a suitable reaction is a process of selecting an appropriate response related to the identified network-based attack. The process of selecting a response requires to take into account the economics of an reaction e.g., risks and benefits. The literature describes several response selection models, but they are not widely adopted. In addition, these models and their evaluation are often not reproducible due to closed testing data. In this paper, we introduce a new response selection model, called REASSESS, that allows to mitigate network-based attacks by incorporating an intuitive response selection process that evaluates negative and positive impacts associated with each countermeasure. We compare REASSESS with the response selection models of IE-IRS, ADEPTS, CS-IRS, and TVA and show that REASSESS is able to select the most appropriate response to an attack in consideration of the positive and negative impacts and thus reduces the effects caused by an network-based attack. Further, we show that REASSESS is aligned to the NIST incident life cycle. We expect REASSESS to help organizations to select the most appropriate response measure against a detected network-based attack, and hence contribute to mitigate them.
  • Keywords
    computer network security; telecommunication traffic; ADEPTS; CS-IRS; IE-IRS; NIST incident life cycle; REASSESS; TVA; automated incident handling; closed testing data; computer network monitoring; malicious traffic detection; network infrastructure; network-based attack; network-based attacks; reaction initiation; response selection models; service outages; Adaptation models; Biological system modeling; Delays; Internet; NIST; Network topology; Security; automatic mitigation; cyber security; intrusion response systems; network security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    IT Security Incident Management & IT Forensics (IMF), 2015 Ninth International Conference on
  • Conference_Location
    Magdeburg
  • Print_ISBN
    978-1-4799-9902-6
  • Type

    conf

  • DOI
    10.1109/IMF.2015.13
  • Filename
    7195806