electricfork

Methodologies

Posted Jan 15, 01:28 PM by ben

Maybe I’m being a bit pedantic but there seems to be a recursive loop somewhere here. The information security lifecycle tends to be quoted as:

countermeasures/protect -> detect -> respond

And of course everyone then breaks down the respond methodology down somewhere akin to:
prepare -> detect -> contain -> eradicate -> recover -> follow-up

That “d” word is pretty popular huh? I find it interesting that there’s not a lot of attention towards it. Especially in IR books. As a rule of thumb, they’ll spend the first chapter on the preparing stage, a section on explaining why IDS/detection is out of scope, a bit on containment, then 80% of the remaining book on eradication. (Which, incidentally, when did ‘detection’ become synonymous to just an IDS? Don’t you get calls when things ‘act wierd’?)

While it makes logical sense to have detect as a stage in the entire IR process, that doesn’t mean it doesn’t deserve at least a chapter on the subject. And don’t you dare make that subject about snort. Indeed, detection can be broken up into stages just like IR. Since I’ve yet to come across any in my own reading here is my own process:

discover -> prioritize -> investigate -> escalate -> follow-up

Once we get to ‘escalate’ the rest of the IR process takes over, notably containment. I guess everyone likes to talk about responding because there are results from it. Same goes to implementing an IDS system or setting up awareness to sysadmins and users. Has anyone taken the time to prioritizing/categorizing events? Finding valuable metrics? Reporting? Writing a detection book that’s absolutely not about technology but about managing the detection implementation? How about a magazine article? Am I simply ignorant to some de facto ‘standard’ on this?


// :: /

Comments

  1. Good point Ben...

    I think the reason they focus on the other "stuff" is because it's sexy (like in the movies) to actually be on the hunt. I kind of equate the "detection/monitor" piece as being one of the "cold warriors" in a missle bunker... only called upon once shit hits the fan.

    (BTW

    David · Jan 16, 09:00 AM · #

Commenting is closed for this article.

Creative Commons License
This work by http://electricfork.com is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 United States License.

archive

about

charmsec

I lead an information security ops and response team. This site is a collection of interesting notes and brainstorms on the protecting from, detecting of, and responding to badness. You can read more about me or my site here.

You can subscribe to my blog via rss , or if you're looking for older items check out my archive of previous posts.

I organize a small infosec meetup in baltimore called charmsec. If you are looking for charmsec details you probably want to go here.

 

RSS

:: © 2002-2008