Designing and Developing an Application for Incident Response Teams



Similar documents
Designing and developing an Application for Incident Response Teams

SIRIOS the Framework for CERTs

Open Source Incident Management Tool for CSIRTs

OTRS: Issue Management System Meets Workflow of Security Team Pavel Kácha, 2007 CESNET, z. s. p. o.

RT for Incident Response (RTIR)

RFC 2350 CSIRT-TEHTRIS [CERT-TEHTRIS]

RT and RT for Incident Response

Request Tracker for Incident Response (RTIR)

Customize the data collected from users when submitting a ticket to help get straight to the issue.

RT and RT for Incident Response

Building CSIRT Capabilities

RTIR incident handling work-flow

How To Create A Distributed Virtual Network Control System

Automated resolving of security incidents as a key mechanism to fight massive infections of malicious software

CERT Polska. Przemyslaw Jaroszewski, Miroslaw Maj CERT POLSKA. TF-CSIRT Meeting, Copenhagen, 23 May

Request for Comments: 3067 Category: Informational JANET-CERT Y. Demchenko TERENA J. Meijer SURFnet February 2001

Integration of Standardized Syntax and Semantics (Common Language) into CSIRT Operations

Incident Management Process: Strategies, tools and techniques

SES / CIF. Internet2 Combined Industry and Research Constituency Meeting April 24, 2012

IT Support Tracking with Request Tracker (RT)

ServiceDesk Plus On-Demand Comparison Document ServiceDesk Plus v8 vs ServiceDesk Plus On- Demand ENTERPRISE VERSIONS

Using the BWSD Help Desk Website

CERT/CC Overview & CSIRT Development Team Activities

933 COMPUTER NETWORK/SERVER SECURITY POLICY

DANCERT RFC2350 Description Date: Dissemination Level:

Jumpstart Your Incident Response Plan September 2014

CSIRT Introduction to Security Incident Handling

Incident Response Procedures

Naverisk 2013 R3 - Road Map

3 Simple Steps to Take Charge of Your Network Access Security

Vulnerability Assessment Report Format Data Model

Managed Incident Lightweight Exchange (MILE)

Table of Contents INTRODUCTION...2 HOME PAGE...3. Announcements... 6 Personalize... 7 Reminders... 9 Recent Items SERVICE CATALOG...

How to integrate Verax NMS & APM with Verax Service Desk

Your Help Desk evaluation is not complete until you check out the comparison between the different editions of ServiceDesk Plus and the price.

QUICK START GUIDE. Cisco C170 Security Appliance

STRATEGIC POLICY. Information Security Policy Documentation. Network Management Policy. 1. Introduction

everything HelpDesk [Ease of Use] [100% Web Help Desk] [Business Process Automation] [World Class Customer Service]

How to Work with HEAT Self Service

Dell KACE K1000 Management Appliance. Service Desk Administrator Guide. Release 5.3. Revision Date: May 13, 2011

Vector HelpDesk v6.0. What's New Bulletin. Feature rich internal and external customer support

DFW INTERNATIONAL AIRPORT STANDARD OPERATING PROCEDURE (SOP)

Request For Proposal (RFP) Issued by FIRST.Org, Inc. ASSOCIATION MANAGEMENT SYSTEM. Submittal Deadline: December 18 th, 2015

Track-It! 8.5. The World s Most Widely Installed Help Desk and Asset Management Solution

Network Security Monitoring and Behavior Analysis Pavel Čeleda, Petr Velan, Tomáš Jirsík

Enterprise Communication Suite

Table of Contents INTRODUCTION... 2 HOME PAGE Announcements Personalize & Change Password Reminders SERVICE CATALOG...

Patch and Vulnerability Management Program

Intrusion Detection Systems

CERT.AZ description as per RfC 2350

VRDA Vulnerability Response Decision Assistance

Coordinating Attack Response at Internet Scale (CARIS)

c360 Product Catalog

X-log Incident-Monitor System for Internal Control

jsecrm Corporate Edition

K7 Business Lite User Manual

User Guide Secure Configuration Manager

Table of Contents INTRODUCTION... 2 HOME PAGE Announcements... 7 Personalize & Change Password... 8 Reminders... 9 SERVICE CATALOG...

CSIRT Description for CERT OPL

NCP Secure Enterprise Management for Windows OS. New Features version 1.03 to 2.05

SolarWinds Log & Event Manager

Integral Party Plan Software. Implementation Options 2015

Network Monitoring. Sebastian Büttrich, NSRC / IT University of Copenhagen Last edit: February 2012, ICTP Trieste

Everything You Need in Service Management Software

Improving End-User Support with the K1000 Help Desk/Service Desk

#42 D A N T E I N P R I N T. Tackling Network DoS on Transit Networks. David Harmelin

Bomgar 10.6 License Comparison

IT Service Desk Manual Ver Document Prepared By: IT Department. Page 1 of 12

Your New Service Request Process: Technical Support Reference Guide for Cisco ServiceGrid

Vulnerability Remediation Plugin Guide

quality of service Screenshots

University System of Maryland University of Maryland, College Park Division of Information Technology

1.1 SERVICE DESCRIPTION

Support Desk Help Manual. v 1, May 2014

1.1 SIP - No call possible

Cisco Unified Attendant Console Advanced Version 10.0

ServiceDesk Plus On-Demand QUICK START GUIDE

Business Voice over IP. Customer Care and Support Guide for Migrating Customers

Customer Interaction Solutions

Business Benefits. Infrastructure Management. Adrian Parry Technical Consultant.

Product Comparison List

VitalQIP DNS/DHCP & IP Address Management Software and Appliance Solution

New features and highlights

F-Secure Messaging Security Gateway. Deployment Guide

Ticketing Systems with RT

Network Management & Monitoring Ticketing Systems with RT

Microsoft Version: Demo 30.0

GFI Product Manual. Administration and Configuration Manual

Implementing, Managing, and Maintaining a Microsoft Windows Server 2003 Network Infrastructure

101 ways to use SysAid

Security Frameworks. An Enterprise Approach to Security. Robert Belka Frazier, CISSP

ITX HELP DESK CONSULTANT PROGRAMMER I UCD / PROGRAMMER II UCD. This position is not represented by a collective bargaining unit

Network Security Monitoring

ObserveIT Service Desk Integration Guide

Concierge SIEM Reporting Overview

Feature Comparison. Help Desk. Ticket Management. to Ticket. Fully Customizable User Interface. Escalation Rules.

CorreLog: Mature SIEM Solution on Day One Paul Gozaloff, CISSP. Presentation for SC Congress esymposium CorreLog, Inc. Tuesday, August 5, 2014

Information Sharing Use Cases

McAfee Network Threat Response (NTR) 4.0

QUICK START GUIDE. Cisco S170 Web Security Appliance. Web Security Appliance

Transcription:

Designing and Developing an Application for Incident Response Teams Kees Leune and Sebastiaan Tesink Tilburg University, The Netherlands FIRST 2006, Baltimore, MD, USA High-quality Internet for higher education and research

Overview The Problem Objectives The solution: AIRT Related work Recent improvements Summary 2 High-quality Internet for higher education and research

Context Tilburg University CSIRT established in March, 2004 2,000 managed nodes on-campus 3,000 nodes in student houses using cable-modems 2,000 nodes in student houses using direct glassfiber connections Campus-wide wireless access for all faculty, staff and students. Cable modems were causing 95% of incidents; exposed directly to the Internet in our main IP range (not a good plan) 3 High-quality Internet for higher education and research

Problem analysis Seven incident responders, all part-time. Consequence: Tracking problem Which incidents are being handled, and how? Coordination problem Who does what? 4 High-quality Internet for higher education and research

Starting development Need for a tool to support day-to-day operations. Regular email ticketing systems (Top Desk and Request Tracker) did not provide much improvement. Specialized incident response tool: RTIR was too much RT and not enough IR. Need to tap in many existing databases to find information (MAC address registrations, LDAP, other internal databases). 5 High-quality Internet for higher education and research

Development Objectives Ability to record incidents and take initial actions in less than 30 seconds (average) after an incident handler becomes aware of the report. Email that is generated and sent automatically should be received and processed automatically as much as possible. Application should be web-based and available under an Open license. Application must be able to interact with existing data sources, tools and programs. 6 High-quality Internet for higher education and research

Importance of incoming email PREPARE Estimated 95% or more comes in the form of Email Detect Triage Respond PROTECT Carnegie Mellon's Incident Management Process 7 High-quality Internet for higher education and research

Email vs. Information Automated reporting originating from known sources, containing data in known formats 85%-95% Unknown sources and/or unknown formats The actual message is NOT all that important-- it is the information contained in the message in which we are interested 8 High-quality Internet for higher education and research

AIRT Features Comprehensive incident management console, Outgoing mail using mail templates, including support for PGP signed mail and automatic actions, Import queue to automatically process data from known (and trusted) sources. AIRT ships with support for MyNetwatchman, Spamcop, IDMEF, etc. Export queue to (securely) run commands on the host operating system, Maintains original incident identifiers, Extensive search abilities (by IP address, hostname, incident number, network range), Detects repeat offenders, Open and extensible. 9 High-quality Internet for higher education and research

AIRT Basics Incident data: Basic incident data: incident type, and incident status, and incident state, and logging. A number of IP addresses, which belong to a network, which is managed by a constituency, which has constituency contacts. Each IP address plays a certain role in the incident. A number of users. 10 High-quality Internet for higher education and research

Incident Overview The incident overview provides a comprehensive overview of the current state of the constituency. Features: Display of incident ID, Constituency, host name, Status, State, Type, Date (including ordering) Filtering by status/state/type Mass creation of incidents Mass update of incidents Mass processing of outgoing email (template-based) 11 High-quality Internet for higher education and research

Screenshot incident overview cons-1 airt.nl cons-1 cons-1 airt.nl cons-2 cons-2 cons-2 cons-1 cust-1 external external airt.nl cust-1 external cust-2 cons-1 cust-2 cust-2 12 High-quality Internet for higher education and research

Import queue The AIRT import queue allows data from different sources to be automatically processed and relevant information to be extracted from the incoming mail. 13 High-quality Internet for higher education and research

14 High-quality Internet for higher education and research

Search facilities AIRT provides a number of search facilities to quickly find all data required to adequately respond to complaints: Search by IP address Search by email address Search by network range Search by incident ID (internal and external) 15 High-quality Internet for higher education and research

16 High-quality Internet for higher education and research

Related work Standards IODEF Overly complex and elaborate. Subset of IODEF can be implemented as import filter. CAIF Still in development, used for storing security announcements. CAIF import filter is viable. IDMEF Under development at IETF; simple XML-based standard for incident respose alert representation. Possible candidate to replace XIRL. 17 High-quality Internet for higher education and research

Related Work Products Request Tracker for Incident Response. E-mail ticketing system with web-based front-end. Most well-known competitor to AIRT. Operates on top of general RT product, enhanced with several securityrelated functions. SIRIOS: Modular application framework designed for (CSIRTs) with main focus on incident management and vulnerability handling. SIRIOS is based on OTRS and is sponsored by CERT-Bund, the German governmental CERT. 18 High-quality Internet for higher education and research

Improvements since paper was authored IDMEF import filter, Ability to associate actions with sending mail templates, Ability to associate external incident identifiers with AIRT incidents, Mass sending of email, Export queue, Numerous bug fixes, Various interface enhancements. 19 High-quality Internet for higher education and research

Summary and conclusions AIRT provides an incident management system that is based on the notion of an 'incident'. Provides easy integration with existing products. Adopts Open standards where possible. Currently in use with a number of CSIRTs in The Netherlands (SURFnet-CERT, UvA-CERT, UvT-CERT, CERT-UT). Being evaluated by several others worldwide. 20 High-quality Internet for higher education and research

Thanks AIRT has been developed with the support of SURFnet, the Dutch National Research and Education Network. http://www.surfnet.nl 21 High-quality Internet for higher education and research

Kees Leune kees@uvt.nl Contact Information Tilburg University, Infolab P.O. Box 90153 5000 LE Tilburg The Netherlands http://www.airt.nl 22 High-quality Internet for higher education and research