Logo des Repositoriums
 

Automated resolving of security incidents as a key mechanism to fight massive infections of malicious software

dc.contributor.authorKaiser, Jochen
dc.contributor.authorVitzthum, Alexander
dc.contributor.authorHolleczek, Peter
dc.contributor.authorDressler, Falko
dc.contributor.editorGöbel, Oliver
dc.contributor.editorSchadt, Dirk
dc.contributor.editorFrings, Sandra
dc.contributor.editorHase, Hardo
dc.contributor.editorGünther, Detlef
dc.contributor.editorNedon, Jens
dc.date.accessioned2019-06-04T08:24:21Z
dc.date.available2019-06-04T08:24:21Z
dc.date.issued2006
dc.description.abstractToday, many end systems are infected with malicious software (malware). Often, infections will last for a long time due to missing (auto- mated) detection or insufficient user knowledge. Even large organizations usually do not have the necessary security staff to handle all affected computers. Obviously, automated infections with malicious software cannot be handled by manual repair; new approaches are needed. One way to encounter automatic mass infections is to semi-automate the incident management. Less important security incidents should be handled by the user himself while serious incidents should be forwarded to qualified personal. To enable the end user resolving his own security incidents, both organizational and technical information have to be provided in a comprehensible way. This paper describes PRISM (Portal for Reporting Incidents and Solution Management), which consists of several components addressing the goal: a unit receiving security incidents in the IDMEF format, a component containing the logic for handling security incidents and corresponding remedies, and a component generating dynamic web pages presenting adequate solutions for recorded security incidents. PRISM was verified using case studies for universities, companies and end-user/provider scenarios.en
dc.identifier.isbn978-3-88579-191-1
dc.identifier.pissn1617-5468
dc.identifier.urihttps://dl.gi.de/handle/20.500.12116/23464
dc.language.isoen
dc.publisherGesellschaft für Informatik e. V.
dc.relation.ispartofIT-Incident Management & IT-Forensics - IMF 2006
dc.relation.ispartofseriesLecture Notes in Informatics (LNI) - Proceedings, Volume P-97
dc.subjectIncident Management
dc.subjectMalicious Software
dc.subjectMassive infections
dc.titleAutomated resolving of security incidents as a key mechanism to fight massive infections of malicious softwareen
dc.typeText/Conference Paper
gi.citation.endPage103
gi.citation.publisherPlaceBonn
gi.citation.startPage92
gi.conference.dateOctober, 18th - 19th, 2006
gi.conference.locationStuttgart
gi.conference.sessiontitleRegular Research Papers

Dateien

Originalbündel
1 - 1 von 1
Lade...
Vorschaubild
Name:
92.pdf
Größe:
328.36 KB
Format:
Adobe Portable Document Format