• DocumentCode
    3700101
  • Title

    Approaches to improve the activity of computer incident response teams

  • Author

    Andrii Gizun;Viktor Gnatyuk;Nadiia Balyk;Pawel Falat

  • Author_Institution
    National Aviation University, 1 Kosmonavta Komarova Ave, 03680 Kyiv, Ukraine
  • Volume
    1
  • fYear
    2015
  • Firstpage
    442
  • Lastpage
    447
  • Abstract
    Today incident detection mechanisms, that define CERT / CSIRT effectiveness, based mostly on two principles - signature and heuristic. Their disadvantage is that they are focused on mathematical models, which require a lot of time to prepare statistics and so it decreases CERT/CSIRT efficiency. In this work, we have proposed approaches to ensure CERT / CSIRT high efficiency and its evaluation. To detect incidents we suggest using mathematical models based on expert´s estimations. The proposed method allows solving the problem of incident detection and its identification based on expert judgments in fuzzy conditions. To estimate CERT / CSIRT effectiveness was introduce baselines. It enabled to determine CERT / CSIRT effectiveness during the necessary period. The report by the following parameters should be carried out regularly to get the full picture of their changes and identify the main trend.
  • Keywords
    "Standards","Security","Pragmatics","Fuzzy logic","Computers","Servers","Mathematical model"
  • Publisher
    ieee
  • Conference_Titel
    Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications (IDAACS), 2015 IEEE 8th International Conference on
  • Print_ISBN
    978-1-4673-8359-2
  • Type

    conf

  • DOI
    10.1109/IDAACS.2015.7340775
  • Filename
    7340775