DocumentCode
3700101
Title
Approaches to improve the activity of computer incident response teams
Author
Andrii Gizun;Viktor Gnatyuk;Nadiia Balyk;Pawel Falat
Author_Institution
National Aviation University, 1 Kosmonavta Komarova Ave, 03680 Kyiv, Ukraine
Volume
1
fYear
2015
Firstpage
442
Lastpage
447
Abstract
Today incident detection mechanisms, that define CERT / CSIRT effectiveness, based mostly on two principles - signature and heuristic. Their disadvantage is that they are focused on mathematical models, which require a lot of time to prepare statistics and so it decreases CERT/CSIRT efficiency. In this work, we have proposed approaches to ensure CERT / CSIRT high efficiency and its evaluation. To detect incidents we suggest using mathematical models based on expert´s estimations. The proposed method allows solving the problem of incident detection and its identification based on expert judgments in fuzzy conditions. To estimate CERT / CSIRT effectiveness was introduce baselines. It enabled to determine CERT / CSIRT effectiveness during the necessary period. The report by the following parameters should be carried out regularly to get the full picture of their changes and identify the main trend.
Keywords
"Standards","Security","Pragmatics","Fuzzy logic","Computers","Servers","Mathematical model"
Publisher
ieee
Conference_Titel
Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications (IDAACS), 2015 IEEE 8th International Conference on
Print_ISBN
978-1-4673-8359-2
Type
conf
DOI
10.1109/IDAACS.2015.7340775
Filename
7340775
Link To Document