Introduction
Every organization irrespective how secure they are, there will be incidents occurring either internal or external. Planning for such incidents are vital. We will see life cycle which covers the responsibilities from identification to investigation and to mitigation.
Incident Response
Incident Response Lifecycle
- Preparation
- Detection and Analysis
- Containment, Eradication and Recovery
- Post Incident Activity
Incident Response Planning - Preparation
- Documentation
- Communication details and protocols
- Documentation for incident analysis
- Incident mitigation software
- Capture the data, including hardware and software to use later as evidence
- Policies while handling incidents
- Roles and Responsibilities:
- Incident Response Team - IRT, Cyber Incident Response Team - CIRT, SME plans and executes how to handle the intrusion. Trained team to handle the incidents for the entire cycle
- IT security management, precaution and post action measures such as firewalls
- Compliance officers, planning and communication
- Technical staff, helps in resolving
- Users, awareness and training
- Vendors, awareness and training
- Management, strategies
- Communications team, informing the press or infected parties
- Legal team, decides when the information needs to be shared
- CIO - Chief Information Officer, CISO - Chief Information Security Officer, mission, policies and decision making
- Exercise
- It is important to ensure effectiveness during an event or identify any deficiencies in the process that should be addressed.
- Mock runs without impacting production or any system, rehearsal.
- Functional exercises, run through actual drill as they would perform during actual emergency.
- Tabletop exercises as full drill would be time consuming and expensive, these would be in smaller simulated disaster version.
- Walk through, discuss and test processes, procedure from the tabletop exercise.
- Simulation, test the simulated event such as phishing attack
- Training, is critical to be given periodically to each teams based on their roles and responsibilities. Hence each roles and responsibilities needs to be clearing defined.
- Jump Kit
- As like first-aid, jump kit is prepared and available for immediate use of an incident.
- Communication
- Contact list needs to be update to date and accessible for everyone.
- Hardware and software for analysis and mitigation
- Secure storage facility
- Forensics workstations
- Portable printer
- Protocol analyzer
- Ancillary analysis resources
- Port lists
- Network diagrams
- Application architecture
- Continuity or Recovery Plans
- Disaster Recovery Plan
- To ensure full recovery of operational capacity following the natural disaster.
- Documentation, planning and periodic tests needs to be done.
- BCP or COOP - Continuity of operations planning
- Ensures the continuity of operations by restorations of an organization functions in the shortest time possible, even if the services resume at reduced level during emergency.
- COOP is similar to BCP but primarily focus on government and public sectors.
- Based on the incident either of the plan could be considered as part of recovery.
- Fundamentals of any disaster recovery plan involves backups.
- Retention Policies
- Backup of copies
- Regulatory compliance
- Operational needs
Attack Frameworks
- Cyber Kill Chain
- Lockheed Martin developed to defend its network based on chain of attacks made by the attacker.
- Cyber kill chain adopts this process in cyber security.
- The cyber kill chain has steps involved the attacker attacks the system from the beginning to end, as a security engineer one needs to break this chain as early as possible.
- Lockheed Martin's cyber kill chain attack from the attacker's perspective in general includes below stages:
- Reconnaissance: Identifying the target
- Weaponization: Preparing for the attack
- Delivery: Launching the attack
- Exploitation: Gaining access from the attack
- Installation: Establishing persistence
- Command and Control: Enabling remote control for further manipulation
- Actions: Achieving the goals
- In order to defend, we need to understand the attacker's actions.
- There are different tools and solutions used at each stage, to break the chain before the attack reaches the goal.
- MITRE ATT&CK
- MITRE ATT&CK - Adversarial Tactics, Techniques and Common Knowledge Framework was created by MITRE Non Profit Organization in 2013 to document attacker tactics and techniques based on real-world observations.
- The document continues to evolve providing the organization's incident response team to understand the attackers behaviour and plan ahead to mitigate these attacks.
- Diamond Model of Intrusion Analysis
- Another similar framework to describe cyber attacks.
- There are 4 parts giving a comprehensive view for cyber attacks.
- Adversary
- Details about the attacker, who, why or purpose of the attack
- Infrastructure
- Infected physical or logical systems or data leak details
- Capability
- Develop or deploy using the attack tools or techniques
- Target
- Affected area, data centre or country or region
- The model provides flexible framework to analyze the threat as cognitive (understand interrelated logic) and as well as mathematical(improves strategic).
Incident Detection
- Challenge
- It is difficult to identify an incident has occurred as there is huge volume of data and hard to detect legitimate threats.
- Incidents are complex extensive knowledge is needed.
- Precursor
- Sign that an incident might occur in future
- Logs or vulnerability scanners giving the heads up incident
- Network traffic deviate from normal flow
- Unauthorized host configuration change alerts
- Indicators
- Sign of incident has occurred or may be occurring
- Alarms from anti malware or anti virus software
- Alerts from intrusion detection/prevention system
- Exploit announcement
- Direct contact from the attackers reach for ransom
- Isolation and Containment
- Sandboxes, to avoid malware spreading over the network it has brought to isolation run the malware and analyze the results
- Malware are smart at times they run differently or destruct the running system if they are isolated or unable to connect to other systems in network.
- Recovery after Incident
- Removing the malware is important following one of the methods
- Restore from backups
- Rebuild from scratch
- Replace compromised files
- Disable breached user accounts and create new
- Tighten the system, such as
- Firewalls
- Enable Multi Factor Authentication
- Certificate changes
- Reconstitution
- Eradication means removing the element of the incident such as malware.
- Recovery is restore systems to normally functional operations.
- Not all the incidents requires eradication, for some only recovery but be good enough, and sometimes bother eradication and recovery needs to work hand in hand.
- Eradication and recovery should be done in phased approach as recovery may take time and it needs to be efficient.
- Documentation
- Lessons learnt from the incident needs to be captured with all the details along with time and to be improved over a period of time.
- Functional impact of the incident, categorization such high impact or low
- Information impact of the incident, type of impact on the information, eg: data leak of PII can be classified as data breach
- Recoverability from the incident
- Post incident analysis documentation for future prevention.
Investigations
Identify Vulnerability
![]() |
| Credit: https://docs.gitlab.com/ee/user/application_security/vulnerability_report/img/project_level_vulnerability_report_v14_5.png |
SIEM - Security Information and Event Management
Logging
- Network logs
- Switch logs
- Router logs
- Firewall logs
- DNS logs
- Operating system logs
- Application logs
- Web application logs
- Database logs
- Audit logs
- System logs
- Call Manager logs
- Bandwidth logs
- Security logs
- Access logs - requests and connections between systems
- Syslogs
- Transferring logs from one device to centralized database usually SIEM is called syslogs in Linux.
- Logs come with different severity levels - debug, information, warning, error or fatal, we can configure to capture based on the level. Log level warning is good for the production and debug for development environment.
- Daemons running syslog are:
- syslog - syslog message includes the facility code and the severity level. A facility code is used to specify the type of system that is logging the message. Messages with different facilities may be handled differently. Eg: 0 - kernel messages, 1 - user messages, 2 - mail messages.
- rsyslog - Rocket Fast System Log
- syslog-ng - Logging with filter
- nxlog - Multi operating system platform log collector
- Journalctl
- The journald daemon collects data from all available sources and stores them in a binary format for easy and dynamic manipulation.
- Journalctl command is used to view, search and filter the logs stored in the binary format.
- Metadata
- The data that describes other data sources. Will be useful while performing the incident analysis.
- Eg: for email we will have standard header storing the sending and destination address, in mobile having the gps locations, etc.
- Network Activity
- Netflow
- Gathers the traffic statistics from all the traffic flow in the entire network.
- IPFIX
- IP Flow Information Export, tracks the IP actions in the network
- IPFIX collects the data packets from across the network, organized by an Exporter which sends the compiled version to the Collector.
- IPFIX provides the flexibility by customizing the templates, these templates outlines the data the user wants to collect.
- Serves as industry standard for the export of flow information from network devices.
- sFlow
- Sampled Flow, used for monitoring high speed switched networks.
- Packet sampling in embedded technology is used to monitor network devices such switches, routers, wireless access points.
- Only the portion of the actual network traffic is captured, yet been found useful in getting the complete network visibility, for defence against security threats.
- Protocol analyser
- Able to analyse the traffic at packet level, several tools such as wireshark protocol analyser
Incident Mitigation
Approach
- Allow List
- Create a list of applications that are approved
- Allow only the approved applications to run on the endpoint
- Restrictive approach
- Deny List
- Maintain deny list of applications
- These list of applications will not be allowed to be executed on the endpoint
- Anti-virus and anti-malware behaves the same
- Quarantine
- Applications suspected to be malicious will not be allowed to run.
- It will move from that system and place it into a quarantine area, where no applications are allowed to run. This does not mean removing it or cleaning it, just in different area to avoid spread.
- Later security team can perform additional analysis on the suspected application and this will avoid its spread if proven malignant.
Criteria
- Application Hash: Execute only if hash of the executable matches on the system.
- Certificate: Execute only if the digital signature matches.
- Path: Limit permissions to certain folders, allowing to be executed only from certain folders. Eg: one may run an application with local rights and accessing only those certain folders. Here this cannot extend accessing the folders belongs to root or other users.
- Network zone: Set a policy that would allow or disallow an application to run based on the zone it is executing from. Eg: an application run in private area but prohibited to be executed in public zone.
Controls
- Firewalls
- Allow or deny application traversing in the network
- Block using rules such as ip address block or allow, zone wise allow or block
- MDM - Mobile Device Manager
- Have rules on the mobile devices that can allow or disallow access.
- These rules or polices can be configured using MDM and only security administrator can set or unset the policies
- DLP - Data Loss Prevention
- DLP identifies and blocks the transfer of any PII - Personally Identifiable Information.
- Eg: Credit card numbers, social security number, etc if it has been transferred outside will be blocked.
- Content filter/URL filter
- Restrict or allow only certain websites.
- Many of the these URL filters can also be integrated with third party blocklists.
- Blocklists can be updated constantly allowing real time blocking the malicious sites.
- Certificates
- Allow access from only trusted devices
- Deny the access if it does not have trusted certificate on that device
- Isolation
- Isolation is a process where a device or application is moved into an area where it has limited or no access to other resources.
- It is a key strategy while fighting against malicious software or software thats constantly trying to communicate back to a command and control location.
- Network Isolation
- Isolating device to a different network disabling the access to the rest of the network, when suspected malicious or not fully protected.
- No communication to other devices.
- Process Isolation
- When a process running on the device seems to be suspicious, we can disallow any access from that process to the rest of the network.
- This will limit application execution but allow device management.
- Containment
- Run each application in its own sandbox, limiting the interaction with the host operating system and other applications.
- Here it prevents the spread of malicious software to prevent from jumping outside of that application to infect the local machine or other devices in the network.
- Segmentation
- In general extensive security is created between the outside of the network and internal network. But once the malicious software enters inside network it is able to traverse freely without any concern of being blocked.
- To overcome this network administrators have started to create segmented networks within the network.
- Eg: Database is usually placed in a network where it can be accessed only from backend application. And web application servers can be accessed from internet but internally it can only interact with backend applications.
- SOAR - Security, Orchestration, Automation and Response
- As there are different and many controls needs to be taken care, it would be challenging and mistakes can occur if done manually.
- To automate these processes we need SOAR.
- Using SOAR, an admin can integrate multiple third party tools and have them all work together.
- Runbooks
- A runbook holds detailed steps on how to perform particular task
- Playbooks
- When a particular event occurs, a set of runbook together performed is called a playbook.









