Method for cyberincidents network-centric monitoring in modern information & communication systems
Олександр Григорович Корченко, Віктор Олександрович Гнатюк, Євгенія Вікторівна Іванченко, Сергій Олександрович Гнатюк, Нургуль Абадуллаєвна Сєйлова · Ukrainian Information Security Research Journal · 2016
Information and communication technologies implementation in many spheres of social live is directed on business processes efficiency improving. However vulnerabilities and cyberthreats generate cyberincidents. New effective methods of detection, identifying, processing and investigation are necessary for localization and counteraction. One of approaches is network-centric concept oriented on counteraction to cyberincidents beginning and emergency recovery by network combining unique system of measures. Based on this concept in the paper method for cyberincidents network-centric monitoring that realizes using 8 stages: cyberattack classification; cyberattack type detection; cyberincident categorization; forming of rules plurality for cyberincident extrapolation; security objects defining; cyberincident influence defining on information and communication systems components; most criticality components defining in information and communication systems; cyberincident danger level rating. This method allows to define most important security objects and also forecast cyberincidents categories resulted from cyberat-tacks and danger level (criticality). Besides this method and instrumentations based on it can be useful for cyberincidents response teams CERT / CSIRT to process cyberincidents (in particular dispatching) and response. As well as departments that assign functions to secure information and communication systems both in company and state.