Incident Response Support System for Multi-Located Network by Correlation Analysis of Individual Events
Masahito Kumazaki, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura · 2021
Recent targeted attacks have affected large networks, including those made up of multiple locations. Since branch offices are less secure than the headquarters (HQ), it is difficult to completely prevent malware from entering the network through these attacks. Therefore, it is important to quickly detect and respond to these attacks to prevent them from spreading to other locations. However, under the current management system, managers at each site must respond to incidents without sharing information from other sites, and the manager at the HQ cannot obtain enough information to estimate the relationship between the incidents. We propose a management system that refers to all of incident information archived by the organization, generates recommendations on the basis of the similarity between the ongoing incident and archived ones, and notifies each administrator to respond to the incident that occurred in his/her network regardless of resolved or unresolved incidents. The proposed system also notifies the administrators at HQ of the entirety of the attack on the basis of the relationship among recent and ongoing incidents.