Assessment System for Residual Risks of Information Leakage in Incident Countermeasures

Tomohiro Noda, Hirokazu Hasegawa, Hiroki Takakura · 2021

Recent targeted attacks make it difficult for us to protect our corporate resources. Therefore, we need to focus not on protecting against intrusion but on mitigating the intrusion. We previously propose a countermeasure support system, which recommends proper countermeasures against targeted attacks. However, this system does not take into account lateral movement from hosts where bridgeheads are established. In this paper, we propose a countermeasure assessment system based on residual risks of information leakage. This system calculates the risk of a host on the basis of network access control and host behavior. It also calculates the importance of resources in terms of access control that describes access of authorized personnel to file servers and the roles of the personnel. Using this information, this system analyzes the residual risks of information leakage after the countermeasure is applied and presents it to the network administrator. This system allows network administrators to choose countermeasures for incidents in terms of residual risks that cannot be covered with previous systems.

Read the paper · More papers on PaperTik