SECOPS 5: Event correlation and normalization Flashcards
Event data type for DHCP
Transaction
Event data type for DNS
Transaction
Event data type for AAA
Alert
Event data types for Netflow
Session, Statistical
Event data type for IPS
Alert. Some full packet capture
Event data types for Firewall
Session, pcap, Statistical
Event data types for Proxy (web/email)
Transaction, Extracted content
Event data type for Anti-Virus
Alerts, Extracted content
Direct Evidence
Does not require any reasoning to reach a conclusion
Circumstantial evidence
Requires inference linking the evidence to the conclusion
Indirect evidence
aka Circumstantial evidence
IPS alert evidence type
Direct
Best evidence
Eyewitness
4 Phases of forensics
Collection
Examination
Analysis
Reporting
Forensics collection
Identify, label, record, acquire
Forensics examination
Forensically processing data to extract data of interest.
Forensic analysis
Analyze the results of the examination
Forensic reporting
Report results of the analysis.
Describes actions performed. How tools were chosen, further actions to take, recommendations for improvement.
Normalization
Manipulating event data to fit into a common schema
Correlation
Recognizing that two or more events are related
Aggregation
More or less, searching
Summarization
Graphic or tabular summary of data
Deduplication
Present all details in a concise format. Must be normalized first.