SECOPS 5: Event correlation and normalization Flashcards

1
Q

Event data type for DHCP

A

Transaction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Event data type for DNS

A

Transaction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Event data type for AAA

A

Alert

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Event data types for Netflow

A

Session, Statistical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Event data type for IPS

A

Alert. Some full packet capture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Event data types for Firewall

A

Session, pcap, Statistical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Event data types for Proxy (web/email)

A

Transaction, Extracted content

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Event data type for Anti-Virus

A

Alerts, Extracted content

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Direct Evidence

A

Does not require any reasoning to reach a conclusion

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Circumstantial evidence

A

Requires inference linking the evidence to the conclusion

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Indirect evidence

A

aka Circumstantial evidence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

IPS alert evidence type

A

Direct

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Best evidence

A

Eyewitness

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

4 Phases of forensics

A

Collection
Examination
Analysis
Reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Forensics collection

A

Identify, label, record, acquire

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Forensics examination

A

Forensically processing data to extract data of interest.

17
Q

Forensic analysis

A

Analyze the results of the examination

18
Q

Forensic reporting

A

Report results of the analysis.

Describes actions performed. How tools were chosen, further actions to take, recommendations for improvement.

19
Q

Normalization

A

Manipulating event data to fit into a common schema

20
Q

Correlation

A

Recognizing that two or more events are related

21
Q

Aggregation

A

More or less, searching

22
Q

Summarization

A

Graphic or tabular summary of data

23
Q

Deduplication

A

Present all details in a concise format. Must be normalized first.