SECOPS 5: Event correlation and normalization Flashcards
Event data type for DHCP
Transaction
Event data type for DNS
Transaction
Event data type for AAA
Alert
Event data types for Netflow
Session, Statistical
Event data type for IPS
Alert. Some full packet capture
Event data types for Firewall
Session, pcap, Statistical
Event data types for Proxy (web/email)
Transaction, Extracted content
Event data type for Anti-Virus
Alerts, Extracted content
Direct Evidence
Does not require any reasoning to reach a conclusion
Circumstantial evidence
Requires inference linking the evidence to the conclusion
Indirect evidence
aka Circumstantial evidence
IPS alert evidence type
Direct
Best evidence
Eyewitness
4 Phases of forensics
Collection
Examination
Analysis
Reporting
Forensics collection
Identify, label, record, acquire