Intrusion Notification - PowerPoint PPT Presentation

1 / 7
About This Presentation
Title:

Intrusion Notification

Description:

Symantec (Security Response and Deep Sight) SANS. US-CERT ... Symantec. SANS. US-CERT. MS-ISAC Multi-State Information Sharing and Analysis Center ... – PowerPoint PPT presentation

Number of Views:84
Avg rating:3.0/5.0
Slides: 8
Provided by: tguer
Category:

less

Transcript and Presenter's Notes

Title: Intrusion Notification


1
Intrusion Notification Detection Procedures
2
Tim Guerriero
  • Commonhelp / Operations
  • Security Lead
  • 617-660-8304
  • Tim.Guerriero_at_state.ma.us

3
Notification of New Virus or Vulnerability
  • When New Vulnerabilities come out and New High
    threats are announced
  • Commonhelp will send a notification out to MAGNet
    Users immediately using Email and the Mass Alert
    Network (MAN)
  • Message Identifying the virus or vulnerability
  • What the name is
  • Severity
  • Source used to identify
  • Symantec (Security Response and Deep Sight)
  • SANS
  • US-CERT
  • MS-ISAC Multi-State Information Sharing and
    Analysis Center
  • Microsoft Security
  • Systems affected (Operating Systems,
    Applications)
  • Description
  • Impact
  • Recommendations

4
Abnormal Activity On Your Network
  • Computers Being Locked Up or Locked Out
  • Emails from People you dont know with strange
    files
  • An Attack On Your Internal Network

5
Intrusion Detection Procedures
  • Once an infection is noticed inside MAGNet
  • ITD will Confirm what the virus or vulnerability
    is
  • Commonhelp will send a notification out to MAGNet
    Users immediately using Email and the Mass Alert
    Network (MAN)
  • Message Identifying the virus or vulnerability
  • What the name is
  • Severity
  • Source used to identify
  • Symantec
  • SANS
  • US-CERT
  • MS-ISAC Multi-State Information Sharing and
    Analysis Center
  • Microsoft Security
  • Systems affected (Operating Systems,
    Applications)
  • Description
  • Impact
  • Recommendations

6
Procedures for ITD
  • Once a threat inside MAGNet is Identified a
    Conference call between all the vital groups is
    immediately called to discuss action items for
    the threat
  • Stop infected host or Servers from infecting
    other agencies, immediate removal
  • Solution on how to fix infected machines
  • Decide timeframe from when the infection is
    detected till action is taken
  • Action Taken
  • Access List to the infected ports
  • WAN Disconnection
  • Enabling infected machines
  • Get approval to Scan Network
  • Scan Network
  • Verified Clean

7
Commonhelp
  • 1-866-888-2808 option 5
  • commhelp_at_state.ma.us
Write a Comment
User Comments (0)
About PowerShow.com