Dr Anton Chuvakin Blog (Original)

Security writing since the mid-2000s. New posts are mirrored from Anton on Security on Medium.

Processes for Network Forensics

Historical Archive Note: This post was originally published on the Gartner Blog Network on February 15, 2013 by Anton Chuvakin.
Original URL: http://blogs.gartner.com/anton-chuvakin/2013/02/15/processes-for-network-forensics/ | Archive.org Snapshot

Just as I did with SIEM and DLP, I wanted to explore the process (practice, procedure, workflow) side of network forensics tooling. So, my question is the same: what processes/practices are absolutely essential for an effective use of a network forensics tool?

I can think of a few off the top of my head:

  1. incident response process (and, yes, I cringe as I am writing this as it is so painfully obvious)
  2. indicator analysis process which essentially means investigating a clue reported by a 3rd party, logs, NIPS alerts, etc
  3. process for defining and refining capture policies
  4. process for defining and refining detection alerts (if the tools is utilized for monitoring)
  5. data exploration process aimed at understanding what is going on, was going on, which  may be based on a threat hypothesis or other suspicions (see additional details on this here)

Other ideas!? Do you think #5 is the same as #2 perhaps?

P.S. BTW, check out this great piece called “The Security Processes You Must Get Right.”

P.P.S. While we are on the subject of network forensics, check out this excellent piece by a true network forensics literati.

Related posts: