Investigating cybersecurity incidents requires in-depth knowledge from the analyst. Moreover, the whole process is demanding due to the vast data volumes that need to be analyzed. While various techniques exist nowadays to help with particular tasks of the analysis, the process as a whole still requires a lot of manual activities and expert skills. We propose an approach that allows the analysis of disk snapshots more efficiently and with lower demands on expert knowledge. Following a user-centered design methodology, we implemented an analytical tool to guide analysts during security incident investigations. The viability of the solution was validated by an evaluation conducted with members of different security teams.
翻译:调查网络安全事件需要分析员深入了解。此外,整个过程要求很高,因为需要分析大量数据。虽然现在存在各种技术来帮助完成分析的特定任务,但整个过程仍然需要大量的手工活动和专家技能。我们提议一种方法,可以更有效地分析磁盘快照,减少对专家知识的需求。我们采用以用户为中心的设计方法,采用了分析工具,在安全事件调查期间指导分析员。与不同安全小组成员进行的评估证实了解决方案的可行性。