网络安全事件处理系统及其应用实践
IHS and Application
摘要 计算机安全事件响应小组面对繁杂的各类事件报告和事件处理流程,往往容易出现应急服务规范难于保障、很多事件无法跟踪到底、处理事件的记录和有关文档事后查找困难、处理的事件难以统计等一系列问题。为了有效解决这些问题,“网络安全事件处理系统”的需求应运而生。主要介绍“网络安全事件处理系统(IHS)”,以及CNCERT/CC在事件处理过程中的应用实践。
关键词 网络安全 网络安全事件处理系统 计算机安全事件响应小组
Abstract:CSIRTs(Computer Security Incident Response Team)usually face lots of incident
reports and complicated incident handling procedures.As a result,there would be difficulty
in guaranteeing service standards, tracking incidents, seeking relevant documents, and
doing accurate statistics. Incident handling system (IHS) is designed to solve those
problems. This article mainly introduces IHS and the related practice of CNCERT/CC.
Keywords: computer security; incident handling system; CSIRT