<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - incident-response</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/incident-response/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2013-10-18T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/incident-response/atom.xml</id>
    <entry xml:lang="en">
        <title>DDoS Survival</title>
        <published>2013-10-18T00:00:00+00:00</published>
        <updated>2013-10-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/ddos-survival-isc2tc/"/>
        <id>https://blog.itys.net/vol1/posts/ddos-survival-isc2tc/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/ddos-survival-isc2tc/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;Matthew J. Harmon and Phil Reno present at the (ISC)2 Twin Cities Area Chapter
on DDoS Survival, delivered on October 18, 2013, provides a comprehensive primer
on Distributed Denial of Service (DDoS) attacks and how organizations can
withstand and mitigate them. It begins by defining DDoS as resource exhaustion
aimed at disrupting servicesand tracing its roots from IRC-driven pranks to
sophisticated protest and extortion campaigns.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;threats-and-attack-techniques&quot;&gt;Threats and Attack Techniques&lt;&#x2F;h2&gt;
&lt;p&gt;The first section surveys real-world threats and attack techniques. The
presenters highlight notable incidents such as Anonymous&#x2F;AntiSec campaigns and
itsoknoproblembro browser-based botnets and reference data on rising attack
volumes from sources like Arbor Networks. They categorize attack vectors across
the OSI stack (TCP&#x2F;SSL floods, HTTP-level assaults like Slowloris and
chunked-header exploits, and ICMP&#x2F;UDP floods) and assess attacker skill levels,
from low-effort LOIC&#x2F;XOIC scripts to more advanced injection-driven browser
botnets.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;defense-and-resilience&quot;&gt;Defense and Resilience&lt;&#x2F;h2&gt;
&lt;p&gt;The second section focuses on defense and resilience strategies. Harmon and Reno
outline four architectural approaches: ISP-level scrubbing, Cloud SOC via
proxy&#x2F;DNS redirection, full-service cloud scrubbing with BGP rerouting, and
in-house solutions. Detailing the pros and cons of each. They emphasize risk
transference through CDNs and anti-DDoS services, null-routing tactics, and
bigger pipes, supplemented by application-level tweaks. The presentation
concludes with guidance on selecting providers (key questions on SLAs,
mitigation capabilities, and cost structures), proactive load testing, and
leveraging automation tools (Chef, Puppet, Ansible, SaltStack, Fabric) to scale
and verify infrastructure readiness under attack.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;56583_2013-10-18_DDoS_Survival-ISC2TC.pdf&quot;&gt;DDoS Survival&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Incident Handling, Forensics and Hacking Techniques</title>
        <published>2011-10-19T00:00:00+00:00</published>
        <updated>2011-10-19T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/incident-handling-mncia/"/>
        <id>https://blog.itys.net/vol1/posts/incident-handling-mncia/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/incident-handling-mncia/">&lt;p&gt;The SANS Incident Handling &amp;amp; Forensics presentation by Matthew J. Harmon
provides a comprehensive overview of how organizations should prepare for,
respond to, and learn from security incidents. Drawing on industry best
practices and real-world examples, it emphasizes the importance of structured
processes, clear communication, and rigorous evidence handling to minimize
damage and restore operations promptly.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;incident-response&quot;&gt;Incident Response&lt;&#x2F;h2&gt;
&lt;p&gt;First, the talk lays out the six core phases of incident response: Preparation,
Identification, Containment, Eradication, Recovery, and Lessons Learneddetailing
the goals and key actions at each stage. Core principles such as work in pairs,
maintain a strict chain of custody, never operate on original data, and enforce
a need-to-know policy are reinforced throughout. These guidelines ensure that
responders act methodically, take comprehensive notes, and prevent further
compromise while preserving forensic integrity.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;techniques-and-toolkits&quot;&gt;Techniques and Toolkits&lt;&#x2F;h2&gt;
&lt;p&gt;Second, the presentation transitions to practical techniques and toolkits. It
introduces the SANS Investigative Forensic Toolkit (SIFT) and offensive-focused
distributions like BackTrack for evidence acquisition and analysis. Step-by-step
procedures cover documenting the scene, identifying and preserving data sources
(from servers and workstations to mobile devices), performing bit-by-bit
imaging, and analyzing logs and memory. Finally, it underscores the need to
produce clear, audience-appropriate reportswhether for corporate management,
legal teams, or law enforcementto drive improvements and policy changes
post-incident.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;55853_2011-10-19_Incident_Handling_Forensics_and_Hacking_Techniques-MNCIA.pdf&quot;&gt;Minnesota High Tech Crime Investigators
Association&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
