- Cybersecurity:Attack and Defense Strategies
- Yuri Diogenes Erdal Ozkaya
- 139字
- 2021-06-30 19:15:50
Best practices to optimize incident handling
You can't determine what's abnormal if you don't know what's normal. In other words, if a user opens a new incident saying that the server's performance is slow, you must know all the variables before you jump to a conclusion. To know if the server is slow, you must first know what's considered to be a normal speed. This also applies to networks, appliances, and other devices. To mitigate scenarios like this, make sure you have the following in place:
- System profile
- Network profile/baseline
- Log-retention policy
- Clock synchronization across all systems
Based on this, you will be able to establish what's normal across all systems and networks. This will be very useful when an incident occurs and you need to determine what's normal before starting to troubleshoot the issue from a security perspective.
推薦閱讀
- Windows Server 2012 Hyper-V:Deploying the Hyper-V Enterprise Server Virtualization Platform
- 每天5分鐘玩轉Kubernetes
- Linux從零開始學(視頻教學版)
- 玩到極致 iPhone 4S完全攻略
- 循序漸進學Docker
- Instant Optimizing Embedded Systems using Busybox
- 奔跑吧 Linux內核(入門篇)
- Linux運維最佳實踐
- Linux系統安全基礎:二進制代碼安全性分析基礎與實踐
- Linux內核觀測技術BPF
- 完美應用RHEL 8
- 注冊表應用完全DIY
- 計算機系統的自主設計
- Linux軟件管理平臺設計與實現
- Linux應用大全 基礎與管理