Model-Based Incident Response Playbooks

Avi Shaked*, Yulia Cherdantseva, Pete Burnap

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Inevitably, all systems are vulnerable, and none are impervious to attack. Incident response is an important element in maintaining the cyber security posture of organizations. Incident response practitioners often rely on process descriptions in the form of playbooks as recipes for handling incidents as they occur. However, current practices and mechanisms do not offer a disciplined approach to designing and representing playbooks, risking the effectiveness of the playbooks in directing and coordinating incident response. In this paper, we propose a formal, model-based design approach to designing cyber security incident response playbooks. We provide a tool prototype for the approach, developed using the Eclipse framework, and demonstrate how it can accommodate playbooks. Finally, we discuss how the approach can improve aspects of incident response throughout its lifecycle, by correctly prescribing and coordinating response actions as well as supporting organizational learning.

Original languageEnglish
Title of host publicationProceedings of the 17th International Conference on Availability, Reliability and Security, ARES 2022
PublisherAssociation for Computing Machinery
ISBN (Electronic)9781450396707
DOIs
StatePublished - 23 Aug 2022
Externally publishedYes
Event17th International Conference on Availability, Reliability and Security, ARES 2022 - Vienna, Austria
Duration: 23 Aug 202226 Aug 2022

Publication series

NameACM International Conference Proceeding Series

Conference

Conference17th International Conference on Availability, Reliability and Security, ARES 2022
Country/TerritoryAustria
CityVienna
Period23/08/2226/08/22

Keywords

  • Cyber Security
  • Incident Response
  • Metamodeling
  • Model-based Design
  • Playbooks
  • Process Models

Fingerprint

Dive into the research topics of 'Model-Based Incident Response Playbooks'. Together they form a unique fingerprint.

Cite this