研究生(外文):Bon-Yen Liaw
論文名稱(外文):The study of incident response in Taiwan
外文關鍵詞:computer securitysecurity incidentscomputer security incident response teamInternet
隨著網路的使用不斷的增加, 電腦系統不再是獨立分開的系統,相反的、在這資訊科技高度發展的數十年中,隨著系統與系統之間連接不斷增加,電腦之間的計算能力、設備、資源都在一個高度共享的環境中。 然而、危險也隨之而來。自從1988年以來所發生的第一個電腦病毒(Morris Worm)以來,大眾便了解到電腦網路實際是處在一個危險的環境之中。隨著安全事件不斷大量而且快速的在世界各地增加,很多國家陸續成立了很多組織以解決、了解這些問題。

台灣電腦危機處理/協調中心(TWCERT/CC ,Taiwan Computer Emergency Response Team/ Coordination Center)是其中的一個在這樣的情況下所產生的單位。台灣電腦危機處理/協調中心成立的主要宗旨是在讓一般民眾了解並警覺到電腦網路危安事件、回覆處理或者協調來自國內外的安全事件、監控台灣的網路安全環境並在必要的時候發布安全通報以減輕病毒等特殊安全事件對台灣造成的影響。
Due to the enlargement of the use of Internet, computers are no longer separated systems. On the contrary, the frequency of sharing between computers’ computing abilities, devices, and resources is surprisingly high in the last few decades. This situation makes people have a more convenient network situation. However, dangers also come along. Ever since the event occurred in 1988, the first computer worm (Morris Worm) makes people be aware of this issue. The computer network world has becoming an environment contains many potential dangers. Whereas the computer security incidents are increasing dramatically, many countries have established some specific organizations to solve these problems.

TWCERT/CC (Taiwan Computer Emergency Response Team/ Coordination Center) is one of these organizations. The utilities of TWCERT/CC are to help people be aware of computer network dangers, to make responses and coordinate the security incidents inside and outside Taiwan, and to supervise the security circumstances in Taiwan and to announce alerts or take proper actions when the situation is serious.

Responding and coordinating those incidents in TWCERT/CC is one crucial everyday job which requires a very complicated procedure. However, without a systematic method to handle the security incidents would be a heavy load for a computer security incident response team. This research is to develop a systematic method and procedure to handle incident and a system can implement this procedure. The goal is to shorten the processing time of incidents and enhance the accuracy of handling incidents, and to analyze the data collected from the system to get useful information.
1.1. The networked environment------------------------------------------------------------1
1.2. The threats to the network--------------------------------------------------------------4
1.3. The Computer Emergency Response Team/ Coordination Center ---------------8
1.4. Motivation of this research------------------------------------------------------------10
1.5. Research Method and steps-----------------------------------------------------------11

2.Related studies--------------------------------------------------------------------------------13
2.1. The classification of attacks-----------------------------------------------------------13
2.2. Incident and Incident reports----------------------------------------------------------14
2.2.1. Incident classification---------------------------------------------------------------------------------15
2.2.2. Incident response---------------------------------------------------------------------------------------18
2.2.3. IR services----------------------------------------------------------------------------------------------19
2.2.4. Comparing the paradigm functions with functions provided by TWCERT/CC-------------20
2.3. Incidents versus attacks----------------------------------------------------------------21
2.4. The incidents people concerned mostly about--------------------------------------22
2.5. Automation of incident response/incident report ----------------------------------25

3.Research design------------------------------------------------------------------------------30
3.1. Research outline-----------------------------------------------------------------------30
3.2. System testing--------------------------------------------------------------------------35

4.Research Results-----------------------------------------------------------------------------40
4.1. Case study-------------------------------------------------------------------------------40
4.2. Statistic data from research-----------------------------------------------------------42

5.Conclusions and Future study--------------------------------------------------------------51
5.1. Conclusions-----------------------------------------------------------------------------51
5.2. Future study-----------------------------------------------------------------------------52

6. References------------------------------------------------------------------------------------53
