Foreword
Preface
1. What Is Incident Response?
Real-Life Incidents
What Is an Incident?
About the Bad Guys
What Is Incident Response?
Risk Assessment and Incident Response
Development of Incident Response Efforts
Are You Ready? Are You Willing?
2. Incident Response Teams
Who Should Do It?
Public Resource Teams
Internal Teams
Commercial Teams
Vendor Teams
Ad Hoc Teams
Forum of Incident Response and Security Teams (FIRST)
Now Who Should Do It?
3. Planning the Incident Response Program
Establishing the Incident Response Program
Internal Versus External
Types of Incidents
Who Are the Clients?
Summary
4. Mission and Capabilities
Roles and Responsibilities
Staffing and Training
Involving the Critical Players
List of Contacts
Setting Up a Hotline
Establishing Procedures
Awareness and Advertising
Fire Drills
Issues and Pitfalls
5. State of the Hack
The Moving Target
Keeping Up with Attack Profiles
Training
6. Incident Response Operations
We've Been Hit-Now What?
Incident Response Processes
While Under Pressure
7. Tools of the Trade
What's Out There?
Network-Based Tools
Network Monitors and Protocol Analyzers
Network-Based Intrusion Detection Systems
Network Vulnerability Scanners
Other Essential Network-Based Tools
Host-Based Tools
Communications
Encryption
Removable Storage Media
The Incident Kit
If We Ruled the World
8. Resources
Security Information on the Web
Incident Response Team Resources
Commercial Incident Response Service Providers
Antivirus Products
Mailing Lists and Newsgroups
U.S. Government Resources
Training, Conferences, and Certification Programs
Legal Resources
A. FIRST
B. Sample Incident Report
Index