2

How to prepare for and respond to a SolarWinds-type attack

 3 years ago
source link: https://www.csoonline.com/article/3602588/how-to-prepare-for-and-respond-to-a-solarwinds-type-attack.html
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

How to prepare for and respond to a SolarWinds-type attack

If you can perform these tasks on your Windows network, then you are properly prepared to respond to a nation-state attack like SolarWinds.

By Susan Bradley

Contributing Writer,

CSO | Jan 6, 2021 2:00 am PST

If you use the recently compromised SolarWinds Orion monitoring products, you are already reviewing your infrastructure and possibly blocking network access to the servers in your domain. For those of you who do not use the SolarWinds software, this is an opportunity to review your own processes and determine whether you would have detected the compromised code and backdoors.

The instructions for mitigating the SolarWinds compromise, provided by the US Cybersecurity and Infrastructure Security Agency (CISA), are a good example of the process required to identify and remove sophisticated advanced persistent threats (APTs), even those executed by nation-states. If you can perform these steps, then you’re in a good position to respond properly if the need arises.

Create a forensic image

First, determine if you could forensically image all suspected devices in your network. Forensic imaging creates an exact copy (including the empty space) of a server’s or workstation’s hard drive. Access Data FTK Imager is one such product that allows you to take a complete backup of a system to deem whether it’s forensically sound. It generates hash reports for regular files and disk images to ensure that you have an exact copy of the drive.

Volume 0%
Loading ad

To continue reading this article register now

Learn More   Existing Users Sign In


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK