{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,28]],"date-time":"2025-09-28T20:25:32Z","timestamp":1759091132174,"version":"3.41.2"},"reference-count":25,"publisher":"Emerald","issue":"3","license":[{"start":{"date-parts":[[2007,6,12]],"date-time":"2007-06-12T00:00:00Z","timestamp":1181606400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2007,6,12]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-heading\">Purpose<\/jats:title><jats:p>Security information management systems (SIMs) have been providing a unified distributed platform for the efficient management of security information produced by corresponding mechanisms within an organization. However, these systems currently lack the capability of producing and enforcing response policies, mainly due to their limited incident response (IR) functionality. This paper explores the nature of SIMs while proposing a set of requirements that could be satisfied by SIMs for the efficient and effective handling of security incidents.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title><jats:p>These requirements are presented in a high\u2010level architectural concept and include policy visualization, system intelligence to enable automated policy management, as well as, data mining elements for inspection, evaluation and enhancements of IR policies.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Findings<\/jats:title><jats:p>A primitive mechanism that could guarantee the freshness and accuracy of state information that SIMs provide in order to launch solid response alarms and actions for a specific incident or a series of incidents is proposed, along with a role based access control administrative model (ARBAC) based on a corporate model for IR. Basic forensic and trace\u2010back concepts that should be integrated into SIMs in order to provide the rich picture of the IR puzzle are also examined.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Practical implications<\/jats:title><jats:p>The support of policy compliance and validation tools to SIMs is also addressed.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title><jats:p>The aforementioned properties could greatly assist in automating the IR capability within an organization.<\/jats:p><\/jats:sec>","DOI":"10.1108\/09685220710759568","type":"journal-article","created":{"date-parts":[[2007,6,19]],"date-time":"2007-06-19T10:55:10Z","timestamp":1182250510000},"page":"226-240","source":"Crossref","is-referenced-by-count":4,"title":["Incident response requirements for distributed security information management systems"],"prefix":"10.1108","volume":"15","author":[{"given":"Sarandis","family":"Mitropoulos","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dimitrios","family":"Patsos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christos","family":"Douligeris","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"key2022020419514897600_b1","unstructured":"Aberdeen Group (2003), \u201cTurning IT security into effective business risk management\u201d, An Executive White Paper, available at: www.ca.com."},{"key":"key2022020419514897600_b2","doi-asserted-by":"crossref","unstructured":"Arvidsson, J., Cormack, A., Demchenko, Y. and Meijer, J. (2001), \u201cTERENA's incident object description and exchange format requirements\u201d, RFC 3067, available at: www.ietf.org.","DOI":"10.17487\/rfc3067"},{"key":"key2022020419514897600_b3","unstructured":"BSI (1999), Information Security Management, BS7799, Part 1: Code of Practice for Information Security Management, BSI, Bonn."},{"key":"key2022020419514897600_b4","unstructured":"CERT Advisory CA\u20102001\u201026 (2001), Nimda Worm, available at: www.cert.org."},{"key":"key2022020419514897600_b5","unstructured":"Chien, E. and Sz\u00f6r, P. (2002), \u201cBlended attacks exploits, vulnerabilities and buffer\u2010overflow techniques in computer viruses\u201d, paper presented at Virus Bulletin Conference, New Orleans, LA, September."},{"key":"key2022020419514897600_b6","doi-asserted-by":"crossref","unstructured":"Chuvakin, A. (2004), \u201cSecurity event analysis through correlation\u201d, Information Systems Security, Vol. 13 No. 2, pp. 13\u201018.","DOI":"10.1201\/1086\/44312.13.2.20040501\/81648.3"},{"key":"key2022020419514897600_b7","doi-asserted-by":"crossref","unstructured":"Damianou, N., Dulay, N., Lupu, E. and Sloman, M. (2001), \u201cThe ponder policy specification language\u201d, Proceedings of Policy 2001: Workshop on Policies for Distributed Systems and Networks, Bristol, Volume 1995 of Lecture Notes in Computer Science.","DOI":"10.1007\/3-540-44569-2_2"},{"key":"key2022020419514897600_b8","unstructured":"Debar, H., Curry, D. and Feinstein, B. (2005), \u201cThe intrusion detection message exchange format (IDMEF), (internet\u2010draft)\u201d, available at: www.ietf.org."},{"key":"key2022020419514897600_b9","doi-asserted-by":"crossref","unstructured":"Eckmann, S., Vigna, G. and Kemmerer, R. (2002), \u201cSTATL: an attack language for state\u2010based intrusion detection\u201d, Journal of Computer Security, Vol. 10 Nos 1\/2, pp. 71\u2010104.","DOI":"10.3233\/JCS-2002-101-204"},{"key":"key2022020419514897600_b10","unstructured":"Feiertag, R., Kahn, C., Porras, P., Schnackenberg, D., Staniford\u2010Chen, S. and Tung, B. (1999), \u201cA common intrusion specification language\u201d, available at: http:\/\/people.emich.edu\/pstephen\/."},{"key":"key2022020419514897600_b11","doi-asserted-by":"crossref","unstructured":"Ferraiolo, D.F. et al. (2001), \u201cProposed NIST standard for role\u2010based access control\u201d, ACM Transactions on Information and System Security, Vol. 4 No. 3, pp. 224\u201074.","DOI":"10.1145\/501978.501980"},{"key":"key2022020419514897600_b12","unstructured":"Gula, R. (2005), \u201cCorrelating IDS alerts with vulnerability information\u201d, White paper, Tenable Network Security, available at: www.tenablesecurity.com."},{"key":"key2022020419514897600_b13","unstructured":"Hansman, S. (2003) A Taxonomy of Network and Computer Attack Methodologies, technical report, Department of Computer Science and Software Engineering, University of Canterbury, Christchurch."},{"key":"key2022020419514897600_b14","unstructured":"IETF (1992), Request for Comments (RFC) 1305, Network Time Protocol (Version 3) \u2013 Specification, Implementation and Analysis, available at: www.ietf.org."},{"key":"key2022020419514897600_b15","unstructured":"ISO (1995), ISO\/IEC JTC1\/SC21, Basic Reference Model of Open Distributed Processing, Part 2: Descriptive Model, ITU\u2010T X.903\u2010ISO\/IEC 10746\u20103, ISO, Geneva."},{"key":"key2022020419514897600_b16","doi-asserted-by":"crossref","unstructured":"Krugel, C., Toth, T. and Kerer, C. (2001), \u201cDecentralized event correlation for intrusion detection\u201d, Proceedings of Information Security and Cryptology, Volume 2288 of Lecture Notes in Computer Science.","DOI":"10.1007\/3-540-45861-1_10"},{"key":"key2022020419514897600_b17","unstructured":"Kruse, W. and Heiser, J. (2002), Computer Forensics, Addison\u2010Wesley, Ontario."},{"key":"key2022020419514897600_b18","doi-asserted-by":"crossref","unstructured":"Kuznetsov, V., Simkin, A. and Sandstr\u00f6m, H. (2002), \u201cAn evaluation of different IP trace\u2010back approaches\u201d, Proceedings of Information and Communications Security: 4th International Conference, ICICS 2002, Singapore, Volume 2513 of Lecture Notes in Computer Science.","DOI":"10.1007\/3-540-36159-6_4"},{"key":"key2022020419514897600_b19","doi-asserted-by":"crossref","unstructured":"Lupu, E. and Sloman, M. (1997), \u201cTowards a role based framework for distributed systems management\u201d, Journal of Network and Systems Management, Vol. 5 No. 1, pp. 5\u201030.","DOI":"10.1023\/A:1018742004992"},{"key":"key2022020419514897600_b21","unstructured":"Mitropoulos, S., Patsos, D. and Douligeris, C. (2005), \u201cNetwork forensics: towards a classification of trace\u2010back mechanisms\u201d, Proceedings of Security and Privacy for Emerging Areas in Communication Networks, Workshop of the 1st International Conference on Network Forensics, Athens."},{"key":"key2022020419514897600_b20","doi-asserted-by":"crossref","unstructured":"Mitropoulos, S., Patsos, D. and Douligeris, C. (2006), \u201cOn incident handling and response: a state\u2010of\u2010the\u2010art approach\u201d, Computers and Security, Vol. 25 No. 5, pp. 351\u201070.","DOI":"10.1016\/j.cose.2005.09.006"},{"key":"key2022020419514897600_b22","unstructured":"NIST (2004), Computer Security Incident Handling Guide, NIST Special Publication 800\u201061, NIST, Gaithersburg, MD."},{"key":"key2022020419514897600_b23","doi-asserted-by":"crossref","unstructured":"Sandhu, R., Bhamidipati, V. and Munawer, Q. (1999), \u201cThe ARBAC97 model for role\u2010based administration of roles\u201d, ACM Transactions on Information and System Security (TISSEC), Vol. 2 No. 1.","DOI":"10.1145\/300830.300839"},{"key":"key2022020419514897600_b24","unstructured":"Schnackenberg, D., Djahandari, K., Reid, T. and Wilson, B. (2002), Cooperative Intrusion Trace\u2010back and Response Architecture (CITRA), Boeing Phantom Works and NAI Labs, Prepared Under Contract N66001\u201001\u2010C\u20108048 for Space and Naval Warfare System Center (SSC), San Diego, CL."},{"key":"key2022020419514897600_b25","unstructured":"Sullivan, D. (2005), \u201cThe definitive guide to security management\u201d, Realtimepublishers.com, available at: www.ca.com."}],"container-title":["Information Management &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/09685220710759568","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685220710759568\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685220710759568\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T00:09:02Z","timestamp":1753402142000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/15\/3\/226-240\/186993"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2007,6,12]]},"references-count":25,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2007,6,12]]}},"alternative-id":["10.1108\/09685220710759568"],"URL":"https:\/\/doi.org\/10.1108\/09685220710759568","relation":{},"ISSN":["0968-5227"],"issn-type":[{"type":"print","value":"0968-5227"}],"subject":[],"published":{"date-parts":[[2007,6,12]]}}}