Protecting a device against a cyber incident
A computer-implemented method and a system is provided for protecting at least one device of a target infrastructure against a cyber incident, whereby an infrastructure database contains device-specific information for its devices, by providing a security playbook for the given cyber incident, transforming the security playbook to a transformed playbook, analyzing the respective step of the transformed playbook based on a policy and process database, which shows a rule indicating whether at least a part of the step can be executed without any restriction or only with a restriction or has to be blocked, executing the steps based on the labeled playbook taking the handling label into account and for generating at least one instruction derived from at least one of the steps, and generating a device-specific command based on the instruction and based on a syntax processable by the device.
1 . A system for protecting at least one device of a target infrastructure against a cyber incident, whereby an infrastructure database contains device-specific information for devices, the system comprising:
one or more processors configured to:
provide a security playbook for the cyber incident, whereby the security playbook describes steps to be executed in reaction to the cyber incident and placeholders to be replaced with device-specific information when the security playbook is applied to the target infrastructure;
transform the security playbook to a transformed playbook, whereby the placeholders include device references identified by placeholder syntax within the security playbook that are replaced with device-specific addresses from the infrastructure database based on device type to generate the transformed playbook;
analyze the respective step of the transformed playbook based on a policy and process database, which shows a rule indicating whether at least a part of the step can be executed without any restriction or only with a restriction or has to be blocked, and for forming a labeled playbook based on the transformed playbook showing the respective rule for at least one part of the step indicated by a respective handling label;
execute the steps based on the labeled playbook taking the handling label into account and for generating at least one instruction derived from at least one of the steps; and
generate a device-specific command based on the instruction and based on a syntax processable by the device, whereby the device-specific command is transmitted via a message based on a communication protocol to the device for processing the device-specific command by a respective device.
2 . The system according to claim 1 , wherein the cyber incident contains at least one tag describing the cyber incident and is used for selecting the security playbook from a number of security playbooks.
3 . The system according to claim 1 , wherein the placeholders further represent an action and/or data of the security playbook that are transformed to a device-specific action and/or device-specific data based on the infrastructure database.
4 . The system according to claim 1 , wherein the policy and process database provides for at least one of the placeholders of one of the steps, whereby the respective placeholder is unchanged by the transformation, a rule describing a handling instruction for transforming this placeholder to a transformed placeholder.
5 . The system according to claim 1 , wherein the one or more processors are further configured to:
verify an executability of the steps of the labeled playbook, for defining an order of execution of the steps and for generating an updated playbook based on the labeled playbook based on the definition of the order of execution; and
execute the steps of the updated playbook taking the handling label into account and for generating at least one instruction derived from at least one of the steps.
6 . The system according to claim 5 , wherein the one or more processors are configured to transmit the at least one of the instructions via the message and for receiving a status based on the execution result of the instruction.
7 . The system according to claim 5 , wherein the one or more processors are configured to generate the instruction based on a command step of the updated playbook, of at least a part of one of the steps of the updated playbook, whereby the command step describes at least an action to be executed by one of the devices.
8 . The system according to claim 5 , wherein the one or more processors are configured to perform a specific action signaled by the handling label of the step before continuing to execute the respective step.
9 . The system according to claim 8 , wherein the specific action represents a request to receive a confirmation for continuing to execute the respective step, with a stop of the continuation in case of the confirmation being negative.
10 . The system according to claim 1 , wherein the security playbook is provided based on at least a keyword describing the cyber incident from a playbook database.
11 . The system according to claim 10 , wherein a search of the security playbook in the playbook database based on the keyword is organized such that search results are prioritized to provide the security playbook with a high priority, and a new security playbook is received and stored in an organized way in the playbook database.
12 . The system according to claim 11 , wherein a draft playbook is received, validated, and transformed to generate the new security playbook that shows a compatible description to be processable.
13 . A computer-implemented method for protecting at least one device of a target infrastructure against a cyber incident, whereby an infrastructure database contains device-specific information for devices, comprising:
providing a security playbook for the given cyber incident, whereby the security playbook describes steps to be executed in reaction to the cyber incident and placeholders to be replaced with device-specific information when the security playbook is applied to the target infrastructure; transforming the security playbook to a transformed playbook, whereby the placeholders include device references identified by placeholder syntax within the security playbook that are replaced with device-specific addresses from the infrastructure database based on device type to generate the transformed playbook;
analyzing the respective step of the transformed playbook based on a policy and process database, which shows a rule indicating whether at least a part of the step can be executed without any restriction or only with a restriction or has to be blocked, and for forming a labeled playbook based on the transformed playbook showing the respective rule for at least one part of the step indicated by a respective handling label;
executing the steps based on the labeled playbook taking the handling label into account and for generating at least one instruction derived from at least one of the steps; and
generating a device-specific command based on the instruction and based on a syntax processable by the device, whereby the device-specific command is transmitted via a message based on a communication protocol to the device for processing the device-specific command by a respective device.
14 . The computer-implemented method according to claim 13 , wherein the computer-implemented method is further implementing and realizing one or several of enhancements of a corresponding system.