- 1、本文档共8页,可阅读全部内容。
- 2、有哪些信誉好的足球投注网站(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
- 3、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 4、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
查看更多
The Diamond Model of Intrusion Analysis (入侵的钻石模型分析)
The Diamond Model of
Intrusion Analysis
A Summary
By
Sergio Caltagirone
This document is not a reference guide to the Diamond Model. See technical report
for official reference and complete details.
Why the Diamond Model Matters
The Diamond Model, for the first time, accurately details the fundamental aspects of all
malicious activity as well as the core analytic concepts used to discover, develop, track,
group, and ultimately counter both the activity and the adversary. The model emerged in
2006 by senior analysts asking the simple question, “How do we do our work?”
Unfortunately, it required seven years of thought, implementation, and refinement to
complete the model. This delay is primarily because the intrusion analysis discipline has
long been regarded as an art – to be learned and practiced, rather than a science – to be
studied and refined. It is a discipline that prizes and studies analytic outcomes far more
than understanding the processes and principles used to those achieve those outcomes.
This approach has held analysis back from identifying first principles and foundational
concepts. It frustrated the development of new tradecraft and a more complete
understanding of malicious activity. This restriction had further implications slowing the
evolution of threat mitigation which relies on efficient, effective, and accurate analysis.
The Diamond Model begins to address these challenges by applying scientific rigor to the
discipline. With the Diamond, new and more effective mitigation strategies can be
developed that increase the cost on the adversary while reducing the cost to the defender.
It integrates traditional information assurance strategies and cyber threat intelligence
seamlessly. It increases analytic efficiency and effectiveness by highlighting analytic
opportunities and intelli
您可能关注的文档
- The British constitution, law reform and the (英国宪法、法律改革和).pdf
- THE BUCKLING OF SLENDER CONCRETE AND (纤细的混凝土和屈曲).pdf
- THE BUDDIPOLETM OPERATING MANUAL Yahoo(雅虎BUDDIPOLETM操作手册).pdf
- THE BUILDING BLOCKS OF ULTRAMARATHON …(马拉松的基石u2026).pdf
- THE BUILT IN VALUE OF THE R8000 SERIES (的建在价值R8000系列).PDF
- The Business Case for Lean Six Sigma in Higher (精益六西格玛在更高的业务案例).pdf
- The Business Plan MIT(商业计划麻省理工学院).pdf
- The Business Plan and Executive Summary(商业计划和执行概要).pdf
- The Business Process Transformation Framework (业务流程转换框架).pdf
- THE CALCULUS 7 Verbundzentrale des GBV(微积分7 Verbundzentrale des GBV).pdf
- 第18讲 第17课 西晋的短暂统一和北方各族的内迁.docx
- 第15讲 第14课 沟通中外文明的“丝绸之路”.docx
- 第13课时 中东 欧洲西部.doc
- 第17讲 第16 课三国鼎立.docx
- 第17讲 第16课 三国鼎立 带解析.docx
- 2024_2025年新教材高中历史课时检测9近代西方的法律与教化含解析新人教版选择性必修1.doc
- 2024_2025学年高二数学下学期期末备考试卷文含解析.docx
- 山西版2024高考政治一轮复习第二单元生产劳动与经营第5课时企业与劳动者教案.docx
- 第16讲 第15课 两汉的科技和文化 带解析.docx
- 第13课 宋元时期的科技与中外交通.docx
文档评论(0)