Learning Objectives:
-
Understand the principles of security monitoring and incident detection.
-
Apply SIEM correlation and endpoint telemetry analysis to identify security events.
-
Analyse network anomalies and DoS patterns using packet and log analysis.
-
Assess the severity, impact, and root cause of cyber incidents.
2.1 Security Monitoring and Detection
The Coursera course on Incident Response and Cyber Forensics teaches participants to “analyze security events using SIEM correlation rules and endpoint telemetry data” and to “investigate network anomalies and DoS patterns using packet and log analysis” . The course covers security monitoring principles, SIEM correlation workflows, and endpoint telemetry analysis to transform alerts into structured investigations.
Key Detection Capabilities:
-
SIEM Correlation: SIEM systems correlate events from multiple sources to identify potential security incidents. The course teaches “SIEM correlation workflows” and “endpoint telemetry analysis” .
-
Network Analysis: Analysing network traffic to detect anomalies and potential attacks. The course covers “investigating network anomalies and DoS patterns using packet and log analysis” .
-
Endpoint Telemetry: Analysing endpoint data to detect malicious activity. The course covers “endpoint telemetry analysis” .
-
Anomaly Detection: Differentiating baseline activity from malicious behaviour.
The course also covers “establishing the baseline” and “differentiating baseline activity from malicious behavior” . The FSB’s framework for incident response emphasises that analysis determines the severity, impact and root cause of the cyber-incident to drive appropriate response and recovery activities .
2.2 Incident Analysis
Incident analysis is the process of determining the severity, impact, and root cause of a cyber incident. The FSB’s framework requires effective response and recovery activities, including forensic analysis .
Key Analysis Activities:
-
Severity Assessment: Assessing the severity of the incident and its potential impact on operations.
-
Impact Assessment: Assessing the actual impact of the incident on systems, data, and operations.
-
Root Cause Analysis: Determining the root cause of the incident to prevent recurrence.
-
Forensic Analysis: Conducting forensic analysis to gather evidence and understand the attack.
The Central Bank of Eswatini’s Guidelines require financial institutions to have procedures in place for collecting, logging and analysing security-relevant events in order to trigger actionable security alerts or initiate the security incident process.
2.3 Forensic Analysis in Incident Response
Digital forensics is essential for effective incident response. The Coursera course covers “applied demonstrations” for interpreting abnormal network patterns and “forensic-ready documentation and evidence handling” . The course teaches “forensic documentation and evidence handling techniques to support investigations” .
Key Forensic Capabilities:
-
Evidence Collection: Collecting digital evidence in a forensically sound manner.
-
Evidence Preservation: Preserving evidence to maintain its integrity.
-
Timeline Reconstruction: Reconstructing the timeline of events during the incident.
-
Log Analysis: Analysing logs to understand attacker activity.
-
Memory Analysis: Analysing memory dumps to detect malicious activity.
The course covers “forensic log and artifact analysis with proper documentation” and “memory capture simulations” . The FSB’s framework emphasises that analysis should include forensic analysis to determine the severity, impact and root cause of the cyber-incident .
2.4 Detection and Analysis Tools
The Coursera course teaches participants to “apply SIEM correlation and network traffic analysis to detect security incidents and identify abnormal behavior” and to “investigate network anomalies and DoS patterns using packet and log analysis” . The course covers using packet capture tools such as Wireshark to analyse denial-of-service and distributed denial-of-service attack patterns .
Key Tools:
-
SIEM: Security Information and Event Management systems.
-
Wireshark: Packet capture and analysis tool.
-
Endpoint Detection and Response (EDR): Endpoint monitoring and response tools.
-
Log Analysis Tools: Tools for analysing logs from multiple sources.
-
Forensic Tools: Tools for digital evidence collection and analysis.