Network Security Center
NetSec
Internet Services Unit - King Abdulaziz City for  Science & Technology



عربي

Home

About NetSec

Intrusion Detection

Handling an Incident

Computer Viruses

Cryptography

NetSec Disclaimer

Contact NetSec

Links

ISU

  

Handling an Incident

Its important to remember that reporting a security incident to the right parties can mean a faster response to handle that incident, the following steps are to be followed:

  1. By obtaining the Source IP address (from the router or firewall logs or from any intrusion detection software).
  2. Go to http://www.ripe.net/db/whois.html, enter the IP address obtained in (1) in the query window and press "search".
  3. If the IP number is correct, the results are produced is composed of three parts:
    • Inetnum: This field provides information about the net block containing the IP address queried.
    • Route: This field provides information on the organization providing the transit routing service for this IP block.
    • Person: This field provides information about the contact person in the organization that owns the IP block.
  4. E-mail the person listed in the person field and be sure to include the IP address number and the exact timestamp of the incident. Only the owner of the IP block can identify the user(s) using the offending IP address at the time of the incident (e.g. using access logs). Therefore, sending the information to the e-mails listed in the Inetnum and Route fields is useless.
   

 

 

 (C) 2001 Internet Services Unit. All Rights Reserved.