Responding to Attacks. - Page 2© Mayur Kamat
Page 2
Apr 24, 2000
safeguards to ensure that this attack does not harm your network).
My advice in such a situation would be to call in not only some law
enforcement but also at least one qualified security firm to assist in snagging
the offender. The most important features of such an operation are logs and, of
course, locating the perpetrator. You can provide the logs on your own. However,
as far as tracing the individual, you can only go so far. You might start with a
simple traceroute and, before you're finished, you may have implemented a dozen
different techniques only to find that the network from which the perpetrator is
hailing is either also a victim (that is, the cracker is island hopping), a
rogue site, or even worse, located in a country beyond the reach of the U.S.
Justice Department. In such cases, little can be done besides shoring up your
network and getting on with your business. Taking any other course of action
might be very costly and largely a waste of time.
So try to classify the attack you have faced and try to implement the
measures mentioned here. |