Request Tracker for Incident Response

Carlos Fuentes IRIS-CERT/RedIRIS What RT is

● RT is a ckeng system ● Help keep you organized ● Issue tracking . Trouble ckeng . Workflow . Helpdesk . Customer Service . Process management . Bug Tracking

2 What RTIR is

● RT for Incident Response ● Tickeng system ● Designed for CERT/CSIRT teams ● Originally designed for JANET-CERT ● Generalized for a “standard” process . TF-CSIRT RTIR Working Group

3 Designed for CSIRT Teams ● Metadata ● Workflows ● Views ● Plugins

4 Differences from RT

● RTIR is RT

… with more features, a custom interface and special configuraon

5 What RTIR does ● Keeps track of incidents ● Keeps track of correspondence ● Keeps an uneditable history ● Makes incident research easier ● Tracks your SLA commitments ● Integrates with your other systems ● Takes care of the ‘boring’ parts of Incidents Response

6 The RTIR Workflow RTIR Homepage

8 The Concept

● Incidents e everything together ● One Incident for . Many Incident Reports • Someone has a complaint of our constuency . Many Invesgaons • IRT aempts to get the root of the problem . Many Blocks • Track network level intervenon against threat

9 RTIR Relaonships

10 Incident Reports

● It usually starts with a Incident Report . Converstaons with complainers • Something bad happened • Please help me . Related to our constuency . Coming from • Mail • Telephone • FAX • Internal/External Automac Detecon System

11 Incident Reports LifeCycle

12 Incident Reports Worflow

13 Create an IR

14 Create an IR #2

15 IR Details

16 IR History

17 Incident Report Reply

18 Incident Report History

19 Incidents ● Once reported, the team tracks an Incident . Tracking what actually happened . Private / Internal . Tie everything togehter

20 Incident Lifecycle

21 Incident Workflow

22 Create an Incident

23 Incident Details

24 Incident Details #2

25 Incident History

26 Incident  Invesgaon

27 Invesgaons ● The teams starts an Invesgaon . Internal Research and Discovery . Conversaons with external partners • Law Enforcements • Network Providers • Experts • Other CSIRTs . Everyone who acts for resolving the issue

28 Invesgaon Lifecycle

29 Launch Invesgaon

30 Launch Invesgaon

31 Invesgaons Details

32 Invesgaons History

33 Data Detectors

34 Automac IP Detecon

35 Data Detectors

36 Research Tools

37 SSC & RT-IR Integraon

● New features developed: . Integraon with GOCDB • Customer CF’s values: List of the sites • Incident Report & Invesgaons

. Web Service for Invesgaon Creaon Script / • Allows us to launch an invesgaon RT-IR GOCDB Human for a site • Using a predefined RTFM template • Deliver to Site Security Officer and Searching for contacts NGI Security officer • Params required: – Exact name of the site Creaon Inc / Inv & Delivering the mail – Template ID

Results

38 SSC & RT-IR Integraon . Update SSC DB Script Acon • Allows us to store the answers from site in the SSC DB

39 Using RTIR Technical Informaon

● Cost of RTIR: $0 ● Cost of required soware: $0 ● Cost of required hardware: ??? ● Operang System . Unix//FreeBSD/MacOS X/Solaris/etc … ● Database . MySQL 4.1 or 5.0, PostgreSQL 8.x, Oracle 9.x or 10.x, SQLite (for tesng) ● Web Server . Apache, lighthpd, Standalone pure- server

41 Geng RTIR

● hp://bestpraccal.com/rr ● p://p.rediris.es/rediris/cert/rr/ CentOSRTIR.tgz . Vmware image for tesng . Provided by RedIRIS

42 RT & RTIR Community

● hp://wiki.bestpraccal.com - hp://www.rr.org

● r[email protected]cal.com ● [email protected]cal.com ● [email protected]cal.com

43 Quesons Spanish Research & Academic Network

44