Serverless Approaches to Incident Response in Critical Networks
摘要
Serverless computingServerless computing offers the opportunity for improving incident responseIncident response (IR) support within critical infrastructureCritical infrastructure networks, and this paper explores the maximisation of that potential. However, traditional IR approaches based on large amounts of manual processes and on-premises infrastructure lack the ability to scale with the increasing scale, velocity, and sophistication of today’s cyberattacks. The paper posits that the elasticity, automationAutomation, and pay per use nature of serverless computingServerless computing in comparisonComparison is a more agile, scalable as well as a cost-effective proposition. It shows how serverless functions are used to implement automated threat detection and response pipelines alongside existing Security Information and Event Management (SIEMSecurity Information and Event Management (SIEM)) systems. The paper in particular shows how serverless functions can simplify data ingestion, threat intelligence enrichment, live feed analysis, auto responding and reporting. Moreover, the paper further demonstrates the application of serverless capabilities to post incident forensicsForensics in critical infrastructureCritical infrastructure environments, specifically showing the use of serverless to build event driven forensicForensics systems which enable rapid, comprehensive and automated investigations. An example of real-world application is introduced through a case study of an energy plant. Integrating serverless architectures helps organisations get faster incident responseIncident response, less downtime and better protection of important services.