Open adammontville opened 5 years ago
NOTE: This seems more like a process/procedure discovery control.
Input:
Operations:
Measures:
Metrics:
Inputs:
Operations:
Measures:
Metrics: Calculate the variance of log reviews:
If a threshold T for review is used, then calculate the variance according to the target interval:
P (The Probability of detecting an anomaly in log review) [0,1] = D / L
Quality of Log review [0,1] = (1-V) * P (means quality of review is high iff the review is highly regular and the potential is detecting anomalies (at least one per review) is also high)
Ratio of unauthorized ports reported: UP / NP
Inputs:
Operations:
Measures:
Metrics: Calculate the variance of log reviews:
If a threshold T for review is used, then calculate the variance according to the target interval:
Perform automated port scans on a regular basis against all systems and alert if unauthorized ports are detected on a system.
Measures
Metrics