Thuta Learning
ရှာဖွေရန်
AdvancedSecurityintermediate

Incident Response Basics

စိတ်လျှော့ပါ။ ဒီခန်းကို စာအုပ်လိုမဟုတ်ဘဲ စကားပြောသလိုပဲ၊ နားလည်လွယ်အောင် ရှင်းပါမယ်။

ဒီခန်းပြီးရင် ဘာတတ်သွားမလဲ

  • Incident Response Basics ကို ကြောက်စရာမလိုအောင် နားလည်မယ်
  • ကိုယ်တိုင် authorized lab environment ထဲမှာ tool ကို run ကြည့်တတ်မယ်
  • Real assessment/report ထဲမှာ ဒီ concept ကို ချက်ချင်း အသုံးချတတ်မယ်

ခဏလေး ဒီလိုပဲ စဉ်းစားကြည့်

Incident Response lifecycle ရဲ့ phase အဓိက ၅ ခု ရှိပါတယ် — Preparation (IR plan/tool ကို ကြိုတင် ပြင်ဆင်ခြင်း), Identification (incident ဖြစ်နေလား စစ်ဆေးခြင်း), Containment (damage ကို ကန့်သတ်ခြင်း, ဥပမာ - infected machine ကို network ကနေ ချက်ချင်း ဖြုတ်ခြင်း), Eradication (root cause ကို ဖယ်ရှားခြင်း), Recovery (system ကို ပုံမှန်အခြေအနေ ပြန်ရောက်စေခြင်း) — ပြီးရင် Lessons Learned (root cause documentation, ထပ်မဖြစ်ရအောင် improvement) ကို ဆက်လုပ်ရပါတယ်.

လက်တွေ့ scenario နဲ့ ချိတ်ကြည့်မယ်

Company တစ်ခုမှာ ransomware infection detect ရင် — Containment အနေနဲ့ infected machine ကို network ကနေ ချက်ချင်း disconnect (spread ကို ကန့်သတ်ဖို့), Identification/Eradication အနေနဲ့ malware ရဲ့ entry point (phishing email? vulnerability?) ကို ရှာဖွေ, Recovery အနေနဲ့ clean backup ကနေ system ကို restore, Lessons Learned အနေနဲ့ 'ဘယ်လို ဒီလို ဖြစ်ခဲ့လဲ, နောက်တစ်ခါ ဘယ်လို ကာကွယ်မလဲ' ဆိုတဲ့ report ရေးရပါတယ် — ဒီ order (Containment ကို Eradication ထက် အရင်) က အရေးကြီးပါတယ်, damage spread ကို အရင်ရပ်ရမှာမို့.

အတူတူ ကြည့်မယ်

text
Incident Response Lifecycle
=============================

1. Preparation      — IR plan, tools, contacts ready BEFORE an incident
2. Identification    — confirm: is this actually an incident?
3. Containment        — stop the spread (isolate affected systems)
4. Eradication        — remove the root cause (malware, backdoor)
5. Recovery           — restore systems to normal operation
6. Lessons Learned    — document root cause, improve for next time
You should see
IR lifecycle ရဲ့ ၆ ဆင့်ကို sequence အတိုင်း ရှင်းပြနိုင်မည်။

၅ မိနစ် စမ်းကြည့်

'Company laptop တစ်လုံးမှာ ransomware ဖြစ်နေတယ်' ဆိုတဲ့ scenario ကို IR lifecycle ၆ ဆင့်အတိုင်း (Preparation ကလွဲပြီး) response step ကို ကိုယ်တိုင် ရေးဆွဲကြည့်ပါ။

သတိလေးတစ်ချက်

Real incident response ကို practice/simulation မဟုတ်ဘဲ တကယ့် production environment မှာ လုပ်ဆောင်တဲ့အခါ, IR plan/authorization ရှိတဲ့ team member ကသာ lead လုပ်သင့်ပါတယ် — unauthorized 'helpful' action (evidence ဖျက်မိခြင်း, log ဖျက်မိခြင်း) က forensic investigation ကို ပိုဒုက္ခရောက်စေနိုင်ပါတယ်.

ဒီနေရာမှာ လူအများမှားတတ်တယ်

  • Containment မလုပ်ခင် Eradication ကို အရင်ကြိုးစားခြင်း — damage ဆက်ပြီး spread ဖြစ်နေရင်း root cause ရှာနေတာက situation ကို ပိုဆိုးအောင် လုပ်နိုင်ပါတယ်
  • Lessons Learned phase ကို 'incident ပြီးသွားပြီ' ဆိုပြီး skip ခြင်း — root cause documentation မရှိရင် တူညီတဲ့ incident ထပ်ဖြစ်နိုင်ချေ များပါတယ်

အခု ကိုယ်တိုင် စမ်းကြည့်

'Company laptop တစ်လုံးမှာ ransomware ဖြစ်နေတယ်' ဆိုတဲ့ scenario ကို IR lifecycle ၆ ဆင့်အတိုင်း (Preparation ကလွဲပြီး) response step ကို ကိုယ်တိုင် ရေးဆွဲကြည့်ပါ။

You'll know it worked when: IR lifecycle ရဲ့ ၆ ဆင့်ကို sequence အတိုင်း ရှင်းပြနိုင်မည်။

Incident Response Basics | Thuta Learning