Skip to main navigation Skip to search Skip to main content

Palantir: A framework for collaborative incident response and investigation

  • Himanshu Khurana
  • , Jim Basney
  • , Mehedi Bakht
  • , Mike Freemon
  • , Von Welch
  • , Randy Butler

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Organizations owning cyber-infrastructure assets face large scale distributed attacks on a regular basis. In the face of increasing complexity and frequency of such attacks, we argue that it is insufficient to rely on organizational incident response teams or even trusted coordinating response teams. Instead, there is need to develop a framework that enables responders to establish trust and achieve an effective collaborative response and investigation process across multiple organizations and legal entities to track the adversary, eliminate the threat and pursue prosecution of the perpetrators. In this work we develop such a framework for effective collaboration. Our approach is motivated by our experiences in dealing with a large-scale distributed attack that took place in 2004 known as Incident 216. Based on our approach we present the Palantir system that comprises conceptual and technological capabilities to adequately respond to such attacks. To the best of our knowledge this is the first work proposing a system model and implementation for a collaborative multi-site incident response and investigation effort.

Original languageEnglish (US)
Title of host publicationIDtrust 2009 - Proceedings of the 8th Symposium on Identity and Trust on the Internet
EditorsKent Seamons, Neal McBurnett, Tim Polk
PublisherAssociation for Computing Machinery
Pages38-51
Number of pages14
ISBN (Electronic)9781605584744
DOIs
StatePublished - Apr 14 2009
Event8th Symposium on Identity and Trust on the Internet, IDtrust 2009 - Gaithersburg, United States
Duration: Apr 14 2009Apr 16 2009

Publication series

NameACM International Conference Proceeding Series
VolumePart F128834

Other

Other8th Symposium on Identity and Trust on the Internet, IDtrust 2009
Country/TerritoryUnited States
CityGaithersburg
Period4/14/094/16/09

Keywords

  • Digital investigation
  • Incident response
  • Multi-site collaboration

ASJC Scopus subject areas

  • Software
  • Human-Computer Interaction
  • Computer Vision and Pattern Recognition
  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'Palantir: A framework for collaborative incident response and investigation'. Together they form a unique fingerprint.

Cite this