Cybersecurity Incident Response and Forensics: Comparative Analysis and Proposals for Improvement

  • Unique Paper ID: 167700
  • Volume: 11
  • Issue: 4
  • PageNo: 197-201
  • Abstract:
  • In the rapidly evolving landscape of cybersecurity, the effectiveness of incident response and forensic techniques is critical for minimizing the impact of cyberattacks. This research paper compares several widely used techniques, including Security Information and Event Management (SIEM) systems, manual log analysis, automated incident response, Deep Packet Inspection (DPI), and machine learning-based anomaly detection. The comparative analysis focuses on detection accuracy, time to detect (TTD), time to respond (TTR), false positive rate (FPR), scalability, and resource consumption. The findings reveal that while machine learning-based systems offer the highest detection accuracy and scalability, they also require substantial computational resources. The paper concludes with recommendations for hybrid systems and resource optimization to enhance overall cybersecurity defenses

Cite This Article

  • ISSN: 2349-6002
  • Volume: 11
  • Issue: 4
  • PageNo: 197-201

Cybersecurity Incident Response and Forensics: Comparative Analysis and Proposals for Improvement

Related Articles