アナリストは最近の侵入からアーティファクトを受け取り、ドメイン、IPアドレス、電子メールアドレス、およびソフトウェアバージョンを取得できます。侵入分析のダイヤモンドモデルの次のポイントのうち、このインテリジェンスはいつ表されますか?
正解:A
The Diamond Model of Intrusion Analysis is a framework for analyzing and understanding malicious activity on a system or network. It defines the basic atomic element of any intrusion activity as the event, which consists of four core features: adversary, infrastructure, capability, and victim. These features are connected by edges that represent their underlying relationships and arranged in the shape of a diamond1 The infrastructure feature refers to the physical or logical communication structures that are used by the adversary to deliver a capability or interact with a victim. Examples of infrastructure elements are IP addresses, domain names, email addresses, servers, routers, etc. The domain, IP address, email address, and software version that the analyst extracted from the artifacts are all examples of infrastructure elements that can be used to identify or track the adversary's activity.