Dr. Takuho MITSUNAGA Project Associate Professor, Graduate School of Interfaculty Initiative in Information Studies, The University of Tokyo. He is also Technical Advisor at Watch and Warning Group, JPCERT/CC After completing his degree at Graduate School of Informatics, Kyoto University, Mr. Mitsunaga worked at the front line of incident handling and penetration test at a security vendor. In FY 2010, he led an R&D project of the Ministry of Trade, Economy and Industry (METI) for encryption data sharing system for cloud with an efficient key managing function. He has been a member of Watch and Warning Group of JPCERT/CC since April 2011, where he is engaged in cyber attack analysis including APT cases. He has also contributed in some cyber security related books as coauthor or editorial supervisor including “Information Security White Paper 2013”. Proxy log and Firewall log collection is commonly practiced at many organizations mainly for incident handling purposes. Network packets are also important for effective incident analysis. However, its retention and storage could be difficult due to its high volume. On the other hand, opportunities for information exchange using STIX and other formats at cyber security related communities have been increasing. However, such information may not be readily actionable – its threat level and other possible impacts need to be judged before recipient organizations take actions based received information. For example, organizations who obtained a list of malicious IP addresses cannot immediately block corresponding communication since this action may cause possible impact on the business/network operation. As a breakthrough of such problems, The University of Tokyo developed “Network Control System based on Shared Information” by combining Software Defined Networking (SDN) and STIX. This is a new idea that Software Defined Networking (SDN) is made use of for CSIRT activities. The system judges the threat level of information in STIX files based on its categories and tags, and then provides routing configurations to SDN controllers correspond to the threat level as follows: Black (Risk: High) – Block communication immediately Gray (Risk: Medium) – Take network capture White (Risk: Low) – Maintain normal routing By providing different configurations, network load would not increase unnecessarily, and thus impact on the business/network operation would remain low. This system provides a proactive approach for incident handling, enabling network forensics based on the captured data in case of incidents. The University of Tokyo operated verification tests of the system which proved its reliability and effectiveness in terms of behavior in increased network load and application into incident handling procedures etc. This presentation will demonstrate how this system operates and how it can be integrated into CSIRT operation.