Preparing to Detect Signs of Intrusion

SEI Report
The practices contained in this 1998 report identify advance preparations you must make to enable you to obtain evidence of an intrusion or an intrusion attempt.
Publisher

Software Engineering Institute

CMU/SEI Report Number
CMU/SEI-98-SIM-005
DOI (Digital Object Identifier)
10.1184/R1/6582176.v1

Abstract

It is essential that those responsible for your organization's information systems and networks be adequately prepared to detect evidence of breaches in security when they occur. Without advance preparation, it will be difficult, if not impossible, to determine if an intruder has been present and the extent of the damage caused by the intrusion. Thorough preparation will permit you to detect an intrusion or an intrusion attempt during or soon after it occurs. Preparation involves consideration of your security policy and supporting procedures, your critical business information, your systems, your networks, your user community (internal and external), and the tools to be employed in detecting intrusions.  

A general security goal is to prevent intrusions. Even if you have sophisticated prevention measures in place, your strategy for detecting intrusions must include preparation. This module is a companion to Detecting Signs of Intrusion. 

The practices contained in this module identify advance preparations you must make to enable you to obtain evidence of an intrusion or an intrusion attempt. They are designed to help you prepare by configuring your data, systems, networks, workstations, tools, and user environments to capture the necessary information for detecting signs of intrusion.

Cite This SEI Report

Kochmar, J., Allen, J., Alberts, C., Cohen, C., Ford, G., Fraser, B., Konda, S., Kossakowski, K., & Simmel, D. (1998, June 1). Preparing to Detect Signs of Intrusion. (SEI Report CMU/SEI-98-SIM-005). Retrieved August 16, 2026, from https://doi.org/10.1184/R1/6582176.v1.

@techreport{kochmar_1998,
author={Kochmar, John and Allen, Julia and Alberts, Christopher and Cohen, Cory and Ford, Gary and Fraser, Barbara and Konda, Suresh and Kossakowski, Klaus-Peter and Simmel, Derek},
title={Preparing to Detect Signs of Intrusion},
month={Jun},
year={1998},
number={{CMU/SEI-98-SIM-005},
institution={Software Engineering Institute, Carnegie Mellon University},
doi={10.1184/R1/6582176.v1},
url={https://doi.org/10.1184/R1/6582176.v1},
note={Accessed: 2026-Aug-16}
}

Kochmar, John, Julia Allen, Christopher Alberts, Cory Cohen, Gary Ford, Barbara Fraser, Suresh Konda, Klaus-Peter Kossakowski, and Derek Simmel. "Preparing to Detect Signs of Intrusion." (CMU/SEI-98-SIM-005). Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, June 1, 1998. https://doi.org/10.1184/R1/6582176.v1.

J. Kochmar, J. Allen, C. Alberts, C. Cohen, G. Ford, B. Fraser, S. Konda, K. Kossakowski, and D. Simmel, "Preparing to Detect Signs of Intrusion," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, SEI Report CMU/SEI-98-SIM-005, 1-Jun-1998 [Online]. Available: https://doi.org/10.1184/R1/6582176.v1. [Accessed: 16-Aug-2026].

Kochmar, John, Julia Allen, Christopher Alberts, Cory Cohen, Gary Ford, Barbara Fraser, Suresh Konda, Klaus-Peter Kossakowski, and Derek Simmel. "Preparing to Detect Signs of Intrusion." (SEI Report CMU/SEI-98-SIM-005). Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 1 Jun. 1998. https://doi.org/10.1184/R1/6582176.v1. Accessed 16 Aug. 2026.

Kochmar, John; Allen, Julia; Alberts, Christopher; Cohen, Cory; Ford, Gary; Fraser, Barbara; Konda, Suresh; Kossakowski, Klaus-Peter; & Simmel, Derek. Preparing to Detect Signs of Intrusion. CMU/SEI-98-SIM-005. Software Engineering Institute. 1998. DOI: 10.1184/R1/6582176.v1. https://doi.org/10.1184/R1/6582176.v1