Responding to Intrusions

SEI Report
This report provides practical guidance for improving the security of networked computer systems for administrators, managers, and security staff.
Publisher

Software Engineering Institute

CMU/SEI Report Number
CMU/SEI-99-SIM-006
DOI (Digital Object Identifier)
10.1184/R1/6583247.v1

Abstract

These practices are intended primarily for system and network administrators, managers of information systems, and security personnel responsible for networked information resources. These practices are applicable to your organization if your networked systems infrastructure includes host systems providing services to multiple users (file servers, timesharing systems, database servers, Internet servers, etc.) local-area or wide-area networks direct connections, gateways, or modem access to and from external networks, such as the Internet We recommend that you read all of the practices in this module before taking any action. To successfully implement the practices, it is important that you understand the overall context and relationships among them. For instance, once you read the practices in the Handle category, it is easier to understand the Practices in the Prepare category (see the Summary of recommended practices table). If you are dealing with an intrusion, you may want to skip the first two preparatory practices and move immediately to Practice 3, Analyze all information necessary to characterize an intrusion. Once you have completed your response and recovery process, we recommend that you review and implement the preparatory practices.

Cite This SEI Report

Kossakowski, K., Wilson, W., Allen, J., Alberts, C., Cohen, C., Ford, G., Fraser, B., Hayes, E., Kochmar, J., & Konda, S. (1999, February 1). Responding to Intrusions. (SEI Report CMU/SEI-99-SIM-006). Retrieved September 11, 2026, from https://doi.org/10.1184/R1/6583247.v1.

@techreport{kossakowski_1999,
author={Kossakowski, Klaus-Peter and Wilson, William and Allen, Julia and Alberts, Christopher and Cohen, Cory and Ford, Gary and Fraser, Barbara and Hayes, Eric and Kochmar, John and Konda, Suresh},
title={Responding to Intrusions},
month={Feb},
year={1999},
number={{CMU/SEI-99-SIM-006},
institution={Software Engineering Institute, Carnegie Mellon University},
doi={10.1184/R1/6583247.v1},
url={https://doi.org/10.1184/R1/6583247.v1},
note={Accessed: 2026-Sep-11}
}

Kossakowski, Klaus-Peter, William Wilson, Julia Allen, Christopher Alberts, Cory Cohen, Gary Ford, Barbara Fraser, Eric Hayes, John Kochmar, and Suresh Konda. "Responding to Intrusions." (CMU/SEI-99-SIM-006). Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, February 1, 1999. https://doi.org/10.1184/R1/6583247.v1.

K. Kossakowski, W. Wilson, J. Allen, C. Alberts, C. Cohen, G. Ford, B. Fraser, E. Hayes, J. Kochmar, and S. Konda, "Responding to Intrusions," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, SEI Report CMU/SEI-99-SIM-006, 1-Feb-1999 [Online]. Available: https://doi.org/10.1184/R1/6583247.v1. [Accessed: 11-Sep-2026].

Kossakowski, Klaus-Peter, William Wilson, Julia Allen, Christopher Alberts, Cory Cohen, Gary Ford, Barbara Fraser, Eric Hayes, John Kochmar, and Suresh Konda. "Responding to Intrusions." (SEI Report CMU/SEI-99-SIM-006). Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 1 Feb. 1999. https://doi.org/10.1184/R1/6583247.v1. Accessed 11 Sep. 2026.

Kossakowski, Klaus-Peter; Wilson, William; Allen, Julia; Alberts, Christopher; Cohen, Cory; Ford, Gary; Fraser, Barbara; Hayes, Eric; Kochmar, John; & Konda, Suresh. Responding to Intrusions. CMU/SEI-99-SIM-006. Software Engineering Institute. 1999. DOI: 10.1184/R1/6583247.v1. https://doi.org/10.1184/R1/6583247.v1