Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a4399eff786b2407

Jump to content

Internet Storm Center

From Wikipedia, the free encyclopedia
Internet Storm Center
Internet Storm Center logo
Website type
Internet security monitoring
Available inEnglish
OwnerSANS Institute
Websiteisc.sans.edu
CommercialNo
RegistrationOptional
Launched2001
Current statusActive

The Internet Storm Center (ISC) is a program of the SANS Technology Institute, a branch of the SANS Institute which monitors the level of malicious activity on the Internet, particularly with regard to large-scale infrastructure events.[1]

History

[edit]

The ISC evolved from "Incidents.org", a site initially founded by the SANS Institute to assist in the public-private sector cooperation during the Y2K cutover. In 2000, Incidents.org started to cooperate with DShield to create a Consensus Incidents Database (CID). It collected security information from cooperating sites and agencies for mass analysis.[1]

On March 22, 2001, the SANS CID was responsible for the early detection of the "Lion" worm attacks on various facilities. The quick warning and counter-efforts organized by the CID were instrumental in controlling the damage done by this worm, which otherwise might have been considerably worse.[1]

Later, DShield was integrated closer into incidents.org as the SANS Institute started to sponsor DShield. The CID was renamed the "Internet Storm Center" in acknowledgement of the way it uses the distributed sensor network similar to the way a weather reporting center will detect and track an atmospheric storm and provide warnings.[1] Since that time the ISC has expanded its monitoring operations; its website cites a figure of over twenty million "intrusion detection log entries" per day.[1][2] It continues to provide analyses and alerts of security threats to the Internet community.[1][3]

During the last hours of 2005 and the first weeks of 2006, the Internet Storm Center went to its longest period at the time to "yellow" on the Infocon for the WMF vulnerability.[4]

The ISC publishes a daily "Handler Diary", prepared by its volunteer incident handlers to summarize and analyze new threats and Internet security events.[5] The diaries have also been described as a source for new attack trends and as a means of facilitating cooperation among security researchers.[6] The ISC also produces "Stormcast", a daily podcast providing summaries of cybersecurity news.[7] ISC information has been used in coverage of vulnerabilities and exploits by cybersecurity publications.[8][9][10] In 2026, Wiz included the ISC among 13 threat-intelligence feeds it recommended for security professionals to follow.[11]

The Internet Storm Center is currently staffed with approximately 40 volunteers, representing 8 countries and many industries.

Notable members

[edit]

References

[edit]
  1. 1 2 3 4 5 6 Van Horenbeeck, Maarten (2008). "The SANS Internet Storm Center". Proceedings of the 2008 WOMBAT Workshop on Information Security Threats Data Collection and Sharing (WISTDCS 2008). IEEE. pp. 17–23. doi:10.1109/WISTDCS.2008.16.
  2. ↑ "Internet Storm Center (ISC)". Cyber Security Intelligence. Retrieved 26 July 2026.
  3. ↑ "Internet Storm Center (ISC)". ASPR TRACIE. U.S. Department of Health and Human Services. Retrieved 26 July 2026.
  4. ↑ Sachs, Marcus H. "Cyber Security Awareness Month 2008 - Summary and Links". SANS Internet Storm Center. Retrieved 26 July 2026.
  5. ↑ "ISC Feature of the Week: Handler Diaries". SANS Internet Storm Center. 22 February 2012. Retrieved 21 August 2026.
  6. ↑ "Better cybersecurity hinges on understanding actual risks and addressing the right problems". Help Net Security. 7 July 2020. Retrieved 26 July 2026.
  7. ↑ "ISC Feature of the Week: XML Feeds". SANS Internet Storm Center. 15 February 2012. Retrieved 21 August 2026.
  8. ↑ "Cisco Smart Licensing Utility flaws under attack". Cybersecurity Dive. 20 March 2025. Retrieved 21 August 2026.
  9. ↑ "Yet again, threat actors exploit a critical file-transfer service CVE". Cybersecurity Dive. 1 December 2023. Retrieved 21 August 2026.
  10. ↑ "SmartApeSG Campaign Uses ClickFix Scripts to Infect Windows Hosts With RAT Malware". CybersecurityNews. Retrieved 21 August 2026.
  11. ↑ "The 13 Must-Follow Threat Intel Feeds". Wiz. 30 March 2026. Retrieved 21 August 2026.
  12. ↑ "People, it's time to disable Java on all your computer Web browsers". NBC News. 11 January 2013. Retrieved 26 July 2026.
[edit]