Showing posts with label SIEM. Show all posts
Showing posts with label SIEM. Show all posts

Sunday, January 15, 2017

How Many Threat Intelligence (TI) Feeds Are Enough?

MSSPs aside (as they can more easily achieve economies of scale), how many TI feeds should an internal SOC leverage?

Well, that depends on the quality of information.  With that said, several open source & commercial / subscription feeds would not hurt for cross-reference purposes.

Here are some feeds worthy of consideration:

  • US-CERT
  • CTIN
  • Optiv
  • Facebook ThreatExchange
  • Crowstrike
  • AlienVault
  • SSLBL
  • ZeuS Tracker
  • Palevo Tracker
  • Malc0de
  • Binary Defense Systems
  • Carbon Black / Bit9
  • ThreatQuotient
  • Anomali / ThreatStream
  • ThreatConnect

Wednesday, July 27, 2016

SIEM Deployments Does Not Equal Threat Intelligence

Just because an org has deployed a SIEM or uses a SIEM service from a MSSP / SOC vendor does not mean that threat intelligence (TI) has been implemented.

As articulated below, TI is at the next level compared to log aggregation and correlation.

https://securityintelligence.com/how-stix-taxii-and-cybox-can-help-with-standardizing-threat-information/

As always, budget, available resources, technical skill-sets, industry, and jurisdiction will all be factors in the feasibility of onboarding a TI program.

Tuesday, July 19, 2016

NextGen InfoSec Acronym Soup: IPS, ATP, SIEM, CTD, & UEBA

Gartner released some guidance about next generation InfoSec tools and the acronym UEBA caught the eye. 

User and entity behavioral analytics (UEBA) look to tie some usual suspects (e.g., IPS, SIEM) with quasi-new kids (i.e., advanced threat protection: ATP).  This new paradigm is also referred to as cyber threat defense (CTD) by vendors like Cisco.

Watch for newcomers like Cylance and Alert Logic to expand on UEBA for on and off premise solutions in the near future.

http://www.gartner.com/newsroom/id/3347717

http://www.cisco.com/c/dam/en/us/td/docs/security/network_security/ctd/ctd2-0/design_guides/ctd_2-0_cvd_guide_jul15.pdf

Tuesday, June 21, 2016

SIEM Decisions: OSSIM vs ELK, OSSEC vs rsyslog / tail / curl

Before dropping A LOT of money on a commercial SIEM installation, consider your open source options.

OSSIM and / or ELK are your most prevalent open source SIEM solutions.  ELK is the preferred deployment due to ease of use / deployment, as well as being less resource intensive.

Beyond SIEM, most organizations need to feed these log analyzers.  While OSSEC is an option, rsyslog / tail / curl is preferred as most orgs that have adept engineering teams are comfortable with open source solutions / scripting.

Monday, June 20, 2016

MFT vs EDI vs FTP

Does it make sense to implement a dedicated MFT environment?

http://docs.media.bitpipe.com/io_13x/io_130983/item_1359879/axway_datasheet_securetransport_en.pdf

It depends on the org & architecture; however, most orgs could do without.

Healthcare, insurance, fin svcs, or legal orgs may need these, though many will probably be better off using SFTP / FTPS or EDI in a pointed manner.

Wednesday, June 15, 2016

SIEMs / IPS Alone No Longer Work

Advanced threat protection (ATP), or a MSSP / SOC, versus solely SIEM deployments, are needed now more than ever.

https://www.bluecoat.com/documents/download/8540d91b-b8d6-4be6-b0d0-7ed23c897764/0184e57d-7c34-4851-8266-2b430d93a3c6

Most orgs do not do a great job on log analysis, or malware / APT / phishing prevention, so it is well advised that outsourced ATP services be engaged, at least temporarily.

Wednesday, January 27, 2016

More Than SIEM (VSOC, SOC) - Threat Intelligence

In contemporary times it is no longer enough for an organization to simply collect data in a SIEM (on-premise, cloud/VSOC, SOC).

This data must be analyzed and correlated with national, industry, and association-based threat intelligence to determine attack vectors and action items.

In other words, it is essential for us to move beyond security compliance to stop subsequent data breaches.