PPT on Layer-7 Logging
Showing posts with label SIEM. Show all posts
Showing posts with label SIEM. Show all posts
Thursday, August 6, 2020
Sunday, January 15, 2017
How Many Threat Intelligence (TI) Feeds Are Enough?
MSSPs aside (as they can more easily achieve economies of scale), how many TI feeds should an internal SOC leverage?
Well, that depends on the quality of information. With that said, several open source & commercial / subscription feeds would not hurt for cross-reference purposes.
Here are some feeds worthy of consideration:
Well, that depends on the quality of information. With that said, several open source & commercial / subscription feeds would not hurt for cross-reference purposes.
Here are some feeds worthy of consideration:
- US-CERT
- CTIN
- Optiv
- Facebook ThreatExchange
- Crowstrike
- AlienVault
- SSLBL
- ZeuS Tracker
- Palevo Tracker
- Malc0de
- Binary Defense Systems
- Carbon Black / Bit9
- ThreatQuotient
- Anomali / ThreatStream
- ThreatConnect
Labels:
commercial,
MSSP,
open source,
SIEM,
SOC,
threat intelligence,
TI,
US-CERT
Wednesday, July 27, 2016
SIEM Deployments Does Not Equal Threat Intelligence
Just because an org has deployed a SIEM or uses a SIEM service from a MSSP / SOC vendor does not mean that threat intelligence (TI) has been implemented.
As articulated below, TI is at the next level compared to log aggregation and correlation.
https://securityintelligence.com/how-stix-taxii-and-cybox-can-help-with-standardizing-threat-information/
As always, budget, available resources, technical skill-sets, industry, and jurisdiction will all be factors in the feasibility of onboarding a TI program.
As articulated below, TI is at the next level compared to log aggregation and correlation.
https://securityintelligence.com/how-stix-taxii-and-cybox-can-help-with-standardizing-threat-information/
As always, budget, available resources, technical skill-sets, industry, and jurisdiction will all be factors in the feasibility of onboarding a TI program.
Tuesday, July 19, 2016
NextGen InfoSec Acronym Soup: IPS, ATP, SIEM, CTD, & UEBA
Gartner released some guidance about next generation InfoSec tools and the acronym UEBA caught the eye.
User and entity behavioral analytics (UEBA) look to tie some usual suspects (e.g., IPS, SIEM) with quasi-new kids (i.e., advanced threat protection: ATP). This new paradigm is also referred to as cyber threat defense (CTD) by vendors like Cisco.
Watch for newcomers like Cylance and Alert Logic to expand on UEBA for on and off premise solutions in the near future.
http://www.gartner.com/newsroom/id/3347717
http://www.cisco.com/c/dam/en/us/td/docs/security/network_security/ctd/ctd2-0/design_guides/ctd_2-0_cvd_guide_jul15.pdf
User and entity behavioral analytics (UEBA) look to tie some usual suspects (e.g., IPS, SIEM) with quasi-new kids (i.e., advanced threat protection: ATP). This new paradigm is also referred to as cyber threat defense (CTD) by vendors like Cisco.
Watch for newcomers like Cylance and Alert Logic to expand on UEBA for on and off premise solutions in the near future.
http://www.gartner.com/newsroom/id/3347717
http://www.cisco.com/c/dam/en/us/td/docs/security/network_security/ctd/ctd2-0/design_guides/ctd_2-0_cvd_guide_jul15.pdf
Tuesday, June 21, 2016
SIEM Decisions: OSSIM vs ELK, OSSEC vs rsyslog / tail / curl
Before dropping A LOT of money on a commercial SIEM installation, consider your open source options.
OSSIM and / or ELK are your most prevalent open source SIEM solutions. ELK is the preferred deployment due to ease of use / deployment, as well as being less resource intensive.
Beyond SIEM, most organizations need to feed these log analyzers. While OSSEC is an option, rsyslog / tail / curl is preferred as most orgs that have adept engineering teams are comfortable with open source solutions / scripting.
OSSIM and / or ELK are your most prevalent open source SIEM solutions. ELK is the preferred deployment due to ease of use / deployment, as well as being less resource intensive.
Beyond SIEM, most organizations need to feed these log analyzers. While OSSEC is an option, rsyslog / tail / curl is preferred as most orgs that have adept engineering teams are comfortable with open source solutions / scripting.
Monday, June 20, 2016
MFT vs EDI vs FTP
Does it make sense to implement a dedicated MFT environment?
http://docs.media.bitpipe.com/io_13x/io_130983/item_1359879/axway_datasheet_securetransport_en.pdf
It depends on the org & architecture; however, most orgs could do without.
Healthcare, insurance, fin svcs, or legal orgs may need these, though many will probably be better off using SFTP / FTPS or EDI in a pointed manner.
http://docs.media.bitpipe.com/io_13x/io_130983/item_1359879/axway_datasheet_securetransport_en.pdf
It depends on the org & architecture; however, most orgs could do without.
Healthcare, insurance, fin svcs, or legal orgs may need these, though many will probably be better off using SFTP / FTPS or EDI in a pointed manner.
Wednesday, June 15, 2016
SIEMs / IPS Alone No Longer Work
Advanced threat protection (ATP), or a MSSP / SOC, versus solely SIEM deployments, are needed now more than ever.
https://www.bluecoat.com/documents/download/8540d91b-b8d6-4be6-b0d0-7ed23c897764/0184e57d-7c34-4851-8266-2b430d93a3c6
Most orgs do not do a great job on log analysis, or malware / APT / phishing prevention, so it is well advised that outsourced ATP services be engaged, at least temporarily.
https://www.bluecoat.com/documents/download/8540d91b-b8d6-4be6-b0d0-7ed23c897764/0184e57d-7c34-4851-8266-2b430d93a3c6
Most orgs do not do a great job on log analysis, or malware / APT / phishing prevention, so it is well advised that outsourced ATP services be engaged, at least temporarily.
Wednesday, January 27, 2016
More Than SIEM (VSOC, SOC) - Threat Intelligence
In contemporary times it is no longer enough for an organization to simply collect data in a SIEM (on-premise, cloud/VSOC, SOC).
This data must be analyzed and correlated with national, industry, and association-based threat intelligence to determine attack vectors and action items.
In other words, it is essential for us to move beyond security compliance to stop subsequent data breaches.
This data must be analyzed and correlated with national, industry, and association-based threat intelligence to determine attack vectors and action items.
In other words, it is essential for us to move beyond security compliance to stop subsequent data breaches.
Subscribe to:
Posts (Atom)