26
Security Operations Center Security Operations Center Security Operations Center Security Operations Center Petr Kunstat Microfocus SW

Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

  • Upload
    others

  • View
    7

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Security Operations CenterSecurity Operations Center

Security Operations CenterSecurity Operations Center

Petr Kunstat

Microfocus SW

Page 2: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Who of you has Intelligent Security Operational Center

2

Page 3: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Intelligent Security Operational Center depends on …

3

Team size Use cases

Team skills

Infrastructure

Regulation

HW, SW Tools Company

Rules

Ops x Dev x Sec Compliance

Page 4: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Intelligent Security Operational Center depends on …

4

Team size Use cases

Team skills

Infrastructure

Processes

HW, SW Tools Legislation

Ops x Dev x Sec Compliance

PEOPLE TECHNOLOGY PROCESSES

Page 5: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

In all cases the main Objective of SOC

SOC is centralized unit deals with security issues on an organizational & technical level

▪Every second counts- As early as possible; including sophisticated attacks

- Understand the next expected event

- Be able to determine the scope of the attack

- Prevent or mitigate likely business damage

- Learn from detection to improve general security & detection

Detect

AnalyzeRespond

Prevent

Attacks

Page 6: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

PEOPLE

Page 7: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Build on People Experience

9

Page 8: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Train People and Simplify their tasksVisual context

10

Page 9: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Maximize Business Context of Events and Logs

11

Jun 17 2010 12:16:03: %PIX-6-106015: Deny TCP (no connection) from 10.50.215.102/15605 to 204.110.227.16/443 flags

FIN ACK on interface outside

Jun 17 2010 14:53:16 drop gw.foobar.com >eth0 product VPN-1 & Firewall-1 src xxx.xxx.146.12 s_port 2523 dstxxx.xxx.10.2 service ms-sql-m proto udp rule 49

Easy to read and analyze by analyst

Normalization, Categorization

Page 10: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Team expansion Triggers 1->3->10

12

Page 11: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Have technology for SOC under control

13

Page 12: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

TECHNOLOGY

Page 13: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

SOC has to be based on

a Simple, powerful

technology

Open(for innovation)

Analytics(for detection)

3

2

Simple(for you)

1

Page 14: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Finding the Needle in the Haystack

Big Data is the must for 5G/SOC

Page 15: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Intelligent 5G SOC with continuous measures

0) Log collection, Data lakes

1) Compliance –Analysis - Reporting

2) Intelligence – Correlation- Use Cases

3) Detect suspicious behavior

4) Agility – Discovery, Team skills

5) Mitigate false positives

6) Integration – Workflow

7) Big data Analysis, Machine learning

Capabilities – Do I have …. Review

17

Page 16: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

PROCESSES

Page 17: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Triage Process

20

RAW data+ Business

contextCorrelation TRIAGE Incident WF END

L3

L2

L1

Format Preserving Encryption (FPE)

Ex. Tax ID masking

934-753-2356

345-753-5772

Continuous Measures

Regular Feedback

Maturity Audit

Success stories

API

S

[email protected] [email protected] ]ŁĎĂTJtď$Ů˝™µÚNŃ«ěJÝ—OͨAES ECB

Page 18: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Organization of SOC in Bi-Modal IT

▪ Set correctly Interoperability among IT OPS, IT DEV, IT SEC

▪ Set correctly Org Chart (SOC close to CIO)

▪ Set the correct expectation

21

ReactiveProactive VS

Page 19: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

SOC Manager - Reliable Monitoring

22

All product views are illustrations and might not represent actual product screens

Page 20: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

BE STRONG

Page 21: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Top 5 mistakes I saw companies make with SOC

▪ #1 – Lack of organizational support

▪ #2 – Over-reliance on technology

▪ #3 – Basics are overlooked

▪ #4 – Assigning administrative tasks to a SOC

▪ #5 – Focus on compliance

34

Page 22: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Is this a highly successful SOC?

NO!

Page 23: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Characteristics of a Successful SOC

Page 24: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Thank you.

[email protected]

www.microfocus.com

Page 25: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

39

Secure the New

SIEM

Data

Security

Identity

Management

Application

Security

Page 26: Security Operations Center · 2019. 11. 28. · Finding the Needle in the Haystack Big Data is the must for 5G/SOC. Intelligent 5G SOC with continuous measures 0) Log collection,

Intelligent Security Operations – Use case Roadmap

Log Management

• Centralize Logs

• Retain data

• Compliance

Data Analysis

• Forensics

• Rapid Search

• Reporting

Real time alerting

& monitoring

• Detect & identify

• Respond in time

• Build workflow

Security Analytics

• Behavior Profiling

• Threat detection

• Know the unknown

Intelligent Security

Operations

• Integrated monitoring

• People & Process &

Technology

• Efficiency & Resilience