modernizing infosec training and it operations at usf infosec training and it operations at usf ......

67
Modernizing InfoSec Training and IT Operations at USF Goodbye Tedious Tasks! A Novel Automation Framework Leveraging Splunk Tim Ip, Senior Security Engineer Nicholas Recchia, Director & Information Security Officer September, 2017 | Washington, DC

Upload: vutu

Post on 20-Mar-2018

220 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Modernizing InfoSec Training and IT Operations at USFGoodbye Tedious Tasks!A Novel Automation Framework Leveraging Splunk

Tim Ip, Senior Security Engineer

Nicholas Recchia, Director & Information Security Officer

September, 2017 | Washington, DC

Page 2: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

During the course of this presentation, we may make forward-looking statements regarding future events or

the expected performance of the company. We caution you that such statements reflect our current

expectations and estimates based on factors currently known to us and that actual events or results could

differ materially. For important factors that may cause actual results to differ from those contained in our

forward-looking statements, please review our filings with the SEC.

The forward-looking statements made in this presentation are being made as of the time and date of its live

presentation. If reviewed after its live presentation, this presentation may not contain current or accurate

information. We do not assume any obligation to update any forward looking statements we may make. In

addition, any information about our roadmap outlines our general product direction and is subject to change

at any time without notice. It is for informational purposes only and shall not be incorporated into any contract

or other commitment. Splunk undertakes no obligation either to develop the features or functionality

described or to include any such feature or functionality in a future release.

Splunk, Splunk>, Listen to Your Data, The Engine for Machine Data, Splunk Cloud, Splunk Light and SPL are trademarks and registered trademarks of Splunk Inc. in

the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners. © 2017 Splunk Inc. All rights reserved.

Forward-Looking Statements

THIS SLIDE IS REQUIRED FOR ALL 3 PARTY PRESENTATIONS.

Page 3: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

▶ University of San Francisco (USF) more than 12,000 students, faculty and staff

▶ Catholic Jesuit Education

About Us

Page 4: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

About Me

▶ Tim Ip

• Senior Security Engineer

• Leverages Splunk to automate processes in USF

• From Hong Kong 2 years ago

• 10+ years experience in security industry and 6+ years experience on SIEM development

• Previous worked for a consulting company as a SIEM consultant

• Primary focus on Security monitoring, process automation and big data analytics

• Holds a master degree, OSCP, GPEN, CISSP, CISA and CISM

• GitHub / LinkedIn / Twitter: timip.net

Page 5: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

▶ Nick Recchia

• Director & Information Security Officer

• USF Alumnus

• 12+ years experience in Information Technology and 8+ years focused on InfoSec with integration

• Manages the security group and oversee related InfoSec programs

• Holds doctorate degree in Organization and Leadership, CISSP, PMP, ITILv3, etc.

• LinkedIn

About Me

Page 6: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

▶ Ch.1 – Background & Context

• InfoSec training: from manual methods to strategic innovation

▶ Ch.2 – Course Automation

• Methodology and technical highlights

▶ Ch.3 – IT Automation

• Reuse methodology

▶ Key Takeaways

▶ Q&A

AgendaOur Splunk Journey

Page 7: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Background & Context

InfoSec training: from manual methods to strategic innovation

Page 8: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Background: Technology Transformation Manual methods to strategic innovations

Page 9: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Automation

Background: Technology Transformation Manual methods to strategic innovations

?

Current State

(2015)Future State

(2017)

Page 10: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Background: Infosec Training @ USFTimeline: required security training

~2007

New employee

orientation

Orientation

revamped

cutting ISO

2010

SANS Security The

Human (STH)2014

Splunk

(SIEM)

2015

Rebuilt

InfoSec

Team

New CIO

2016

ITS Division

Re-org

How?Model after

Harassment

training?

Security

Training

Splunk

POC

Page 11: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Context: Infosec Training @ USFConceptual Development

Automation

Technology

People

Process

Page 12: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Process:

• Enrollment?

• Monitoring progress?

• Encourage

completion?

Technology:

People:

InfoSec

Team

InfoSec CourseContext: People, Process and Technology

Enrollment (3000 people)

Employee, Faculty & Affiliate<<

Page 13: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Context: Enrollment High-level: Leverage Existing Process

HR processes new

employee into

Banner

Banner Enterprise

Resource Planning

(ERP)

Start date

confirmed

Nightly

update

USF LMS

InfoSec Course

Page 14: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Context: Monitor ProgressHigh-level: Automated Course Alerts & Mgmt. Reports

Banner ERP

USF LMS

InfoSec Course

Correlation and

Alerting - SIEM

Page 15: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Concept: Auto AlertsHigh-level: Inform, Remind, Escalate

Page 16: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Context: Infosec Training @ USFConceptual formula

Automation

Splunk

Ninja

Business

Intel

Trusted Partnership

Page 17: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Course Automation

Page 18: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Framework IntroductionUse Case: InfoSec Course Automation

1. Course Data

Input2. Actions

3. Intelligence

Input

4. Knowledge

InfoSec

Course

Automation

Page 19: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

How to make it happen?

KnowledgeCourse Data

Intelligence

Actions

Page 20: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Splunk@USF

On-Premise

Data from

external 3rd party

systems

User

EndpointsInfra.Data from

other systems

SplunkCloud>

Splunk Heavy

Forwarder

Splunk Heavy

Forwarder

on AWSSearch Head

Page 21: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Splunk@USF

On-Premise

Data from

external 3rd party

systems

User

EndpointsInfra.Data from

other systems

SplunkCloud>

Search Head

Splunk Heavy

Forwarder

Provides:

• Filtering

• Compression

• Encryption

Splunk Heavy

Forwarder

on AWS

Page 22: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Splunk@USF

On-Premise

Data from

external 3rd party

systems

User

EndpointsInfra.Data from

other systems

SplunkCloud>

Splunk Heavy

Forwarder

Splunk Heavy

Forwarder

on AWS

Provides:

• Customized Automation

• Development

Environment

Search Head

Page 23: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Architecture

Course Data

Intelligence

Actions

Knowledge

Page 24: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

1. Course Data Input

For InfoSec Course

Page 25: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Architecture

Knowledge

Intelligence

ActionsCourse Data

Page 26: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Canvas Integration

CANVAS Raw

Data

API

• Gradebook History

• Assignment Submission

• Enrollments

• Section

• User List

• Ana Student Summaries

• Course Assignment

SPLInfoSec

Student

Status

Snapshot

Page 27: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Canvas IntegrationDashboard

Actionable?

Page 28: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Ninja BrainstormingWe need something more actionable

How to give access to the division leads?

Send the information to them an email?

InfoSec Team Division Leads need to access to

the data to monitor their staff progress!

Page 29: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Ninja BrainstormingWe need something more actionable

Email Report? No!

I need to make the email more user

friendly!

Page 30: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

2. Actions

For InfoSec Course

Page 31: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Course Data

Architecture

Knowledge

Intelligence

Actions

Page 32: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

To Students:

• Welcome Email

• Reminder Email

• Overdue Email

NotificationType of notification

To division leads:

• Monthly Report

• Escalation Report

Page 33: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

▶ Not user friendly

▶ Lack of enforcement

▶ Not Actionable

Default Alert Notification

Page 34: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

▶ User friendly email

▶ Dynamic information from Splunk

▶ Flexible and reusable

Customized Email NotificationsGoals

Page 35: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Customized Email Notification SchedulerCustomized Email Scheduler

Search Head

Email Template

Splunk Query

___ ____ Results

Email

Scheduler

• Expanding results

• Replace tokens

with query results

• Loop

• Send out email

Page 36: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

© 2017 SPLUNK INC.

Customized Email Notification

For Student

▶ Reminder, Due Date Approaching and Due Date Overdue Alert

• All dynamic information from Splunk query

• Customized “Add to Calendar” Link

Page 37: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

© 2017 SPLUNK INC.

Customized Email Notification

For Executive

▶ Executive Report

• Statistics by role

• Overview and details

Page 38: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

© 2017 SPLUNK INC.

Customized Email Notification

For Executive

▶ Executive Report

• Statistics by role

• Overview and details

Page 39: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow
Page 40: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Ninja BrainstormingLack of Enforcement

Will students ignore the notification?

How to influence the action?

Escalate to supervisor!

Hmm… Where can we get the

supervisor information?

Page 41: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

3. Intelligence Input

For InfoSec Course

Page 42: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

ActionsCourse Data

Architecture

Knowledge

Intelligence

Page 43: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Banner/ServiceNow – Splunk Integration

Daily Batch JobERP

SPL

User

Inventory

Splunk AppsITSM ServiceNow

Raw Data

Banner Raw

Data

Page 44: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Ingest ERP DataBanner: Escalation Data

Employee Supervisor

Tim Nick

Vince Nick

Nick Opinder

Michael Nick

Opinder PaulEmployee Escalation Path

Tim Tim, Nick, Opinder, Paul

Vince Vince, Nick, Opinder, Paul

Nick Nick, Opinder, Paul

Michael Michael, Nick, Opinder, Paul

Opinder Opinder, Paul

Page 45: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

▶ Roles

▶ Department

Ingest ITSM dataServiceNow: User Profile

Page 46: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

4. Knowledge

For InfoSec Course

Page 47: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Intelligence

ActionsCourse Data

Architecture

Knowledge

Page 48: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Business LogicFrom complex business requirements and SPL queries

Day 10

Courtesy Reminder

(Employee)

Day 30

Manager Escalation

(Employee, Supervisor and

Manager)Day 1

Welcome Email

(Employee)

Day 27

Due Date Approaching

(Employee and Supervisor)

Course

Completed

If user completed the course,

they will receive a

congratulation email.

(Employee)

We will listed on department head

escalation report.

Page 49: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Knowledge

Business

Knowledge

Splunk SPL

Query /

dashboard/

automation

Ninja

Experience/Skills

Page 50: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

SPL Queries

SPL

ServiceNow

Raw Data

Banner Raw

Data

User

Inventory

CANVAS Raw Data

InfoSec

Course

Student

Status

Snapshot

SPL

SPL Dashboards

EmailsSPL

Page 51: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Results

InfoSec Course

Page 52: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Use CaseFor supporting InfoSec Course Automation

• Enrollment

• Score

• Assignment

1. Machine

Data• Customized Email

Notification Scheduler

2. Actions

• ServiceNow: User Inventory

• Banner: Escalation Path

3. Intelligence

• Business Logic

• Splunk Ninja

• Splunk SPL Query

4. Knowledge

InfoSec

Course

Automation

Page 53: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Normal NotificationNotification vs Completion

Page 54: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Management EscalationNotification vs Completion

Page 55: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Course Data

Actions

Intelligence

Knowledge } InfoSec Course

Automation

Page 56: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Machine Data

Adaptive Responses

Intelligence

Knowledge } IT InfoSec Course

Automation

Page 57: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

IT Automation

Page 58: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

USF Automation Framework

Machine

Data

Adaptive

Responses

Intelligence

Knowledge

Automation

Framework

• OS/Application Log

• App from Splunkbase

• Customized API

• Self-Service Notification

• ServiceNow Ticket Creation

• CMDB

• User Profile

• Escalation Path• Business Logic

• Splunk Ninja

• Splunk SPL Queries

Page 59: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

External

▶ Splunkbase

• e.g.: Splunk Add-on for Facebook ThreatExchange

▶ Customized Threat Intelligence Download

• https://github.com/timip/threatintel

Internal

▶ User Inventory (Human)

▶ CMDB (Machine)

Intelligence Inputs

Page 60: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Adaptive ResponsesHuman

Students Faculty

Employee/ Affiliate

Customized

Email

ServiceNow

Ticket

Customized

Email

ServiceNow

Ticket

Slack

Channel

Severity

Page 61: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Adaptive ResponseSelf Service Notification

Page 62: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Adaptive ResponsesNext Step: Human + Machine

Students Faculty

Employee/ Affiliate

Customized

Email

ServiceNow

Ticket

Customized

Email

ServiceNow

Ticket

Slack

Channel

MachineTrigger

Antivirus

Full Scan

Apply new IP

blocking

firewall rule

And more…

Page 63: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Knowledge

Business

Requirements

Splunk SPL

Query

Ninja Experience

Page 64: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Adaptive

Response

Machine Data

Input

Intelligence

Input

Knowledge

InfoSec Course

Automation

PCI Password

Expired Notification

PCI Anti-Virus Problem

Notification

Expanding Use CasesIncrease automation to IT

Canvas Banner /

ServiceNowEmail

Splunk Ninja +

Business Intel

Domain Controller

User List

ServiceNow User

Profile

Email

Sophos Log ServiceNow CMDB Email /

ServiceNow Ticket

Splunk Ninja +

Business Intel

Splunk Ninja +

Business Intel

Page 65: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

© 2017 SPLUNK INC.

Key Takeaways

People:

• Trusted partnership - business intel/company culture & Splunk Ninja skills

Technology

• Splunk - reuse valuable data for various use cases – security, IT operations, beyond

Process

• Transition data/business intelligence in to queries/actions

Automation: Turn data/intelligence into answers

and/or actions

Page 66: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

Q&A

Tim Ip | Senior Security Engineer

Nicholas Recchia | Director & Information Security Office

Page 67: Modernizing InfoSec Training and IT Operations at USF InfoSec Training and IT Operations at USF ... •InfoSec training: from manual methods to strategic innovation ... ServiceNow

© 2017 SPLUNK INC.

Don't forget to rate this session in the

.conf2017 mobile app

Thank You