security operations: moving to a narrative-driven model...2015/03/31  · security operations:...

11
Josh Goldfarb VP, CTO - Americas Security Operations: Moving to a Narrative-Driven Model

Upload: others

Post on 17-Oct-2020

4 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Security Operations: Moving to a Narrative-Driven Model...2015/03/31  · Security Operations: Moving to a Narrative-Driven Model 229 DAYS MEDIAN NUMBER OF DAYS BEFORE DETECTION 67%

Josh Goldfarb – VP, CTO - Americas

Security Operations:

Moving to a Narrative-Driven Model

Page 2: Security Operations: Moving to a Narrative-Driven Model...2015/03/31  · Security Operations: Moving to a Narrative-Driven Model 229 DAYS MEDIAN NUMBER OF DAYS BEFORE DETECTION 67%
Page 3: Security Operations: Moving to a Narrative-Driven Model...2015/03/31  · Security Operations: Moving to a Narrative-Driven Model 229 DAYS MEDIAN NUMBER OF DAYS BEFORE DETECTION 67%

229 DAYSMEDIAN NUMBER OF DAYS BEFORE DETECTION

67% 100%OF COMPANIES LEARNED THEY WERE BREACHED FROM AN EXTERNAL ENTITY

OF VICTIMS HADFIREWALLS OR UP-TO-DATEANTI-VIRUS SIGNATURES

Page 4: Security Operations: Moving to a Narrative-Driven Model...2015/03/31  · Security Operations: Moving to a Narrative-Driven Model 229 DAYS MEDIAN NUMBER OF DAYS BEFORE DETECTION 67%

UNDERSTANDING THE ATTACK

ATTACKERS UTILIZE MULTIPLE VECTORS

AND MULTIPLE FLOWS TO COMPLETE THEIR MISSION

Page 5: Security Operations: Moving to a Narrative-Driven Model...2015/03/31  · Security Operations: Moving to a Narrative-Driven Model 229 DAYS MEDIAN NUMBER OF DAYS BEFORE DETECTION 67%

CONTINUOUS SECURITY MONITORING

Page 6: Security Operations: Moving to a Narrative-Driven Model...2015/03/31  · Security Operations: Moving to a Narrative-Driven Model 229 DAYS MEDIAN NUMBER OF DAYS BEFORE DETECTION 67%

How long have I been under attack?

What was the extent of the damage?

What are the Indicators of Compromise?

So Many Important Questions

Copyright © 2014, FireEye, Inc. All rights reserved.

How many endpoints are infected?

What are the Indicators of Compromise?

Page 7: Security Operations: Moving to a Narrative-Driven Model...2015/03/31  · Security Operations: Moving to a Narrative-Driven Model 229 DAYS MEDIAN NUMBER OF DAYS BEFORE DETECTION 67%

Challenges: Alert-Driven Detection Model

Challenges

Alerts lack context, making accurate and

timely detection difficult

Forensics technologies lack performance

for immediate response

Snapshot, moment in time

Limited context, “straw” view

One detail, not the whole story

Manual context-building

Not timely

Precise data extraction challenging

1

2

Page 8: Security Operations: Moving to a Narrative-Driven Model...2015/03/31  · Security Operations: Moving to a Narrative-Driven Model 229 DAYS MEDIAN NUMBER OF DAYS BEFORE DETECTION 67%

Putting Together the Story: Narrative Driven Security

What does the complete picture look like?What is my exposure?

Forensics

Did the attack succeed?What else can I learn about the attack?

Network

Where is the attack destined?Do I see artifacts of intrusion?

Endpoint

Page 9: Security Operations: Moving to a Narrative-Driven Model...2015/03/31  · Security Operations: Moving to a Narrative-Driven Model 229 DAYS MEDIAN NUMBER OF DAYS BEFORE DETECTION 67%

COMPONENTS THAT BUILD THE NARRATIVE

TECHNOLOGY

EXPERTISE

INTELLIGENCE

Page 10: Security Operations: Moving to a Narrative-Driven Model...2015/03/31  · Security Operations: Moving to a Narrative-Driven Model 229 DAYS MEDIAN NUMBER OF DAYS BEFORE DETECTION 67%

How?

• Identify risks, goals, and priorities• Identify gaps in telemetry• Develop content• Improve signal-to-noise ratio• Concentrate into unified work queue• Enrich with supporting evidence• Automate common analysis steps• Interleave intelligence• Present the narrative

Page 11: Security Operations: Moving to a Narrative-Driven Model...2015/03/31  · Security Operations: Moving to a Narrative-Driven Model 229 DAYS MEDIAN NUMBER OF DAYS BEFORE DETECTION 67%

@ananalytical