Sunday, August 5, 2018

2018 Security Operations SOC Summit wrap up


2018 SOC Summit is finished, the MGT517 following it is almost done. I'm enjoying co-teaching it with Carson Zimmerman. It's his first time out, and I've enjoyed hearing his perspectives on the material.

I'll hit the high points from the talks with my favorite take away from each. For the TL;DR, have a few memes from the talks.

You should download the talks from here:
https://cyber-defense.sans.org/resources/summit-archives

Carson:
. Measure not just the breadth of your log collection, but the depth
. Unit test your SIEM rules / use cases
. Track your SIEM use case analyst quality
. Analyst baseball card

Shelly & Brett
. Establish Trust and protect it
. Scribe to collect and report: but everyone is repsonsible for taking notes!

Alissa
. Insight into the state of your potential hires. Go read what they are saying about their prospects.
. Chaos is not for everyone
. Bad apples spread bacteria
. Let Alissa talk to your SOC analysts! Figure out the problems and address them.

SOC Survey
. Hard to collect data, and we don't have a defined data set, but here are the highlights for this year's survey.
. Tune in for the webcasts and download the paper.

CompariSIEM
. tools matter, but making the most of the tool is the path to success

FOOD, not FUD
. Framework of 5 items to provide Factual, Objective, Optimized Data

Sun or Stars
. Challenges are abundant, few organizations are thinking about striving for what's best for the long term

Hacking your SOEL:
. Move the activity to the front of the response activity

All about your Assets:
. Identify tools that contain the information you need, and figure out how to connect those tools together

The Healthy SOC: A Case Study:
. I'm going to ask you next year to come give a presentation about how you moved from where you are today to what you are next year. Will we be impressed? ;)


-=-=-=-=-=- ~Day 2~ -=-=-=-=-=-

What the CISO Really Wants
. Have an in person conversation once a month with no computers, no technology, where you listen to understand

Building the SecOps Use Case:
. Develop the program for building and assessing use cases, starting with business use

Back to Basics: System Integrity
. Integrity Monitoring is important for identifying change

TTP Zero:
. Normalize the data to constrained conecpts to effectively and consistenly deliver the message on security operations

Technical to Managerial positions:
. It's a different skillset, you probably can't be both

Threat Hunting Tour de Force
. Start with ad hoc techniques then migrate them into procedures

Burning Down the Haystack
. operational tasks should be operational, identify pain points and fix them

Most Dangerous Game:
. Assess if you have full coverage using ATT&CK

Monday, April 2, 2018

Metrics, metrics, everywhere and not a lot of thinking

Someone sent me a personal e-mail asking for guidance on metrics, so I thought I would replicate that here publicly.

Also, Carson Zimmerman will keynote at the SOC Summit in New Orleans in August, 2018 with a talk specifically on metrics. Hopefully you can make it to that event. If you can't make it, you can check out that talk afterward via video.

When starting out, I'd pick 3-5 reported metrics and a couple of service level objectives to start. Too many metrics results in diminished clarity on if you're meeting the objectives of the organization.
Metric
. Time to detection
. Method of Detection
. Time to initiate Response
.  Root cause analysis: Level 1,2,3. 
1 is a measure was available, but wasn't applied
2 is a measure was available, we chose through risk acceptance not to apply and it allowed issue to occur
3 is "zero day" - no measure was available
Service Level Objectives
. Initial notification within 1 hour to system owners of affected systems
. Eradication results in final closure, no need to reopen 100% of time


Online resource, look at Veris, which is the data schema behind the Verizon DBIR:

Look at Pescatore's "briefing the board" info:

For a book to read on metrics, the standard reference is Joqaith's Security Metrics:

Also look at the Hubbard / Siersen  "how to measure risk" book. Rich gave a talk last year at the SOC summit, but I don't see the talk posted. 




Sunday, September 17, 2017

File under #failure

Equifax announced a massive breach of tax payer information.

TL;DR : Lock your credit accounts:

https://www.experian.com/freeze/center.html#content-01
https://www.innovis.com/securityFreeze/index
https://www.transunion.com/credit-freeze/place-credit-freeze2
https://www.freeze.equifax.com/Freeze/jsp/SFF_PersonalIDInfo.jsp


Basic recommendation, freeze your credit report. This does two things. First, it protects you. Second, if most US taxpayers freeze their credit it will change the way these companies do business. They're collecting information about you and reselling it to third parties. They'll charge you a fee (credit monitoring) to protect that information. In my opinion it is perverse that they'll only protect your information for a fee. It will be interesting to see how the class action law suits which follow will shape the credit monitoring services.

I'm also interested in how the Internal Revenue Service (IRS) of the United States addresses this. They've been pretending for two decades too long that the social security number is somehow a shared secret. It is not. Time to re-key, IRS. You have suffered a data breach through an irresponsible vendor partner. You've allowed these vendors to leverage your information for far too long. Fix this broken system.

Tuesday, June 6, 2017

SANS SOC Summit 2017

A quick listing from each talk on TODO items that I extracted from the presentation.

The presentations are available here:
https://cyber-defense.sans.org/resources/summit-archives

Day 1

Keynote Good vs Evil: Winning the Age Old Battle
Doug Burks (@dougburks), CEO, Security Onion Solutions LLC
TODO: Practice Japanese. More work on motivating people to perform optimally.


Stuck in the Box: A SIEM's Tale
Justin Henderson (@SecurityMapper), Systems and Security Architect, GSE # 108, Cyber Guardian Red/Blue
TODO: Develop a list of "go to" Event IDs

How to Measure Anything in the SOC
Rich Seiersen, Former General Manager - Cyber Security & Privacy, GE Healthcare
TODO: Develop predictive analytical model for SOC (and read Rich's book)

Metrics for Justifying SOC Investment to the CEO and Board
John Pescatore, Director of Emerging Security Trends, SANS Institute
TODO: Decide on key performance indicators and develop report / dashboard to depict them.

Debunked: Traditional IR Calls
Gregory Braunton, National Director, Threat Management, Incident Response and Forensics, Catholic Health Initiatives
TODO: Visual collaboration tool. (Reminds me also to develop the ACH rubrics for common incident scenarios.)

Siri for SOC: How an Intelligent Assistant can Augment the SOC Team
Bobby Filar (@filar), Sr. Data Scientist, Endgame
Rich Seymour, Sr. Data Scientist, Endgame
TODO: Develop question based playbook for analysts.

The Need for Investigation Playbooks at the SOC
Matias Cuenca-Acuna, Principal Engineer, Intel Security

Ismael Valenzuela, SANS Certified Instructor, GSE #132; Global Director of Foundstone Consulting Services
TODO: Differentiate response playbook and investigative playbook, refine current playbook.


Day 2


Keynote: Survey Says: Actionable Insights from the SANS SOC Survey
Chris Crowley (@CCrowMontance), SANS Institute
TODO: Build a survey that captures a representative sample of SOCs globally.


SIEMple Simon Met a WMIman
Craig L. Bowser, Sr. Security Engineer, Dept. of Energy
TODO: Adapt this for SOC Analysts, and have a punch list of checks to be sure they're accomplishing these checks.

Inattentional Blindness (IB) & Security Monitoring
Ismail Cattaneo, Sr. Manager of Security Operations & Engineering, Verizon Enterprise Solutions
TODO: Pay attention, and keep working on a converged analytical methodology between "Organizational Dimensions, Analysis of Competing Hypotheses, Kill Chain, and Diamond Model"

Hunting Adversaries with "rastrea2r" and Machine Learning
Gabriel Infante-Lopez, Software Architect & Data Science, Intel Security
Ismael Valenzuela, SANS Certified Instructor, GSE #132; Global Director of Foundstone Consulting Services
TODO: Look at the open source project for collecting information between disparate tools.

Color My Logs: Understanding the Internet Storm Center
Johannes Ullrich, PhD, Dean of Research, SANS Technology Institute
TODO: Look for ways to enrich information in SOC data with restful information from within SANS ISC. Install a Raspberry Pi.

SOCs for the Rest of Us
Dave Herrald (@daveherrald), GSE #79, Senior Security Architect, Splunk
Ryan Kovar (@meansec), Staff Security Strategist, Splunk
TODO: Take the questions Dave and Ryan used and turn it into an assessment capability.

Building the Cybersecurity Workforce We Need: Creating Pipelines and Pathways Without Poaching
Arlin Halstead, Strategic HR Business Partner, NTT Security
Maxwell Shuftan (@SANSCyberTalent), Director of CyberTalent Solutions, SANS Institute
TODO: Refine hiring standard questions and look at retention methodology.

DDoS Attacks in Action
Ben Herzberg, Security Research Group Manager, Imperva Incapsula
TODO: Practice Python. Inventory DDoS vulnerability assessment and remediation tools.

Tuesday, April 25, 2017

Threat Hunting Summit 2017 and MGT517.2017.2

I had the opportunity to see many great talks, but missed just as many due to obligations and getting other work done. If you didn't get to attend the THIR summit, the high quality videos should be online soon here:

https://www.sans.org/event/threat-hunting-and-incident-response-summit-2017/summit-videos/

If you are interested in my talk, you can see the powerpoint here:

https://bit.ly/crow-th

More elaboration on the security operations functional areas here:

http://www.montance.com/mgt517

Thank you to the people who took the time to chat with me about their opinions or experience on the topics I covered. It's tough to present a complete system in 30 minutes. I hope your organization has a strategic vision for what your security operations is going to be. If you don't, steal my diagram from the bit.ly link above and start to plan for how your functions can work together to optimize your scarce resources.

Also, much appreciation to the folks who attended MGT517. I was impressed by the discussions we had. I feel like I learn a massive amount each time I teach. Some of it is validation of the opinions I hold, some of it is a challenge to my approach. Criticism and permutations help to refine the system. I'm excited about a few things that I'm going to incorporate. First is the notion of a more data-centric depiction of the metrics I advocate for the SOC. Another enhancement planned for the next revision is a deeper dive into threat hunting scenarios. Finally, ACH brainstorm templates for incident types to encourage analysts to employ ACH, Kill Chain, and Diamond Model as analytical tools.

Wednesday, April 19, 2017

Positive feedback

...never has a SANS track been more relevant, timely, thorough, and pragmatic as I found the MGT517 course to be. In my opinion, Chis (and I am quite sure an entire team of reviewers) has thought of, considered, and addressed every issue that I have encountered in my journey to standing up an internal SOC at my company.
Positive thoughts. There are many things I'd like to refine within the class, but I appreciate the acknowledgement.

Friday, April 14, 2017

MGT517 Hot Wash - Orlando - 2017-04-14

MGT517 Hot Wash - Orlando - 2017-04-14

The first official run of MGT517 just wrapped up in Orlando, FL.

Primary take away messages from the attendees.
1. There are a number of companies trying to build a SOC, but they're not exactly sure what a SOC is.
2. Political issues are more difficult to overcome than technical problems.
3. I'm roughly 12-18 months late on this class. A common comment from people, "I wish I had taken this class 12 months ago when I started building the SOC for ____ company."

Some improvements I plan to make:
1. In the Design discussion, depict the ways we're going to cover the material in the build, operate, and mature sections. (TODO - near term)
2. Set up a website with resources for reference (TODO - near term).
3. Adjust the metrics to present the balanced scorecard approach, and include some of the examples that John Pescatore gave in his lunch time talk to the class. (TODO - near term)
4. Enhance the swimlane diagram depicts the functional area process relationships with updated inputs, people, artifacts, and technology. (TODO - ongoing)

I was pleased by the excellent attendees. Lots of great discussion and insight shared by people. A benefit of the class is making the connections with the small number of other professionals in the space.

Finally, I'm thrilled at the overwhelming response of people to attend the course. I know that it is full for the next couple of runs. Anyone who is unable to get into the class, please be patient, we're running the course many times this year. Take a look at the events later this year. If the demand is persistent, I'll work with SANS to add additional runs this year.