security analytics using elk stack

12

Click here to load reader

Upload: cysinfo-cyber-security-community

Post on 12-Apr-2017

262 views

Category:

Software


3 download

TRANSCRIPT

Page 1: Security Analytics using ELK stack

Security Analytics Using ^^^ Stack

Abhishek Bhuyan

Page 2: Security Analytics using ELK stack

ELKB Stack

Page 3: Security Analytics using ELK stack

DisclaimerThis is more of demo session than slides...

Page 4: Security Analytics using ELK stack

Elasticsearch ● Distributed and Analytics Engine

○ Query anything - structured, unstructured, geo, metric○ Analyze - Explore trends and patterns○ RESTfulAPI○ Schema Free, JSON Documents○ Fast and Horizontally Scalable

Page 5: Security Analytics using ELK stack

Logstash ● Data Processing Pipeline

○ Ingest Data, Process and Output■ Ingest Data of many sources (Input Plugins)■ Parse & Transform data on the fly (Filter Plugins)■ Change Data Representations (Codec Plugins)■ Output data to many forms (Output Plugins)

Page 6: Security Analytics using ELK stack

Beats ● Lightweight Data Shippers

○ Data Gathering■ Filebeat■ Metricbeat■ Packetbeat■ Winlogbeat■ Heartbeat

Page 7: Security Analytics using ELK stack

Kibana ● Explore, Visualise, Discover Data

○ Interactive Visualization○ Custom Dashboards

Page 8: Security Analytics using ELK stack

Evolution of Cyber Threats

Page 9: Security Analytics using ELK stack

Evolution of Cyber Threats

Page 10: Security Analytics using ELK stack

What is Analytics?

● Data Driven approach for analyzing logs● Ask the right question and then figure out what data you need

to answer it○ Helps in modeling your data○ Helps in choosing the technology or tools you want to use

Page 11: Security Analytics using ELK stack

Let’s Demo

Page 12: Security Analytics using ELK stack

“The goal is to turn data into information, and information into insight.”

– Carly Fiorina, former CEO, Hewlett-Packard Co.