socs for the rest of us

40
SOCs for the Rest of Us By Dave Herrald And Ryan Kovar

Upload: ryan-kovar

Post on 22-Jan-2018

75 views

Category:

Presentations & Public Speaking


2 download

TRANSCRIPT

Page 1: SOCs for the rest of us

SOCs for the Rest of Us

By Dave Herrald

And Ryan Kovar

Page 2: SOCs for the rest of us

Disclaimer

2

During the course of this presentation, we may make forward looking statements regarding

future events or the expected performance of the company. I often lie. Maybe this is a lie.

Wik Alsø wik Alsø alsø wik Wi nøt trei a høliday in Sweden this yër? See the løveli lakes

The wøndërful telephøne system And mäni interesting furry animals The characters and

incidents portrayed and the names used in this Presentation are fictitious and any similarity

to the names, characters, or history of any person is entirely accidental and unintentional.

Signed RICHARD M. NIXON Including the majestik møøse A Møøse once bit my Marcus...

No realli! He was Karving his initials on the møøse with the sharpened end of an

interspace tøøthbrush given him by Svenge – his brother-in-law – a Canadian dentist and

star of many Norwegian møvies: "The Høt Hands of an Canadian Dentist", "Fillings of

Passion", "The Huge Mølars of Horst Nordfink"... In addition, any information about our

roadmap outlines our general product direction and is subject to change at any time

without notice. Splunk undertakës no øbligation either to develøp the features or

functionality described or to include any such feature or functionality in a future release.

Page 3: SOCs for the rest of us

> Dave Herrald @daveherrald

- Senior Security Architect- 20+ years in IT and security

-Information security officer, security architect, pen tester, consultant, SE, system/network engineer

- GIAC GSE #79, former SANS Mentor

# whoami

Page 4: SOCs for the rest of us

• 17 years of cyber security experience

• Worked in US/UK Public Sector and DOD most recently in nation state hunting roles

• Enjoys clicking too fast, long walks in the woods, and data visualization

• Current role on Security Practice team focuses on incident/breach response, threat intelligence, and research

• Currently interested in automating methods to triage data collection for IR analyst review.

• Also investigating why printers are so insubordinate ಠ_ಠ

4

Staff Security Strategist

Minster of the OODAloopers

@meansec

# whoamiRyan Kovar: CISSP, MSc(Dist)

Page 5: SOCs for the rest of us
Page 6: SOCs for the rest of us
Page 7: SOCs for the rest of us
Page 8: SOCs for the rest of us

Agenda•Our Experiences•Hypotheses•Who we interviewed•Synthesize•Things to take home• Conclusions

Page 9: SOCs for the rest of us

What we do @Splunk

Architect Strategist

This That

Page 10: SOCs for the rest of us

Where we go

Page 11: SOCs for the rest of us

Who we see

Page 12: SOCs for the rest of us

Who we see

Page 13: SOCs for the rest of us

We’ve seen it all

I’ve got Bro, Splunk, FireEye. I do OSINT, collect ALL the Logs, and even drink beer

at work.

We don’t need a SOC. We have a guy named Dave. He is

friends with the boss and is great at

computers

Sure I’m secure. I have a Firewall!

Page 14: SOCs for the rest of us
Page 15: SOCs for the rest of us

• Orgs have moved past Tiers• Traditional “Tier 1” jobs are

replaced by automation• Best SOCs have Data

Scientists• No one has a good incident

recording tool• SOCs align to Kill Chain

model

Page 16: SOCs for the rest of us

• Orgs have moved past Tiers• Traditional “Tier 1” jobs are

replaced by automation• Best SOCs have Data

Scientists• No one has a good incident

recording tool• SOCs align to Kill Chain

model

Page 17: SOCs for the rest of us

• Orgs have moved past Tiers• Traditional “Tier 1” jobs are

replaced by automation• Best SOCs have Data

Scientists• No one has a good incident

recording tool• SOCs align to Kill Chain

model

Page 18: SOCs for the rest of us

• Orgs have moved past Tiers• Traditional “Tier 1” jobs are

replaced by automation• Best SOCs have Data

Scientists• No one has a good incident

recording tool• SOCs align to Kill Chain

model

Page 19: SOCs for the rest of us

• Orgs have moved past Tiers• Traditional “Tier 1” jobs are

replaced by automation• Best SOCs have Data

Scientists• No one has a good incident

recording tool• SOCs have similar people

and toolsets

Page 20: SOCs for the rest of us

What we asked

Page 21: SOCs for the rest of us
Page 22: SOCs for the rest of us

We are here to share the best with you

Page 23: SOCs for the rest of us
Page 24: SOCs for the rest of us

People are more important than tools

>

Page 25: SOCs for the rest of us

Trail of Tiers

Page 26: SOCs for the rest of us

The ability to write code was the most valuable technical skill

Page 27: SOCs for the rest of us

Degree typesdidn’t

matter

Page 28: SOCs for the rest of us

Learn to communicating clearly both written and gooder speaking

Page 29: SOCs for the rest of us
Page 30: SOCs for the rest of us

VS

Page 31: SOCs for the rest of us

Curiosity is the most important SOC analyst trait

Page 32: SOCs for the rest of us

Findings

Page 33: SOCs for the rest of us

• Orgs have moved past Tiers• Traditional “Tier 1” jobs are

replaced by automation• Best SOCs have Data

Scientists• No one has a good incident

recording tool• SOCs have similar people

and toolsets

REVIEW

Page 34: SOCs for the rest of us

Orgs have moved past Tiers

REVIEW

Page 35: SOCs for the rest of us

Traditional “Tier 1” jobs are replaced by automation

REVIEW

Page 36: SOCs for the rest of us

Best SOCs have Data Scientists

REVIEW

Page 37: SOCs for the rest of us

No one has a good incident recording tool

REVIEW

Page 38: SOCs for the rest of us

SOCs have similar people and toolsets

REVIEW

Page 39: SOCs for the rest of us

Takeaways

• Lorem

• Ipsum

• And

• Moresum

• ( Blogpost/whitepaper coming soon)

Page 40: SOCs for the rest of us

Dave Herrald

[email protected]

@daveherrald

Ryan Kovar

[email protected]

@meansec

http://blogs.splunk.com/author/rkovar

Contact info