1
00:00:00,060 --> 00:00:00,900
In this lesson,

2
00:00:00,900 --> 00:00:03,000
we're going to talk about dashboards.

3
00:00:03,000 --> 00:00:05,100
Now, dashboards are a graphical display

4
00:00:05,100 --> 00:00:07,464
of information across multiple different systems,

5
00:00:07,464 --> 00:00:10,140
and generally we're going to use a dashboard inside

6
00:00:10,140 --> 00:00:12,990
of our security operations center as part of a single pane

7
00:00:12,990 --> 00:00:14,184
of glass architecture.

8
00:00:14,184 --> 00:00:17,010
Now, a single pane of glass essentially means I'm going to have

9
00:00:17,010 --> 00:00:18,900
one screen in front of me as an analyst,

10
00:00:18,900 --> 00:00:21,390
and I can access everything across the organization

11
00:00:21,390 --> 00:00:22,920
from that one panel.

12
00:00:22,920 --> 00:00:24,510
And when I'm looking at that one panel, I need

13
00:00:24,510 --> 00:00:26,760
to be able have a dashboard so I can see exactly what's

14
00:00:26,760 --> 00:00:28,680
going on of all of the different systems

15
00:00:28,680 --> 00:00:31,080
across the network and across the world.

16
00:00:31,080 --> 00:00:33,210
For example, one of the most popular tools to create one

17
00:00:33,210 --> 00:00:35,130
of these interactive style dashboards is

18
00:00:35,130 --> 00:00:36,660
a tool known as Splunk.

19
00:00:36,660 --> 00:00:39,540
Splunk is a big data platform that allows the ingestion

20
00:00:39,540 --> 00:00:41,520
of all sorts of different kinds of data,

21
00:00:41,520 --> 00:00:44,220
including security data, incident response data,

22
00:00:44,220 --> 00:00:45,840
and other data like that.

23
00:00:45,840 --> 00:00:47,400
When we have a tool like Splunk,

24
00:00:47,400 --> 00:00:50,010
it can collect data from your firewalls, your applications,

25
00:00:50,010 --> 00:00:51,750
your endpoints, your operating systems,

26
00:00:51,750 --> 00:00:53,010
your intrusion detection systems,

27
00:00:53,010 --> 00:00:55,590
your intrusion prevention systems, your antivirus software,

28
00:00:55,590 --> 00:00:57,450
your networks, and all of this data

29
00:00:57,450 --> 00:00:59,037
can get rolled up into this big data platform.

30
00:00:59,037 --> 00:01:02,010
And then creating a dashboard will allow you

31
00:01:02,010 --> 00:01:03,960
to see the trends over time,

32
00:01:03,960 --> 00:01:05,870
and then you can take actions based on those trends.

33
00:01:05,870 --> 00:01:08,730
For example, if we take a look at a sample dashboard

34
00:01:08,730 --> 00:01:10,320
from Splunk, you can see here

35
00:01:10,320 --> 00:01:13,140
that this shows my basic security posture of the network.

36
00:01:13,140 --> 00:01:14,460
In this case, we can see

37
00:01:14,460 --> 00:01:16,320
that there are access notables going down.

38
00:01:16,320 --> 00:01:18,540
It's actually three less than it was previously.

39
00:01:18,540 --> 00:01:21,660
We can see the endpoint notables going up by 22, bringing us

40
00:01:21,660 --> 00:01:23,550
to a total count of 2000.

41
00:01:23,550 --> 00:01:25,080
And that's red because it's something bad

42
00:01:25,080 --> 00:01:28,020
and we want to look at, we also see network notables going

43
00:01:28,020 --> 00:01:30,300
down, which means our network is getting more secure

44
00:01:30,300 --> 00:01:32,310
and we see identity notables going down,

45
00:01:32,310 --> 00:01:33,780
which tells us we're actually doing a better job

46
00:01:33,780 --> 00:01:35,706
of protecting the privacy of our organization.

47
00:01:35,706 --> 00:01:38,430
We also have things like infections from our antivirus,

48
00:01:38,430 --> 00:01:39,990
and you can see this went up by one,

49
00:01:39,990 --> 00:01:41,549
so this was a red or negative trend.

50
00:01:41,549 --> 00:01:44,189
And then we also have our threat notables going up by 60,

51
00:01:44,189 --> 00:01:46,740
which means there were 60 more attacks this week

52
00:01:46,740 --> 00:01:48,300
than there was last week.

53
00:01:48,300 --> 00:01:50,730
Additionally, you can look down at different graphs

54
00:01:50,730 --> 00:01:52,620
and you can see things like, how is the status

55
00:01:52,620 --> 00:01:54,120
of your vulnerability scanning?

56
00:01:54,120 --> 00:01:55,380
And then if we move down the page,

57
00:01:55,380 --> 00:01:57,450
we can see two different graphs.

58
00:01:57,450 --> 00:01:59,389
On the left side, we have our notable events occurrence

59
00:01:59,389 --> 00:02:01,500
by urgency, and you'll notice

60
00:02:01,500 --> 00:02:03,150
that these are basically the same urgency

61
00:02:03,150 --> 00:02:05,220
that we talk about in vulnerability scanning.

62
00:02:05,220 --> 00:02:08,430
We have unknown, informational, low, medium, high,

63
00:02:08,430 --> 00:02:10,949
and critical, and our goal is to get the criticals down

64
00:02:10,949 --> 00:02:13,230
as low as possible, and we can allow things like

65
00:02:13,230 --> 00:02:15,660
informational or lows to be a little bit higher.

66
00:02:15,660 --> 00:02:17,529
In this network, we can see that the urgency

67
00:02:17,529 --> 00:02:19,853
of critical is actually only 10 things,

68
00:02:19,853 --> 00:02:21,832
but if we go into our mediums, highs

69
00:02:21,832 --> 00:02:24,090
or criticals, we're looking somewhere

70
00:02:24,090 --> 00:02:27,330
between 800 and 2000 in terms of the amount

71
00:02:27,330 --> 00:02:30,030
of notable events for each of those criticality levels.

72
00:02:30,030 --> 00:02:32,610
So as an executive, I would be looking at this

73
00:02:32,610 --> 00:02:35,040
and going, "Okay, we have a very large network

74
00:02:35,040 --> 00:02:37,440
and only 10 criticals, which is great,

75
00:02:37,440 --> 00:02:39,090
but we also need to look at those 10 criticals

76
00:02:39,090 --> 00:02:41,040
and see how we can get them down to zero."

77
00:02:41,040 --> 00:02:43,050
The other thing we have is on the right hand side,

78
00:02:43,050 --> 00:02:44,653
we can see the trends over time.

79
00:02:44,653 --> 00:02:46,973
Here, we can see that over the last 24 hours we had,

80
00:02:46,973 --> 00:02:51,000
on average the threat was around 100 counts.

81
00:02:51,000 --> 00:02:53,310
There were some things that were higher and some were lower.

82
00:02:53,310 --> 00:02:55,170
As you can see in the last hour or so,

83
00:02:55,170 --> 00:02:57,360
at the time of this dashboard, we see a spike

84
00:02:57,360 --> 00:02:59,580
of red going up, which is the endpoint area,

85
00:02:59,580 --> 00:03:01,020
which is showing that we went from the hundred,

86
00:03:01,020 --> 00:03:03,630
which was kind of our baseline up to a thousand.

87
00:03:03,630 --> 00:03:06,150
So this sounds like we're actually under attack in terms

88
00:03:06,150 --> 00:03:07,770
of our endpoints, and we'd want to figure out why

89
00:03:07,770 --> 00:03:09,171
that is and what's going on there.

90
00:03:09,171 --> 00:03:10,770
Now with all of these, because you're dealing

91
00:03:10,770 --> 00:03:12,450
with a dashboard, you can actually click on it

92
00:03:12,450 --> 00:03:14,160
and drill down into it.

93
00:03:14,160 --> 00:03:16,470
When you look at something in the bottom right, for example,

94
00:03:16,470 --> 00:03:18,792
we can see the top notable event occurrence by host,

95
00:03:18,792 --> 00:03:21,210
and we can see that the top host there,

96
00:03:21,210 --> 00:03:24,291
which is at IP address, 10.1.21.153

97
00:03:24,291 --> 00:03:26,220
has quite a few spikes there,

98
00:03:26,220 --> 00:03:28,269
which means we actually had seven

99
00:03:28,269 --> 00:03:29,853
different counts that were occurring.

100
00:03:29,853 --> 00:03:31,371
So we want to go and look at that machine.

101
00:03:31,371 --> 00:03:32,790
If I clicked on that, it would actually drill into that

102
00:03:32,790 --> 00:03:34,890
and show me all the different data points we've collected

103
00:03:34,890 --> 00:03:37,228
from all of the different systems so we can analyze those.

104
00:03:37,228 --> 00:03:40,140
Now, we're not going to cover those in this particular lesson

105
00:03:40,140 --> 00:03:42,450
because all those other data points are going to be specific

106
00:03:42,450 --> 00:03:44,010
to the dashboard you're using.

107
00:03:44,010 --> 00:03:45,630
But in this lesson, I just wanted to show you

108
00:03:45,630 --> 00:03:47,190
how you can read some of these graphs

109
00:03:47,190 --> 00:03:49,170
and get an idea of, are things going better

110
00:03:49,170 --> 00:03:50,790
for you or are things going worse?

111
00:03:50,790 --> 00:03:52,770
And how you can use a dashboard to drill down

112
00:03:52,770 --> 00:03:54,532
and use that as your central single pane of glass

113
00:03:54,532 --> 00:03:57,096
as your starting point, as you begin your investigation,

114
00:03:57,096 --> 00:04:00,033
as you're trying to respond to an incident response.

