1
00:00:06,570 --> 00:00:09,630
- Welcome to Lesson 17:
Explain Security Alerting

2
00:00:09,630 --> 00:00:12,060
and Monitoring Concepts and Tools.

3
00:00:12,060 --> 00:00:14,580
We're gonna start off in lesson 17.1

4
00:00:14,580 --> 00:00:17,550
talking about logging and analysis.

5
00:00:17,550 --> 00:00:19,800
Now, I have to tell you,
I absolutely love logs.

6
00:00:19,800 --> 00:00:21,783
So I'm very excited about this lesson.

7
00:00:22,830 --> 00:00:26,850
Audit and event logs are
great chronological records

8
00:00:26,850 --> 00:00:29,103
of events and actions.

9
00:00:30,000 --> 00:00:33,450
Critical log sources include
what happens in our firewall,

10
00:00:33,450 --> 00:00:36,870
our IDS/IPS devices, our proxy servers,

11
00:00:36,870 --> 00:00:38,820
our authentication servers and devices,

12
00:00:38,820 --> 00:00:41,190
our operating systems, our databases,

13
00:00:41,190 --> 00:00:43,380
and our key applications.

14
00:00:43,380 --> 00:00:45,540
Why are audit and event logs so wonderful?

15
00:00:45,540 --> 00:00:46,860
Well, because they are

16
00:00:46,860 --> 00:00:51,150
a constant truthful record of activity

17
00:00:51,150 --> 00:00:54,240
and they are really a great near-time

18
00:00:54,240 --> 00:00:57,420
and historical detective control.

19
00:00:57,420 --> 00:01:00,240
Now, routine log analysis is beneficial

20
00:01:00,240 --> 00:01:02,100
for monitoring access,

21
00:01:02,100 --> 00:01:05,430
identifying malicious
and suspicious activity,

22
00:01:05,430 --> 00:01:09,270
including indicators of compromise
and indicators of attack,

23
00:01:09,270 --> 00:01:12,060
policy violations, fraudulent activity,

24
00:01:12,060 --> 00:01:13,770
and even operational issues

25
00:01:13,770 --> 00:01:15,810
that at first blush might not seem

26
00:01:15,810 --> 00:01:17,400
like they're tied to security.

27
00:01:17,400 --> 00:01:19,800
So, for example, let's say a log reports

28
00:01:19,800 --> 00:01:21,840
that a drive is about to be full, right?

29
00:01:21,840 --> 00:01:23,610
You're using up all the drive space.

30
00:01:23,610 --> 00:01:26,040
Well, that's an operational or IT issue.

31
00:01:26,040 --> 00:01:27,570
But if the drive gets full

32
00:01:27,570 --> 00:01:30,300
and maybe it stops the
system from operating,

33
00:01:30,300 --> 00:01:31,860
well, that's an availability issue.

34
00:01:31,860 --> 00:01:33,210
And now that belongs to us, right?

35
00:01:33,210 --> 00:01:34,533
That's a security issue.

36
00:01:35,610 --> 00:01:39,180
Just as a reminder, an
indicator of an attack, an IoA,

37
00:01:39,180 --> 00:01:42,780
our behaviors or actions that
suggest an attack is happening

38
00:01:42,780 --> 00:01:44,490
or about to happen.

39
00:01:44,490 --> 00:01:48,000
Where an IoC, an indicator
of compromise, is evidence

40
00:01:48,000 --> 00:01:50,133
that a system may have been compromised.

41
00:01:52,230 --> 00:01:55,050
Now, there's a lot of
challenges in working with logs.

42
00:01:55,050 --> 00:01:56,790
If you've ever looked at a raw log,

43
00:01:56,790 --> 00:01:58,770
you're like, oh my god, it's crazy, right?

44
00:01:58,770 --> 00:02:00,150
They're really big.

45
00:02:00,150 --> 00:02:03,300
Every activity could have
multiple lines, right?

46
00:02:03,300 --> 00:02:04,620
Multiple entries.

47
00:02:04,620 --> 00:02:06,510
They are so cryptic to read.

48
00:02:06,510 --> 00:02:07,777
So if anyone ever says to you,

49
00:02:07,777 --> 00:02:09,300
"Oh yeah, I can just read a log."

50
00:02:09,300 --> 00:02:11,580
You have to, like, you
know, call 'em out on it,

51
00:02:11,580 --> 00:02:13,260
'cause you really just can't.

52
00:02:13,260 --> 00:02:16,710
So here are some of the
challenges with logging, right?

53
00:02:16,710 --> 00:02:17,790
The volume, right?

54
00:02:17,790 --> 00:02:20,400
A single device can easily generate

55
00:02:20,400 --> 00:02:22,830
hundreds of events per minute.

56
00:02:22,830 --> 00:02:26,280
There's a lot of noise
and unnecessary stuff

57
00:02:26,280 --> 00:02:27,630
in our logs, right?

58
00:02:27,630 --> 00:02:31,110
Logs can contain a significant
amount of useless data

59
00:02:31,110 --> 00:02:33,393
that needs to be parsed before processing.

60
00:02:34,710 --> 00:02:35,910
The format.

61
00:02:35,910 --> 00:02:38,040
Don't know why this is true but it is.

62
00:02:38,040 --> 00:02:40,830
Every device and every piece
of software and every database

63
00:02:40,830 --> 00:02:43,320
seems to have their own format for logs.

64
00:02:43,320 --> 00:02:45,240
So before, it's really useful

65
00:02:45,240 --> 00:02:48,300
for doing comparison and analysis,

66
00:02:48,300 --> 00:02:51,300
logs have to be converted
to a standard format

67
00:02:51,300 --> 00:02:54,453
and their data normalized
to ensure consistency.

68
00:02:56,280 --> 00:02:57,690
Then just trying to interpret them, right?

69
00:02:57,690 --> 00:02:59,250
Logs can be cryptic

70
00:02:59,250 --> 00:03:01,953
and really require an
interpretive process.

71
00:03:03,090 --> 00:03:06,090
The logs also might
contain sensitive data.

72
00:03:06,090 --> 00:03:08,910
So let's say for example,
your user's logging in

73
00:03:08,910 --> 00:03:10,530
and they're not paying a lot of attention

74
00:03:10,530 --> 00:03:14,280
so they put their password
in the username field.

75
00:03:14,280 --> 00:03:16,773
But that password may show up in a log.

76
00:03:18,780 --> 00:03:20,490
And inaccessibility.

77
00:03:20,490 --> 00:03:23,100
Sometimes access to logs are restricted.

78
00:03:23,100 --> 00:03:24,780
So it could be, right?

79
00:03:24,780 --> 00:03:26,160
That you don't have rights to those logs

80
00:03:26,160 --> 00:03:29,490
because maybe it's a third
party that has a device.

81
00:03:29,490 --> 00:03:32,223
It is logging, but you
don't have access to it.

82
00:03:34,140 --> 00:03:37,590
So let's look at big picture
log management workflow.

83
00:03:37,590 --> 00:03:39,900
We have to decide what
we're gonna log, right?

84
00:03:39,900 --> 00:03:42,300
We're not gonna log absolutely everything,

85
00:03:42,300 --> 00:03:44,400
all activity that happens in our network

86
00:03:44,400 --> 00:03:47,250
because we would end up chewing
up all kinds of bandwidth

87
00:03:47,250 --> 00:03:48,780
and chewing up drive space.

88
00:03:48,780 --> 00:03:50,160
So we're gonna prioritize.

89
00:03:50,160 --> 00:03:52,263
What is it that we want to log?

90
00:03:54,000 --> 00:03:56,100
And then we're going
to configure our login.

91
00:03:56,100 --> 00:03:58,860
So for log in a firewall or
log in a domain controller,

92
00:03:58,860 --> 00:04:01,470
log in a DNS server, right?

93
00:04:01,470 --> 00:04:03,900
We're, you know, log in
a radius server, right?

94
00:04:03,900 --> 00:04:05,430
We're going to configure it.

95
00:04:05,430 --> 00:04:06,660
And I wanna remind you,

96
00:04:06,660 --> 00:04:08,010
and we talked about this
a little bit early on,

97
00:04:08,010 --> 00:04:08,970
and we always wanna look

98
00:04:08,970 --> 00:04:12,600
for successful and unsuccessful attempts.

99
00:04:12,600 --> 00:04:14,707
So very often people say,

100
00:04:14,707 --> 00:04:17,970
"Oh, I only wanna get successful events

101
00:04:17,970 --> 00:04:19,740
because that told me something happened."

102
00:04:19,740 --> 00:04:22,740
But unsuccessful is also
very important to us, right?

103
00:04:22,740 --> 00:04:23,730
Because that tells us

104
00:04:23,730 --> 00:04:26,913
that somebody or something has
been trying to do something.

105
00:04:28,770 --> 00:04:31,560
Once we have configured
our log environment,

106
00:04:31,560 --> 00:04:34,800
we will be collecting
the data, the log data.

107
00:04:34,800 --> 00:04:37,290
We wanna make sure that we're
not just letting it sit there,

108
00:04:37,290 --> 00:04:38,790
that we are analyzing it

109
00:04:38,790 --> 00:04:42,420
on as close to real-time
basis as possible.

110
00:04:42,420 --> 00:04:46,020
If there is any issues,
any indicators, right?

111
00:04:46,020 --> 00:04:48,930
We're going to wanna respond to those.

112
00:04:48,930 --> 00:04:51,450
And then we're going to
wanna archive our logs.

113
00:04:51,450 --> 00:04:52,620
Why archive our logs?

114
00:04:52,620 --> 00:04:55,110
Because we may need to go back to our logs

115
00:04:55,110 --> 00:04:56,520
at some point in the future

116
00:04:56,520 --> 00:04:58,740
if we're doing any type of investigation

117
00:04:58,740 --> 00:05:00,840
or forensic analysis.

118
00:05:00,840 --> 00:05:03,300
So prioritize, configure, collect,

119
00:05:03,300 --> 00:05:05,493
analyze, respond, archive.

120
00:05:08,310 --> 00:05:11,130
Now the protocol we
generally use for logging

121
00:05:11,130 --> 00:05:12,780
is known as Syslog.

122
00:05:12,780 --> 00:05:15,300
Syslog stands for System Logging Protocol.

123
00:05:15,300 --> 00:05:18,420
And it's a standard protocol
used to send system log

124
00:05:18,420 --> 00:05:21,750
or event messages to a collection server

125
00:05:21,750 --> 00:05:24,300
known as a syslog server.

126
00:05:24,300 --> 00:05:26,790
Now, syslog servers are
used to collect logs

127
00:05:26,790 --> 00:05:28,380
from different devices

128
00:05:28,380 --> 00:05:30,870
so that we can store them
all in a central location

129
00:05:30,870 --> 00:05:32,763
for our monitoring and review.

130
00:05:33,630 --> 00:05:36,480
Now remember that logs could
contain confidential data.

131
00:05:36,480 --> 00:05:38,010
There's always that possibility.

132
00:05:38,010 --> 00:05:41,823
So they should always be
securely transmitted and stored.

133
00:05:44,760 --> 00:05:46,620
So, how are logs actually analyzed?

134
00:05:46,620 --> 00:05:47,910
Well, there's a number of components

135
00:05:47,910 --> 00:05:50,160
in the logging analysis process.

136
00:05:50,160 --> 00:05:53,310
Synchronization,
normalization, aggregation,

137
00:05:53,310 --> 00:05:57,840
deduplication, correlation,
and identification.

138
00:05:57,840 --> 00:06:01,290
Synchronization really isn't
part of the analysis process.

139
00:06:01,290 --> 00:06:03,030
It actually has to happen before.

140
00:06:03,030 --> 00:06:04,140
But that's really the process

141
00:06:04,140 --> 00:06:06,870
of when we're configuring our logs,

142
00:06:06,870 --> 00:06:08,670
making sure that we're synchronizing

143
00:06:08,670 --> 00:06:10,320
with an external time source

144
00:06:10,320 --> 00:06:13,080
with a timestamp protocol like NTP.

145
00:06:13,080 --> 00:06:13,913
Why?

146
00:06:13,913 --> 00:06:15,660
Because when we're actually
doing the correlation,

147
00:06:15,660 --> 00:06:18,510
it's going to be based
on date and timestamp.

148
00:06:18,510 --> 00:06:21,720
So we wanna make sure that
all of our systems are using

149
00:06:21,720 --> 00:06:23,283
the same time source.

150
00:06:24,660 --> 00:06:27,330
Normalization is
standardizing the log details

151
00:06:27,330 --> 00:06:29,550
into a consistent structure.

152
00:06:29,550 --> 00:06:31,770
Aggregation is consolidating events

153
00:06:31,770 --> 00:06:35,040
from the various or disparate
devices and systems.

154
00:06:35,040 --> 00:06:37,710
Deduplication is filtering
out duplicate entries

155
00:06:37,710 --> 00:06:39,000
or that excessive noise

156
00:06:39,000 --> 00:06:41,070
that stuff that we don't need in there.

157
00:06:41,070 --> 00:06:44,730
Correlation will be tying
individual long entries together

158
00:06:44,730 --> 00:06:48,420
based on related information
to build a a fuller picture.

159
00:06:48,420 --> 00:06:50,070
And identification is

160
00:06:50,070 --> 00:06:51,450
ultimately what we're trying to do here.

161
00:06:51,450 --> 00:06:54,273
Identifying normal and abnormal activity.

162
00:06:56,670 --> 00:06:59,340
Now, you can't do that manually.

163
00:06:59,340 --> 00:07:00,277
Now, some people have said to me,

164
00:07:00,277 --> 00:07:02,550
"Oh yeah, I can look at the
logs. I can figure it out."

165
00:07:02,550 --> 00:07:04,530
And again, you wanna call 'em out on it.

166
00:07:04,530 --> 00:07:06,840
You really need a log analysis tool.

167
00:07:06,840 --> 00:07:08,190
And then to respond,

168
00:07:08,190 --> 00:07:11,250
it would be nice if you had
some automated response tools.

169
00:07:11,250 --> 00:07:12,870
So let's look at four tools.

170
00:07:12,870 --> 00:07:17,852
An SIEM, TIP, UEBA, and SOAR.

171
00:07:17,852 --> 00:07:18,840
An SIEM stands

172
00:07:18,840 --> 00:07:21,390
for Security Information
and Event Management.

173
00:07:21,390 --> 00:07:23,250
And it's an automation tool,

174
00:07:23,250 --> 00:07:24,630
again, 'cause we're not
gonna do this manually.

175
00:07:24,630 --> 00:07:26,520
We're doing it in automated fashion

176
00:07:26,520 --> 00:07:28,830
for realtime data capture,

177
00:07:28,830 --> 00:07:32,013
event correlation analysis and reporting.

178
00:07:33,660 --> 00:07:36,540
Now, a TIP is a Threat
Intelligence Platform

179
00:07:36,540 --> 00:07:39,150
which is another automation
tool that combines

180
00:07:39,150 --> 00:07:41,190
multiple threat intelligence feeds

181
00:07:41,190 --> 00:07:44,070
and it integrates with the SIEM.

182
00:07:44,070 --> 00:07:47,220
So not just saying, okay,
let's compare and aggregate

183
00:07:47,220 --> 00:07:48,510
what we see in the logs.

184
00:07:48,510 --> 00:07:50,820
Let's now add some threat intelligence

185
00:07:50,820 --> 00:07:52,833
to be able to do some identification.

186
00:07:54,000 --> 00:07:57,750
UEBA stands for User and
Entity Behavioral Analytics.

187
00:07:57,750 --> 00:08:00,090
And that's yet another automation tool

188
00:08:00,090 --> 00:08:02,970
that models the behavior
of humans and machines

189
00:08:02,970 --> 00:08:06,930
to identify normal and abnormal behavior.

190
00:08:06,930 --> 00:08:09,060
And then lastly, we get to
one of my favorite tools,

191
00:08:09,060 --> 00:08:10,050
which is SOAR.

192
00:08:10,050 --> 00:08:10,883
SOAR stands

193
00:08:10,883 --> 00:08:14,160
for Security Orchestration,
Automation and Response.

194
00:08:14,160 --> 00:08:16,140
Now, it is not an analysis tool.

195
00:08:16,140 --> 00:08:17,880
It is a response tool.

196
00:08:17,880 --> 00:08:22,880
It's a tool that responds to
alerts, can triage the data,

197
00:08:22,920 --> 00:08:26,430
and can follow an
automated digital workflow

198
00:08:26,430 --> 00:08:27,900
to take remediation steps.

199
00:08:27,900 --> 00:08:30,850
And we'll be talking more about
SOAR a little bit later on.

200
00:08:32,430 --> 00:08:34,920
So diving deep into each one here.

201
00:08:34,920 --> 00:08:38,550
An SIEM, security information
and event manager,

202
00:08:38,550 --> 00:08:41,700
solutions offer real-time data capture

203
00:08:41,700 --> 00:08:45,300
and continuous monitoring
for multiple sources,

204
00:08:45,300 --> 00:08:49,410
near-time event correlation
analysis, and reporting.

205
00:08:49,410 --> 00:08:53,508
Now, SIEM is really a
combination of two technologies:

206
00:08:53,508 --> 00:08:56,760
SIM, which was Security
Information Management

207
00:08:56,760 --> 00:08:59,670
and SEM, which was
Security Event Management.

208
00:08:59,670 --> 00:09:03,240
And they came together
and we ended up with SIEM.

209
00:09:03,240 --> 00:09:06,480
Now, SIM focuses on the
centralized log collection,

210
00:09:06,480 --> 00:09:09,570
log storage, log search, and reporting,

211
00:09:09,570 --> 00:09:12,570
where SIM focuses on the threat analysis,

212
00:09:12,570 --> 00:09:14,820
the incident detection and response,

213
00:09:14,820 --> 00:09:17,580
and basic ticketing capability.

214
00:09:17,580 --> 00:09:19,700
Now, there's a number
of ways to have an SIEM

215
00:09:19,700 --> 00:09:20,880
in your environment.

216
00:09:20,880 --> 00:09:21,750
You might decide

217
00:09:21,750 --> 00:09:24,060
that you are going to bring
one in locally, right?

218
00:09:24,060 --> 00:09:25,710
And that you are going to, you know,

219
00:09:25,710 --> 00:09:27,870
on-prem manage and monitor it.

220
00:09:27,870 --> 00:09:31,320
Or you may decide to have a
third party do this for you.

221
00:09:31,320 --> 00:09:33,690
So your logs actually go to a third party.

222
00:09:33,690 --> 00:09:36,270
And the third party is
managing and monitoring

223
00:09:36,270 --> 00:09:37,833
the SIM on your behalf.

224
00:09:40,620 --> 00:09:43,110
Now the TIP, the threat
intelligence platform,

225
00:09:43,110 --> 00:09:43,943
as I said earlier,

226
00:09:43,943 --> 00:09:46,020
combines multiple threat
intelligence feeds

227
00:09:46,020 --> 00:09:48,090
and focuses on TTPs.

228
00:09:48,090 --> 00:09:51,450
That's tactics, techniques, and procedures

229
00:09:51,450 --> 00:09:53,340
to detect threats.

230
00:09:53,340 --> 00:09:54,810
Now, the TIPs don't stand alone.

231
00:09:54,810 --> 00:09:59,760
They integrate with an
existing SIEM or SIEM solution.

232
00:09:59,760 --> 00:10:02,310
The TIPs perform three basic functions:

233
00:10:02,310 --> 00:10:05,580
aggregation, analysis, and action.

234
00:10:05,580 --> 00:10:09,060
So aggregation funnels multiple
threat intelligence feeds

235
00:10:09,060 --> 00:10:11,310
into a centralized feed.

236
00:10:11,310 --> 00:10:14,070
Analysis curates the data using indicators

237
00:10:14,070 --> 00:10:17,730
to define and identify security threats.

238
00:10:17,730 --> 00:10:21,120
And then action shares
relevant threat intelligence

239
00:10:21,120 --> 00:10:24,513
with their incident response
and your defense teams.

240
00:10:27,120 --> 00:10:31,860
Then we get to UEBA, User
Entity Behavioral Analytics.

241
00:10:31,860 --> 00:10:35,790
The User Entity Behavioral
Analytics tools analyze user,

242
00:10:35,790 --> 00:10:37,020
that's you and me, right,

243
00:10:37,020 --> 00:10:40,260
and entity, that's gonna
be resources, behavior,

244
00:10:40,260 --> 00:10:45,260
and apply advanced analytics
to detect anomalies.

245
00:10:45,510 --> 00:10:47,070
So we've got four parts here.

246
00:10:47,070 --> 00:10:50,460
Our user, our entity,
behavioral, analytics.

247
00:10:50,460 --> 00:10:52,290
Let's look at each one of them.

248
00:10:52,290 --> 00:10:53,490
Right, what do we mean by user?

249
00:10:53,490 --> 00:10:56,190
That could be you and I, a user,

250
00:10:56,190 --> 00:10:59,310
or it could be a privileged
user or it could be a service

251
00:10:59,310 --> 00:11:00,990
or it could be a guest.

252
00:11:00,990 --> 00:11:03,810
Entity, talking about things
like routers, servers,

253
00:11:03,810 --> 00:11:07,830
an enterprise application,
even an IoT device.

254
00:11:07,830 --> 00:11:10,380
Behavioral, well, that's
a behavioral baseline

255
00:11:10,380 --> 00:11:12,180
for each entry.

256
00:11:12,180 --> 00:11:15,570
And then analytics is applying
artificial intelligence

257
00:11:15,570 --> 00:11:19,203
and machine learning to
really analyze the behavior.

258
00:11:21,630 --> 00:11:26,343
Now, UEBA often is integrated
into a SIEM or SIEM platform,

259
00:11:27,690 --> 00:11:29,760
adds behavioral context,

260
00:11:29,760 --> 00:11:34,260
detects malicious insider and
privilege account takeovers,

261
00:11:34,260 --> 00:11:37,653
and automates identifying
significant events.

262
00:11:38,580 --> 00:11:40,380
And lastly, we'll predict

263
00:11:40,380 --> 00:11:43,113
which incidents should be prioritized.

264
00:11:45,810 --> 00:11:47,340
So let's talk about SOAR again.

265
00:11:47,340 --> 00:11:49,860
SOAR stands for Security Orchestration,

266
00:11:49,860 --> 00:11:52,050
Automation and Response.

267
00:11:52,050 --> 00:11:54,300
Now these are tools that
allow an organization

268
00:11:54,300 --> 00:11:58,650
to define incident analysis
and response procedures

269
00:11:58,650 --> 00:12:01,380
in an automated digital workflow.

270
00:12:01,380 --> 00:12:03,360
So I wanna define two terms for you:

271
00:12:03,360 --> 00:12:05,070
automation and orchestration.

272
00:12:05,070 --> 00:12:07,620
'Cause there's often
confusion between the two.

273
00:12:07,620 --> 00:12:09,540
When we use the term automation,

274
00:12:09,540 --> 00:12:12,090
what we're talking about
is the ability to execute

275
00:12:12,090 --> 00:12:16,050
a sequence of tasks
without human intervention,

276
00:12:16,050 --> 00:12:17,700
without human intervention.

277
00:12:17,700 --> 00:12:19,470
That's what automation is.

278
00:12:19,470 --> 00:12:21,510
Where orchestration is the integration

279
00:12:21,510 --> 00:12:26,510
of disparate tools and platforms
for an automated response.

280
00:12:26,550 --> 00:12:28,290
I always envision an orchestra.

281
00:12:28,290 --> 00:12:29,220
I have an orchestra,

282
00:12:29,220 --> 00:12:30,960
and we've got the violins, and the violas,

283
00:12:30,960 --> 00:12:32,730
and we've got the woodwinds and the brass,

284
00:12:32,730 --> 00:12:34,230
and we've got the drums, right?

285
00:12:34,230 --> 00:12:36,360
Those are all disparate instruments.

286
00:12:36,360 --> 00:12:38,160
But my conductor, right?

287
00:12:38,160 --> 00:12:40,680
They puts the whole orchestra together

288
00:12:40,680 --> 00:12:42,240
so that they work together, right?

289
00:12:42,240 --> 00:12:44,280
This disparate tools and platforms

290
00:12:44,280 --> 00:12:46,473
for an automated response.

291
00:12:48,300 --> 00:12:51,810
And that, my friends, brings
us to a three-second challenge.

292
00:12:51,810 --> 00:12:54,240
Five challenge questions,
three seconds each.

293
00:12:54,240 --> 00:12:55,073
You ready?

294
00:12:56,190 --> 00:12:57,900
All right. Here's our first question.

295
00:12:57,900 --> 00:13:00,390
The process of standardizing log details

296
00:13:00,390 --> 00:13:02,163
into a consistent structure.

297
00:13:03,000 --> 00:13:05,073
One, two, three.

298
00:13:06,570 --> 00:13:08,013
That's normalization.

299
00:13:09,300 --> 00:13:11,850
Number two, the process of filtering out

300
00:13:11,850 --> 00:13:15,120
duplicate entries or excessive noise.

301
00:13:15,120 --> 00:13:16,953
One, two, three.

302
00:13:18,690 --> 00:13:20,223
That's deduplication.

303
00:13:22,110 --> 00:13:26,370
Number three, an automation
tool for real-time data capture,

304
00:13:26,370 --> 00:13:29,583
event correlation analysis, and reporting.

305
00:13:31,440 --> 00:13:32,673
One, two, three.

306
00:13:34,053 --> 00:13:34,886
It's gonna be

307
00:13:34,886 --> 00:13:37,800
our Security Information
and Event Management tool.

308
00:13:37,800 --> 00:13:38,633
SIEM or SIEM.

309
00:13:41,610 --> 00:13:43,740
Number four, an automation tool

310
00:13:43,740 --> 00:13:47,190
that combines multiple
threat intelligence feeds.

311
00:13:47,190 --> 00:13:48,453
One, two, three.

312
00:13:49,320 --> 00:13:53,070
That's gonna be our TIP, our
Threat Intelligence Platform.

313
00:13:53,070 --> 00:13:56,070
And lastly, number
five, an automation tool

314
00:13:56,070 --> 00:13:59,430
that allows an organization
to define incident analysis

315
00:13:59,430 --> 00:14:02,730
and response procedures
in a digital workflow.

316
00:14:02,730 --> 00:14:04,860
One, two, three.

317
00:14:04,860 --> 00:14:05,693
And that's gonna be

318
00:14:05,693 --> 00:14:07,620
Security Orchestration,
Automation, and Response

319
00:14:07,620 --> 00:14:08,453
known as SOAR.

320
00:14:08,453 --> 00:14:10,740
And we get to revisit
SOAR a little bit later on

321
00:14:10,740 --> 00:14:12,480
when we're talking
about incident response.

322
00:14:12,480 --> 00:14:14,580
And I'll give you some SOAR examples then.

323
00:14:16,380 --> 00:14:18,480
All right, let's do a
security-in-action together.

324
00:14:18,480 --> 00:14:20,030
This is about a budget request.

325
00:14:20,880 --> 00:14:23,460
You've been tasked with
recommending ways to automate

326
00:14:23,460 --> 00:14:27,600
cybersecurity detective
and response processes.

327
00:14:27,600 --> 00:14:31,020
Now you're recommending that
the organization invest in both

328
00:14:31,020 --> 00:14:34,590
an SIEM and SOAR solution.

329
00:14:34,590 --> 00:14:35,670
Now, at your presentation,

330
00:14:35,670 --> 00:14:38,190
you were asked to explain the differences

331
00:14:38,190 --> 00:14:41,910
and if having both was really necessary.

332
00:14:41,910 --> 00:14:43,560
So what's your response gonna be?

333
00:14:43,560 --> 00:14:45,030
Again, this is a budget request,

334
00:14:45,030 --> 00:14:47,970
and you are saying that
you're recommending

335
00:14:47,970 --> 00:14:51,540
both a SIEM and a source solution

336
00:14:51,540 --> 00:14:52,770
because you've been tasked

337
00:14:52,770 --> 00:14:57,660
with detective and response processes.

338
00:14:57,660 --> 00:14:59,580
So you probably have a
pretty hefty budget here

339
00:14:59,580 --> 00:15:02,580
and you have to go and justify it.

340
00:15:02,580 --> 00:15:03,930
Go ahead and put me on pause,

341
00:15:03,930 --> 00:15:06,723
write down your response and come on back.

342
00:15:09,510 --> 00:15:12,360
But you wanna explain the
difference between the two.

343
00:15:12,360 --> 00:15:15,750
The SIEM will ingest
various log and event data

344
00:15:15,750 --> 00:15:18,960
from traditional infrastructure
component sources.

345
00:15:18,960 --> 00:15:23,190
The aggregated data then is
gonna be analyzed by the SIEM

346
00:15:23,190 --> 00:15:27,270
in real time to spot
potential security issues.

347
00:15:27,270 --> 00:15:30,393
So this is our really
our detective process.

348
00:15:32,310 --> 00:15:33,990
The source solutions will take

349
00:15:33,990 --> 00:15:37,890
the SIEM response capabilities
to the next level,

350
00:15:37,890 --> 00:15:40,290
offering an automated response.

351
00:15:40,290 --> 00:15:42,690
So our source systems
are going to supplement,

352
00:15:42,690 --> 00:15:43,960
not replace the SIEM

353
00:15:44,820 --> 00:15:47,550
because our SIEMs are detectives

354
00:15:47,550 --> 00:15:50,163
or our source systems are our responders.

355
00:15:51,930 --> 00:15:54,570
Now, after receiving an
alert from SIEM, right,

356
00:15:54,570 --> 00:15:56,820
that source solution will manage

357
00:15:56,820 --> 00:15:59,250
that incident response process.

358
00:15:59,250 --> 00:16:03,360
So if you have both, right,
they're going to work together.

359
00:16:03,360 --> 00:16:05,820
The SIEM and the SOAR.

360
00:16:05,820 --> 00:16:07,807
Now, if you only could
choose one, they say,

361
00:16:07,807 --> 00:16:09,900
"Well, you can only have one,"

362
00:16:09,900 --> 00:16:12,000
I'm probably gonna start with the SIEM

363
00:16:12,000 --> 00:16:15,510
because I need that strong
detective capability.

364
00:16:15,510 --> 00:16:17,280
We can always respond in other ways,

365
00:16:17,280 --> 00:16:19,710
probably not as
effectively or efficiently,

366
00:16:19,710 --> 00:16:21,210
but we certainly can.

367
00:16:21,210 --> 00:16:23,700
So if you had to
prioritize between the two,

368
00:16:23,700 --> 00:16:26,550
you would invest in the SIEM first

369
00:16:26,550 --> 00:16:30,060
and then maybe in the next
budget cycle, in SOAR.

370
00:16:30,060 --> 00:16:32,793
And doing that, my friends,
is security-in-action.

371
00:16:33,660 --> 00:16:34,800
There's your word cloud.

372
00:16:34,800 --> 00:16:35,823
You know what to do.

373
00:16:36,930 --> 00:16:38,820
All right, I will see you

374
00:16:38,820 --> 00:16:40,670
at the next lesson when you're ready.
