Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Improving Incident Response Workflow

Sponsored · Ship Features Fearlessly Turn features on and off without deploys. Used by thousands of Ruby developers.
Avatar for ag0ncharov ag0ncharov
August 16, 2014

Improving Incident Response Workflow

A case study for HP ArcSight ESM security event management system (SIEM) co-presented at HP Protect 2014 conference in Washington, DC.

Avatar for ag0ncharov

ag0ncharov

August 16, 2014
Tweet

More Decks by ag0ncharov

Other Decks in Technology

Transcript

  1. Improving IR Workflow Using Risk-Based Escalation in HP ArcSight ESM

    MetaNet IVS @meta_net http://MetaNetIVS.com
  2. What This Talk Is About We leveraged the power of

    ArcSight ESM to build advanced content which enables custom, risk-based, automated incident workflow. 2
  3. Why Should You Care 3 ★ Objectives: ★ Show capability

    of ArcSight ESM as a platform ★ Teach the audience to create uncommon use cases based on novel ideas ★ Share our stories and practical experience
  4. Customer Environment • Feeds • MS Windows Server • McAfee

    AntiVirus • CheckPoint Firewall • Cisco ASA • Snort IDS • McAfee Web Gateway • Foundstone • Nessus Vulnerability Scanner ! • EPS: 600 • Cases per Day: 1-2 • Enterprise Systems: 9000 • Enterprise Users: 3000 ! • Things We Like: • Dashboards and drill downs • Things We Dislike: • ESM client is not appropriate for our management • Querying multiple Active Lists at once 6
  5. The Idea 8 Low Risk (Severity Score 1) Medium Risk

    (Severity Score 2) High Risk (Severity Score 3) Indicator Examples ‣ AV: Malware Found and Cleaned ‣ Proxy: Blocked Outbound Connection ‣ FW: Outbound SSH Connection ‣ AV: Malware Found and Not Cleaned ‣ AV: File Infected ‣ Proxy: Blocked Connection (non-US) ‣ IDS: High Severity Alert ‣ Threat Intel: Connection to Known C&C Host ‣ AV: Buffer Overflow ‣ SIEM: Compromise Event to Vulnerable Asset 1 1 1 + + 1 + 2 3
  6. Solutions Provider 9 • SIEM and Event Management Solutions Provider

    • Heavy focus on HP ArcSight and Splunk solutions • Based in San Francisco, CA • Team members world-wide • Custom SIEM tools and methodologies • Experts in: • Maintenance of challenging environments • Complex integrations • Distributed architectures • Custom solutions for a variety of applications • Services catered to customer needs Purveyors of Finely Crafted Analytics
  7. Content Detail 14 Risk Score 2pts+ Low Severity Filters Risk

    Score 1pt Risk Score +1 Risk Score Set 1 Alert Case Case Notification
  8. Content Detail 15 Risk Score 2pts+ Low Severity Filters Medium

    Severity Filters Risk Score 1pt Not Not Risk Score +1 Risk Score Set 1 Risk Score Set 2 Alert Case Case Notification
  9. Content Detail 16 Risk Score 2pts+ Low Severity Filters Medium

    Severity Filters Risk Score 1pt Alert Case Case Notification Risk Score +1 Risk Score Set 1 Risk Score Set 2 Risk Score +2
  10. Content Detail 17 Risk Score 2pts+ Low Severity Filters Medium

    Severity Filters High Severity Filters Risk Score 1pt Risk Score Set 3 Not Alert Case Case Notification Risk Score +1 Risk Score Set 1 Risk Score Set 2 Risk Score +2 Not
  11. Content Detail 18 Risk Score 2pts+ Low Severity Filters Medium

    Severity Filters High Severity Filters Risk Score 1pt Risk Score Set 3 Risk Score +3 Alert Case Case Notification Risk Score +1 Risk Score Set 1 Risk Score Set 2 Risk Score +2
  12. Final Thoughts 23 Only systems reaching 3+ risk severity will

    trigger incident response 1 1 1 1 3 1 1 2 2 1 1 1 1 1 3 1 1 1 2 1 3 1 1 1 2 1 1