Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Improving Incident Response Workflow

ag0ncharov
August 16, 2014

Improving Incident Response Workflow

A case study for HP ArcSight ESM security event management system (SIEM) co-presented at HP Protect 2014 conference in Washington, DC.

ag0ncharov

August 16, 2014
Tweet

More Decks by ag0ncharov

Other Decks in Technology

Transcript

  1. Improving IR Workflow Using Risk-Based Escalation in HP ArcSight ESM

    MetaNet IVS @meta_net http://MetaNetIVS.com
  2. What This Talk Is About We leveraged the power of

    ArcSight ESM to build advanced content which enables custom, risk-based, automated incident workflow. 2
  3. Why Should You Care 3 ★ Objectives: ★ Show capability

    of ArcSight ESM as a platform ★ Teach the audience to create uncommon use cases based on novel ideas ★ Share our stories and practical experience
  4. Customer Environment • Feeds • MS Windows Server • McAfee

    AntiVirus • CheckPoint Firewall • Cisco ASA • Snort IDS • McAfee Web Gateway • Foundstone • Nessus Vulnerability Scanner ! • EPS: 600 • Cases per Day: 1-2 • Enterprise Systems: 9000 • Enterprise Users: 3000 ! • Things We Like: • Dashboards and drill downs • Things We Dislike: • ESM client is not appropriate for our management • Querying multiple Active Lists at once 6
  5. The Idea 8 Low Risk (Severity Score 1) Medium Risk

    (Severity Score 2) High Risk (Severity Score 3) Indicator Examples ‣ AV: Malware Found and Cleaned ‣ Proxy: Blocked Outbound Connection ‣ FW: Outbound SSH Connection ‣ AV: Malware Found and Not Cleaned ‣ AV: File Infected ‣ Proxy: Blocked Connection (non-US) ‣ IDS: High Severity Alert ‣ Threat Intel: Connection to Known C&C Host ‣ AV: Buffer Overflow ‣ SIEM: Compromise Event to Vulnerable Asset 1 1 1 + + 1 + 2 3
  6. Solutions Provider 9 • SIEM and Event Management Solutions Provider

    • Heavy focus on HP ArcSight and Splunk solutions • Based in San Francisco, CA • Team members world-wide • Custom SIEM tools and methodologies • Experts in: • Maintenance of challenging environments • Complex integrations • Distributed architectures • Custom solutions for a variety of applications • Services catered to customer needs Purveyors of Finely Crafted Analytics
  7. Content Detail 14 Risk Score 2pts+ Low Severity Filters Risk

    Score 1pt Risk Score +1 Risk Score Set 1 Alert Case Case Notification
  8. Content Detail 15 Risk Score 2pts+ Low Severity Filters Medium

    Severity Filters Risk Score 1pt Not Not Risk Score +1 Risk Score Set 1 Risk Score Set 2 Alert Case Case Notification
  9. Content Detail 16 Risk Score 2pts+ Low Severity Filters Medium

    Severity Filters Risk Score 1pt Alert Case Case Notification Risk Score +1 Risk Score Set 1 Risk Score Set 2 Risk Score +2
  10. Content Detail 17 Risk Score 2pts+ Low Severity Filters Medium

    Severity Filters High Severity Filters Risk Score 1pt Risk Score Set 3 Not Alert Case Case Notification Risk Score +1 Risk Score Set 1 Risk Score Set 2 Risk Score +2 Not
  11. Content Detail 18 Risk Score 2pts+ Low Severity Filters Medium

    Severity Filters High Severity Filters Risk Score 1pt Risk Score Set 3 Risk Score +3 Alert Case Case Notification Risk Score +1 Risk Score Set 1 Risk Score Set 2 Risk Score +2
  12. Final Thoughts 23 Only systems reaching 3+ risk severity will

    trigger incident response 1 1 1 1 3 1 1 2 2 1 1 1 1 1 3 1 1 1 2 1 3 1 1 1 2 1 1