Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Elastic{ON} Tour D.C. - Tackling Cyber with Roc...

Elastic Co
October 27, 2017

Elastic{ON} Tour D.C. - Tackling Cyber with RockNSM

Elastic{ON} Tour D.C. - October 26, 2017

Cyber is a human versus human problem. RockNSM covers your data gaps and delivers information to your humans so they can find the adversary.

Derek Ditch Missouri Army National Guard

Elastic Co

October 27, 2017
Tweet

More Decks by Elastic Co

Other Decks in Technology

Transcript

  1. 1 CPT Derek “dcode” Ditch October 27, 2017, MOCYBER Twitter:

    @dcode http://rocknsm.io Fending Off the Adversary with a
  2. 3 $ whois derek.ditch • Cyber Officer* in the Missouri

    Army National Guard, 17 years of service • Senior sensor platform engineer for major US bank • Former senior intrusion analyst in NTOC • MS Computer Science, published research in critical infrastructure protection • Father of 3 boys • Live in San Antonio My physical persona * I was previously an all-source intelligence officer
  3. 4 $ whois MOCYBER • We’re an ad-hoc unique &

    beautiful snowflake ‒Part Army CPT ‒Part National Guard DCO-E ‒Part Air National Guard • We’re all volunteer militia • Since 2010, 31 missions & exercises The Team
  4. 6 What is ROCK? A collection platform designed for Network

    Security Monitoring focused on: • Security. Passive sensors are one of the most valuable information assets on your network. Keep them to yourself. • Performance. Processing line-rate network data is taxing on your systems. Let's make the most of them. • Analysis. Connect the dots that make sense at collection time to aid human-driven analysis. • Production-Ready. Sometimes you have to spin up a sensor on short notice. If you wait until the last minute, it better only take a minutes.
  5. 9 I only want to sell you an idea... and

    it won't cost you... or the taxpayers a dime.
  6. 10 What’s the goal? Accept some foundational ideas: • Secure

    Architecture • Smart tactics • Defend with a purpose
  7. 11 I’m not trapped in here with you… you’re trapped

    in here with me. ~ Adversary in Your Network, Probably
  8. 13 What’s the goal? Accept some foundational ideas: • Secure

    Architecture • Smart tactics • Defend with a purpose
  9. 18 Smart Tactics • Passive first! • Use ephemeral infrastructure

    • Minimize use of privileged tokens • Collect all the things and cross reference your observations
  10. 19 What’s the goal? Accept some foundational ideas: • Secure

    Architecture • Smart tactics • Defend with a purpose
  11. 28 SOF Truths • Humans are more important than hardware.

    • Quality is better than Quantity. • Special Operations Forces (SOF) cannot be mass produced. • Competent SOF cannot be created after emergencies occur. • Most Special Operations require non-SOF assistance.