3. Disclaimer
This talk != an EY talk
This talk != an [] talk
This talk == MY talk
Wednesday 22 December 2010
4. Disclaimer
This talk != an EY talk
This talk != an [] talk
This talk == MY talk
Marishka Hargitay !
Wednesday 22 December 2010
5. I. What is SIEM
II. Challenges
III. Common-Sense SIEM
V. What’s the future?
VI. ...
Wednesday 22 December 2010
6. What is SIEM ?
* What is it not (Log Management)
* It’s about information.
* It’s about your needs !
Wednesday 22 December 2010
7. Log
SIEM
Management
Log Collection
Context Data Collection
Log Collection Normalization
Retention Categorization
Search Correlation
Indexing/Parsing Notification/Alerting
Reporting Prioritization
Reporting
Security role workflow
All types of log data Security relevant data
Wednesday 22 December 2010
8. INFORMATION
PROCESSING
DATA
Wednesday 22 December 2010
9. Data vs. information
May 21 20:22:28 slacker2 sshd[8813]: Accepted password for
root from 192.168.20.185 port 1066 ssh2
Wednesday 22 December 2010
10. Data vs. information
May 21 20:20:15 slacker sshd[17834]: Failed password for root from
192.168.20.185 port 1058 ssh2
May 21 20:22:28 slacker2 sshd[8813]: Accepted password for
root from 192.168.20.185 port 1066 ssh2
Wednesday 22 December 2010
11. Data vs. information
May 21 19:30:28 slacker sshd[9287]: Failed password for root from
192.168.20.185 port 1080 ssh2
May 21 19:32:30 slacker sshd[10254]: Failed password for root from
192.168.20.185 port 1045 ssh2
... (2000 of those)
May 21 20:20:15 slacker sshd[17834]: Failed password for root from
192.168.20.185 port 1058 ssh2
May 21 20:22:28 slacker2 sshd[8813]: Accepted password for
root from 192.168.20.185 port 1066 ssh2
Wednesday 22 December 2010
30. Making sense of data
user 1 user 2 user 1 user 2
user 3 user 4 user 3 user 4
70 200
52,5 150
100
35
50
17,5
0
0 monday wednesday friday
monday wednesday friday
200
150 user 4
100 user 3
user 2
50
user 1
0
monday wednesday friday
Wednesday 22 December 2010
34. common-sense SIEM!
DATA
Use Cases
Data Points
time/date who
user name what
source when
destination where
host name why ?
action €€€
... ...
Wednesday 22 December 2010
35. So, where do we go from here ?
Wednesday 22 December 2010
36. mee
tH
oov
er ;
-)
http://www.loggly.com
!= SIEM
= LaaS
currently running in beta
log collection/parsing/search/visualization
(demo)
Wednesday 22 December 2010