George, Here are some additional comments and questions with context:
My question: Is the survey scope intended for anyone in a SOC who is thinking about using Metron, or only for active OpenSOC/Metron users? For question #1, can we say “sources” versus “devices?” Devices imply hardware, which is definitely in scope but seems too limiting. We also have customers who instrument software data sources (pcap.h, API’s, etc.). Context: it would be interesting to understand the higher level use case domain problems SOC’s are potentially trying to solve with Metron before delving into specific data sources. Use cases drive data sources. For example, we are focused on APT’s, which then flows down to specific data sources we would instrument and parse, UI visualizations and analytics. Perimeter defense is a different domain that Metron can solve, but then flows down to different data sources, UI visualizations, etc. We saw one customer use OpenSOC for log aggregation. One idea here is maybe have a list of use cases and have the users prioritize their needs as part of the survey. Question: What specific use cases and cyber security domain problems are you trying to solve with Metron? Question: How would you prioritize, in terms of importance, the use cases and challenges the SOC is tasked to solve? Context: Metron currently has zero-to-limited analytical capabilities. Its more data acquisition, aggregation, filter, storage, and visualization. We are very interested to understand more about the SOC’s data analysis requirements (James has mentioned a correlation engine for the roadmap a few times which is relevant here). Question: What analytical and/or correlation capabilities and features would you like Metron to support for the data: A.) You currently collect B.) You plan to collect in the future Context: The Metron UI has been geared for operational analysis vs analytical analysis (I don’t count wireshark as analytical). We have one progressive customer who is starting to bring very capable data scientists into the SOC to enhance the typical SOC operational analysts. Again, this organizational dynamic in the SOC plays out to Metron in terms of incorporating things like Apache Zeppelin versus just making Kibana/Banana incrementally better. Would definitely like to know what customer’s are doing on this front from a SOC staffing and/or organizational perspective. Question: How would you rate your SOC’s data science and analytical capabilities today. Question: Does your SOC have any plans to enhance its data science and analytical capabilities now or in the future? Context: One customer wanted to store collected data for their enterprise for 18 months on the OpenSOC/Metron HDFS cluster in order to support more advanced analytics. It would be interesting to understand data retention requirements and policies. Soon there will be more rigid compliance implications for storing data that helps uncover Question: What data retention capabilities do you require Metron to support? Context: Cybersecurity and its various domains are going to be regulated more and more. There are going to be more reporting requirements for enterprise companies in terms of sharing cyber related events. The SOC is going to play a larger role with respect to compliance, which could have implications related to Metron technical features or prioritization. Question: What compliance regimes, if any, does your SOC tools and capabilities need to comply with to support the needs of your business. Dave Hirko | [email protected] | 571.421.7729 On 12/13/15, 6:18 AM, "George Vetticaden" <[email protected]> wrote: >Team, >One of action items that I came out of the Requirements meeting last week (See >meeting minutes here: http://tinyurl.com/oehgnep), was to collaborate on a >list of questions for a survey that we can send out to customers/SOC teams. > >This thread is to colloborate on a list of questions that we want on this >survey. The goal is by the middle of next week is take everyone's feedback and >to formalize into a survey that we can start to send out to various users, >customers and SOC teams. > >Please add relevant questions so we can start to create prioritized list of >requirements. > >Here is my starting list of questions: > >---- > >1. What security devices are important to stream into Metron Security Data >Lake Platform? Supporting a device on the Metron platform means providing: > a. agent to collect data from the source > b. parser to parse the device data format into a normalized dataset > >2. What type of enrichment would you like to do to the security telemetry data? > >3. What are the different source of threat intel feeds you get? Which vendor >do you get the feed from and what is the format. Supporting an out of the box >threat intel feed means the following: > a. Supporting parsers for the intel feed to persist the feed store in > normalized form > >---- > > >-- >George Vetticaden >Principal, COE >[email protected]<mailto:[email protected]> >(630) 909-9138
