George,

Here are some additional comments and questions with context:

My question: Is the survey scope intended for anyone in a SOC who is thinking 
about using Metron, or only for active OpenSOC/Metron users?

For question #1, can we say “sources” versus “devices?”  Devices imply 
hardware, which is definitely in scope but seems too limiting.  We also have 
customers who instrument software data sources (pcap.h, API’s, etc.). 


Context: it would be interesting to understand the higher level use case domain 
problems SOC’s are potentially trying to solve with Metron before delving into 
specific data sources.  Use cases drive data sources.  For example, we are 
focused on APT’s, which then flows down to specific data sources we would 
instrument and parse, UI visualizations and analytics. Perimeter defense is a 
different domain that Metron can solve, but then flows down to different data 
sources, UI visualizations, etc.  We saw one customer use OpenSOC for log 
aggregation.  One idea here is maybe have a list of use cases and have the 
users prioritize their needs as part of the survey.

Question: What specific use cases and cyber security domain problems are you 
trying to solve with Metron?

Question: How would you prioritize, in terms of importance, the use cases and 
challenges the SOC is tasked to solve?


Context: Metron currently has zero-to-limited analytical capabilities.  Its 
more data acquisition, aggregation, filter, storage, and visualization.  We are 
very interested to understand more about the SOC’s data analysis requirements 
(James has mentioned a correlation engine for the roadmap a few times which is 
relevant here).

Question: What analytical and/or correlation capabilities and features would 
you like Metron to support for the data:
A.) You currently collect
B.) You plan to collect in the future


Context: The Metron UI has been geared for operational analysis vs analytical 
analysis (I don’t count wireshark as analytical).  We have one progressive 
customer who is starting to bring very capable data scientists into the SOC to 
enhance the typical SOC operational analysts.  Again, this organizational 
dynamic in the SOC plays out to Metron in terms of incorporating things like 
Apache Zeppelin versus just making Kibana/Banana incrementally better.  Would 
definitely like to know what customer’s are doing on this front from a SOC 
staffing and/or organizational perspective.

Question: How would you rate your SOC’s data science and analytical 
capabilities today.

Question: Does your SOC have any plans to enhance its data science and 
analytical capabilities now or in the future?



Context: One customer wanted to store collected data for their enterprise for 
18 months on the OpenSOC/Metron HDFS cluster in order to support more advanced 
analytics.  It would be interesting to understand data retention requirements 
and policies.  Soon there will be more rigid compliance implications for 
storing data that helps uncover 

Question: What data retention capabilities do you require Metron to support?



Context: Cybersecurity and its various domains are going to be regulated more 
and more. There are going to be  more reporting requirements for enterprise 
companies in terms of sharing cyber related events. The SOC is going to play a 
larger role with respect to compliance, which could have implications related 
to Metron technical features or prioritization.

Question: What compliance regimes, if any, does your SOC tools and capabilities 
need to comply with to support the needs of your business.


Dave Hirko | [email protected] | 571.421.7729







On 12/13/15, 6:18 AM, "George Vetticaden" <[email protected]> wrote:

>Team,
>One of action items that I came out of the Requirements meeting last week (See 
>meeting minutes here: http://tinyurl.com/oehgnep), was to collaborate on a 
>list of questions for a survey that we can send out to customers/SOC teams.
>
>This thread is to colloborate on a list of questions that we want on this 
>survey. The goal is by the middle of next week is take everyone's feedback and 
>to formalize into a survey that we can start to send out to various users, 
>customers and SOC teams.
>
>Please add relevant questions so we can start to create  prioritized list of 
>requirements.
>
>Here is my starting list of questions:
>
>----
>
>1. What security devices are important to stream into Metron Security Data 
>Lake Platform? Supporting a device on the Metron platform means providing:
>       a. agent to collect data from the source
>       b. parser to parse the device data format into a normalized dataset
>
>2. What type of enrichment would you like to do to the security telemetry data?
>
>3. What are the different source of threat intel feeds you get? Which vendor 
>do you get the feed from and what is the format. Supporting an out of the box 
>threat intel feed means the following:
>      a. Supporting parsers for the intel feed to persist the feed store in 
> normalized form
>
>----
>
>
>--
>George Vetticaden
>Principal, COE
>[email protected]<mailto:[email protected]>
>(630) 909-9138

Reply via email to