Dave,
1. See responses inline.
2. Few more questions that we can add:
-What are key challenges and limitations of the current SIEM and
security
analytics tools that you use today?
-How would you prioritize the challenges today with the existing
security
tooling you use: (What else should be added to this list)
* To many alerts. There are no prioritization of alerts or the
prioritization's/risk based alerts that are in use are not accurate or
helpful to help me identify on what to focus on.
* There are too many tools that I need to learn
* I don't have a centralized view of my data
* Most of my alerts are false positive
* Managing static rules are too cumbersome.
* I have too many manual tasks.
* I cannot ingest and store all security/telemetry data based
on cost.
* I need to discover bad stuff quicker
-What are the key challenges with the collection, ingestion and storage
of telemetry data with your current security tooling?
-What type of enrichment capabilities does your current security tooling
NOT provide? Is enrichment of the data in real-time a critical
requirement? Is storing the enriched and raw data a critical requirement?
-What are critical requirements for threat intel feed integration with
Metron? For example, is cross referencing your threat intel feeds against
the original and enriched telemetry data a critical requirement?
-What are the critical functions you would like to perform on the
streaming security telemetry data as its coming in real-time in as opposed
to after it lands?
-Most the major security/SIEM vendors claim to have capabilities that
reduce and prioritize the number of alerts. What has been your experience
with these capabilities? Are risk/priority based correlation engines
working to reduce the number of alerts? What are the challenges that you
are experiencing? What are key requirements/capabilities that you would
like to see in a next-gen correlation engine in Metron?
-Most of the major security/SIEM vendors have static rules engine where
an analyst can define simple static rules that get applied after the data
has landed or been indexed. Do you feel Metron should provide similar
functionality or rather focus its efforts on building
relevancy/correlation data science engines/models that can create higher
level meta alerts? Does Metron need to provide both? What is most
important to build out first?
-Do you envision Metron replacing your SIEM solution or complimenting
it?
3. I have started documenting/refining these on the wiki here:
https://cwiki.apache.org/confluence/display/METRON/SOC+Users+Questionnaire
--
George VetticadenPrincipal, COE
[email protected]
(630) 909-9138
On 12/13/15 10:42 AM, "Dave Hirko" <[email protected]> wrote:
>George,
>
>Here are some additional comments and questions with context:
>
>My question: Is the survey scope intended for anyone in a SOC who is
>thinking about using Metron, or only for active OpenSOC/Metron users?
----
George: any soc team whose organization is considering alternative
SIEM/security analytics solutions.
-----
>
>For question #1, can we say ³sources² versus ³devices?² Devices imply
>hardware, which is definitely in scope but seems too limiting. We also
>have customers who instrument software data sources (pcap.h, API¹s, etc.).
----
George: Good point. I'll change it to sources.
----
>
>
>
>Context: it would be interesting to understand the higher level use case
>domain problems SOC¹s are potentially trying to solve with Metron before
>delving into specific data sources. Use cases drive data sources. For
>example, we are focused on APT¹s, which then flows down to specific data
>sources we would instrument and parse, UI visualizations and analytics.
>Perimeter defense is a different domain that Metron can solve, but then
>flows down to different data sources, UI visualizations, etc. We saw one
>customer use OpenSOC for log aggregation. One idea here is maybe have a
>list of use cases and have the users prioritize their needs as part of
>the survey.
>
>Question: What specific use cases and cyber security domain problems are
>you trying to solve with Metron?
>
>Question: How would you prioritize, in terms of importance, the use cases
>and challenges the SOC is tasked to solve?
>
-----
George: We probably need to create list of use cases that they can
prioritize. But I think the previous question is also important so that it
is free form so they can provide us with use cases on their own with
context/details. For this question the list of use cases that we can ask
them to priotize could beŠWhat else do we want to get added?
* Malware Detection & Lateral Movement
* Suspicious Behavior: User, Device, & Application
* Fraud Detection
* Account Hijacking & Privileged Account Abuse
* IP Theft & Data Exfiltration
* Virtual Container & Cloud Asset Compromise
----
>
>Context: Metron currently has zero-to-limited analytical capabilities.
>Its more data acquisition, aggregation, filter, storage, and
>visualization. We are very interested to understand more about the SOC¹s
>data analysis requirements (James has mentioned a correlation engine for
>the roadmap a few times which is relevant here).
>
>Question: What analytical and/or correlation capabilities and features
>would you like Metron to support for the data:
>A.) You currently collect
>B.) You plan to collect in the future
>
>
>Context: The Metron UI has been geared for operational analysis vs
>analytical analysis (I don¹t count wireshark as analytical). We have one
>progressive customer who is starting to bring very capable data
>scientists into the SOC to enhance the typical SOC operational analysts.
>Again, this organizational dynamic in the SOC plays out to Metron in
>terms of incorporating things like Apache Zeppelin versus just making
>Kibana/Banana incrementally better. Would definitely like to know what
>customer¹s are doing on this front from a SOC staffing and/or
>organizational perspective.
>
>Question: How would you rate your SOC¹s data science and analytical
>capabilities today.
>
>Question: Does your SOC have any plans to enhance its data science and
>analytical capabilities now or in the future?
>
>
>
>Context: One customer wanted to store collected data for their enterprise
>for 18 months on the OpenSOC/Metron HDFS cluster in order to support more
>advanced analytics. It would be interesting to understand data retention
>requirements and policies. Soon there will be more rigid compliance
>implications for storing data that helps uncover
>
>Question: What data retention capabilities do you require Metron to
>support?
>
>
>
>Context: Cybersecurity and its various domains are going to be regulated
>more and more. There are going to be more reporting requirements for
>enterprise companies in terms of sharing cyber related events. The SOC is
>going to play a larger role with respect to compliance, which could have
>implications related to Metron technical features or prioritization.
>
>Question: What compliance regimes, if any, does your SOC tools and
>capabilities need to comply with to support the needs of your business.
>
>
>Dave Hirko | [email protected] | 571.421.7729
>
>
>
>
>
>
>
>On 12/13/15, 6:18 AM, "George Vetticaden" <[email protected]>
>wrote:
>
>>Team,
>>One of action items that I came out of the Requirements meeting last
>>week (See meeting minutes here: http://tinyurl.com/oehgnep), was to
>>collaborate on a list of questions for a survey that we can send out to
>>customers/SOC teams.
>>
>>This thread is to colloborate on a list of questions that we want on
>>this survey. The goal is by the middle of next week is take everyone's
>>feedback and to formalize into a survey that we can start to send out to
>>various users, customers and SOC teams.
>>
>>Please add relevant questions so we can start to create prioritized
>>list of requirements.
>>
>>Here is my starting list of questions:
>>
>>----
>>
>>1. What security devices are important to stream into Metron Security
>>Data Lake Platform? Supporting a device on the Metron platform means
>>providing:
>> a. agent to collect data from the source
>> b. parser to parse the device data format into a normalized
>>dataset
>>
>>2. What type of enrichment would you like to do to the security
>>telemetry data?
>>
>>3. What are the different source of threat intel feeds you get? Which
>>vendor do you get the feed from and what is the format. Supporting an
>>out of the box threat intel feed means the following:
>> a. Supporting parsers for the intel feed to persist the feed store
>>in normalized form
>>
>>----
>>
>>
>>--
>>George Vetticaden
>>Principal, COE
>>[email protected]<mailto:[email protected]>
>>(630) 909-9138