blame it on you for the false positives

10
Blame it on YOU for the false- positives! Alex Teixeira Senior Security Practitioner

Upload: alexandre-teixeira

Post on 21-Mar-2017

235 views

Category:

Internet


1 download

TRANSCRIPT

Page 1: Blame it on you for the false positives

Blame it on YOU for the false-positives!

Alex TeixeiraSenior Security Practitioner

Page 2: Blame it on you for the false positives

The #1 mistake Security vendors make is thinking we want more. We want less. I don't want 90,000 events a day; I want the 3 actionable ones.”

Security Analyst of a famous startupTwitter, March 2016

Page 3: Blame it on you for the false positives

Less false-positives &More high-fidelity alerts.

SecMon = Core capabilitySkills gap/shortageBad UX = Unattended alertsHunting entry-point

Page 4: Blame it on you for the false positives

Image source: ThinkGeek

Go beyond the canned content.

Go fully custom!

Page 5: Blame it on you for the false positives

Define an initial scope• Main driver for:– Data collection requirements– Rules development roadmap

• Start with your Security Arsenal– Quick wins & low hanging fruits– Clear red flags

Page 6: Blame it on you for the false positives

• Aggregate by host (target/attacker)• Summarize key fields and drill-down further• Anticipate analyst’s call (recurring actions)– Whose server is this? Who is this user?

Page 7: Blame it on you for the false positives

Handling Exceptions• Key part of operations• Policy driven approach for on-going, every-day

cases (who, when, why) – with expiry date• Whitelisting ‘admins’ is NOT an option

Page 8: Blame it on you for the false positives

Threat Intel != Signature• Context!• Enrichment!• Threat Hunting practice!• Alerting on every match

against the event stream = ∧FP rate

Page 9: Blame it on you for the false positives

Blame it on your bo$$!• Minimizing FPs is directly tied to your team’s

skills and ability to: – Scope, design, deploy, develop & fine-tune rules

• A platform with development-appeal is at the core of the solution, but you need people.

• Less Silver Bullets, More Golden Minds

Page 10: Blame it on you for the false positives

Blame it on me!

@ateixei

foren6.wordpress.com

linkedin.com/in/inode

Images source: Tidydesign