• No results found

Management of Security Information and Events in Future Internet

N/A
N/A
Protected

Academic year: 2021

Share "Management of Security Information and Events in Future Internet"

Copied!
21
0
0

Loading.... (view fulltext now)

Full text

(1)

Management of Security Information and

Events in Future Internet

Who?

Andrew Hutchison1 Roland Rieke2

From?

1T-Systems South Africa

2Fraunhofer Institute for Secure Information Technology SIT

(2)

Overview

Changes and

developments

Management of Security Information and Events (SIEM) in Future Internet (FI)

Vision

New opportunities & new risks

Challenges

Security, resilience, privacy

Solutions and

implied RTD

needs

(3)

Security Information and Event Management

Systems

Product

oriented view

“SIEM technology provides real-time analysis of security alerts generated by network hardware and applications. SIEM solutions come as software, appliances or managed services, and are also used to log security data and generate reports for compliance purposes. ” (Wikipedia, May 2011)

(4)

“Systems Come in Threes!

. . . ajudgemental system, is involved in determining

whether any particular activity (or inactivity) of asystemin

a givenenvironmentconstitutes or would constitute - from

its viewpoint - a failure.”

(Brian Randell, IFIP WG 10.4, Guadeloupe, 2007)

en viro n m e n t judgementa l s ys te m system

(5)

Changes and developments

Future Internet

(FI) is driving a

complete

re-think of the

paradigm

whereby

organisations

deploy and

manage their

own services

and

infrastructure

“Service Models” “Deployment Models” customers

*National Institute of Standards and Technology (NIST) 

App

Cloud applications SaaS Public Clouds: Resources and  Services from the  Internet H b id Cl d

Pl f

App

– SaaS Cloud platforms P S Private Clouds: Hybrid Clouds: The best of both  worlds C it

Platfor

– PaaS Cloud Resources and  services from secure  sources Community Clouds: Fro special interest  groups

Infrastructu

m

infrastructures – IaaS On demand self services Broad network access Resource pooling Rapid Measured Characteristics *

Infrastructu

re

Rapid

elasticity Measured service

re

Source: T-Systems

Services get outsourced into clouds Infrastructures evolve hybrid - real & virtual

(6)

Changes and developments

Cyber-physical

Systems of

Systems (SoS)

get connected

to the Internet

Smart Grid IoT Car-to-X Use of meshed wireless communication structures –> physical actuators get in reach of attackers

(7)

Vision

Services &

infrastructure in

clouds leads to

deployment of

SIEM in clouds

Internet Cloud Campus/Remote Site Internet Gateway Remote Authentication Server Local Authentication Server HIPS Anti-Virus Anti-Spyware Disk Encryption Security Update Repository Data Centre Data Centre Router Security Management Identity Management Mail Content Management: e.g. Anti-Virus, Anti-Spam

Internet Content Management: e.g. URL Filtering

Anti-Virus Anti-Spam

Security Operations Centre

Monitoring Event Correlator Vulnerability Analysis HIPS Anti-Virus Anti-Spyware Firewall & IPS

Mail Relay Proxy Server Internet Gateway Router Mail Server Servers SOC Router Firewall & IPS Firewall & IPS Firewall & IPS Site Router Firewall & IPS Source: T-Systems

Managed SIEM Today, multiple sources are collected centrally within the realm of the provider organisation

(8)

Vision

Services &

infrastructure in

clouds leads to

deployment of

SIEM in clouds

Source: T-Systems

(9)

Vision

New

opportunities

Inter-organisational analyses are possible Adaptive countermeasures

IaaS PaaS SaaS

and new Risks

Privacy and integrity of the events of any particular company

Virtualisation layers introduce new vulnerabilities

IoT enables new remote attacks against critical services & infrastructures

(10)

Vision

New

opportunities

Inter-organisational analyses are possible Adaptive countermeasures

IaaS PaaS SaaS

and new Risks

Privacy and integrity of the events of any particular company

Virtualisation layers introduce new vulnerabilities

IoT enables new remote attacks against critical services & infrastructures

(11)

Vision

New SIEM

deployment

entails different

thinking about

the revenue

model

Source: T-Systems

(12)

Challenges

Security,

resilience,

privacy

Security for cloud applications & service infrastructures Intrusion tolerance, self-protection and self-healing QoS guarantees to ensure reliable and timeous arrival of security event information from the sensors

The debate on Internet net-neutrality could also refer here since there could be a case for expediting control traffic such as SIEM event feeds

New cryptographic techniques enabling processing of data in a privacy-preserving manner

(13)

Challenges

High-level

situational

security

awareness

Resource IaaS PaaS SaaS Application Attacker SIEM reasoning

Provide cross-layer, cross-domain security information

Bgiven that the cloud hides technical delivery of the service from

the SIEM provider (typically increasing for higher level services) SIEM needs limited transparency

(14)

Challenges

High-level

situational

security

awareness

Resource IaaS PaaS SaaS Application Attacker SIEM reasoning

Provide cross-layer, cross-domain security information

Bgiven that the cloud hides technical delivery of the service from

the SIEM provider (typically increasing for higher level services) SIEM needs limited transparency

(15)

Challenges

Adaptive

response

Security Event

Abstraction Process Model Attack Model

Predictive analysis of upcoming security problems

Bgiven that customers have no insights on risk mitigation

mechanisms of cloud providers and overall status Anticipatory impact analysis & decision support Technical but also legal challenges

(16)

Solutions and implied RTD needs

Resilient,

trust-enabling

SIEM

architecture

Authenticated component event reporting Information flow defense Unforgeability provisions Trustworthy event collection

Trusted collection of security-relevant data from highly heterogeneous trusted networked devices (IoT) Resilient Internet-based backbone communication

(17)

Solutions and implied RTD needs

Scalable

security

situation

assessment

Event Processing Engine SOI Logs SOI Events Service Infrastructure Service Infrastructure Authentication Devices Authentication Events Event Collection Event Correlation External Language Events Internal Language Events Languages Alarms Network Events Network Devices Security Events Security Devices

Scalable distribution of acquisition & parallel processing Seamless function splitting core engines/edge collectors Parallel data streaming to SIEM in clouds

(18)

Solutions and implied RTD needs

Cross-layer

reasoning &

mitigation

Process Simulation Engine Predictive Alerts Attack Simulation Engine Counter-measure Evaluation

Multi-level security event modelling aims at a holistic solution to protect service infrastructures of FI Predictive security monitoring enables to fight attacks proactively by predicting their future actions

(19)

A platform

around which

these thoughts

are

crystallizing!

Advanced SIEM Framework

Alert and reaction generation

Scenarios Prototypes

Event and Information Collection Highly-scalable, dependable and

multi-level event collection

Event, Process Models and Attack Models

Predictive security analysis

Multi-domain parallel-running

processes

Process and attack simulation Actions and Counter-measures Security analysis and notification Security-aware processes Olympic Games Mobile money transfer service CI Process Control (Dam) Managed Enterprise Service Infrastructures

Resilient event processing and integration Languages EVENTS RELATIONS POLICIES REACTIONS Multi-level event correlation

Multi-level security event modeling

Trustworthy event collection

Resilient framework architecture

(20)

Conclusions

Changes and

developments

B

FI is driving a complete re-think of the paradigm whereby

organisations deploy and manage their own services and infrastructure

B

Cyber-physical SoS get connected to the Internet

Vision

B

Services & infrastructure in clouds leads to deployment of SIEM in clouds

B

New opportunities and revenue models & new risks

Challenges

B

Security, resilience, privacy

B

High-level situational security awareness

B

Adaptive response

Solutions and

implied RTD

needs

B

Resilient, trust-enabling SIEM architecture

B

Scalable security situation assessment

B

Cross-layer reasoning & mitigation

en viron m e n t judgementa l sy s te m system

(21)

Landscape of

European

Security

Projects

References

Related documents

However, as the case study with Sage AI (UK) attests, the interest in green procure- ment of sustainable textile products for the automotive sector in Europe has not gained

The neighbor matrix includes the degree sequence as its first column and the sequence of all other distances in the graph up to the graph’s diameter, enumerating the number of

Access entry tool for feta to compare nutrient output data of food codes to estimate population distribution of the questionnaire file will enable future researchers using the

Figure 2 presents a network topology with nine SNs and a BS. Let the SNs send information to the BS using greedy forwarding algorithm proposed in GAHR protocol. The greedy

Model of the molecular basis of defence priming in plant cells and the connection to PTMs. In

This survey is intended to determine which proposal to exchange treatment vehicle information will be the easiest for everyone to implement in SEND 3.1. We have supplied 4 SEND

For example, if you choose to show progress based on the current project and percent complete, an activity that should have been 50 percent complete according to its target dates,

CCS-UC-200-WMT-LG-2_KIT Crestron RL2 Codec Cables and Mounting Hardware TS-1051-C Touch Screen TS-1051-C Touch Screen TS-1051-C Touch Screen Crestron RL2 Codec Crestron RL2