• No results found

Defining, building, and making use cases work

N/A
N/A
Protected

Academic year: 2021

Share "Defining, building, and making use cases work"

Copied!
20
0
0

Loading.... (view fulltext now)

Full text

(1)

© Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.

Defining, building, and

making use cases work

Paul Brettle – Presales Manager, Americas

Pacific Region

(2)

What is a use case?

Compliance – FISMA, PCI, SOX, etc…

Network security – firewalls, IDS, routers & switches

Malware

Systems – application and operating system

User monitoring – identity, privileged user, shared accounts

SOC metrics – management metrics, analyst team, infrastructure performance

Fraud – banking, atms

(3)

© Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. 3

Defining a Use Case

Problem

statement

Define

the objective

Identify

data source

Define

thresholds

Identify

deliverables

Evaluate

and refine

1

2

3

4

5

6

(4)

Example use case – audit log cleared

Identify

Data source

How do I know when the audit

log is cleared on my systems?

I need to be notified when

audit logs are cleared for

my critical assets

Operating System

IDS/IPS (Host)

Firewalls

How do I want to be made

aware?

Notification to CIRT

Dashboard tracking

Compliance

Report to Auditors of

Audit Log Cleared

Problem

statement

Define

the objective

Identify

data source

Identify

deliverables

Evaluate

and refine

(5)

© Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. 5

Building a use case

Capture the data / requirements consistently

Utilise a standard process

What works for you is great

Consider Use Case forms

https://protect724.arcsight.com/docs/DOC-1523

(Cindy Jones)

Targeted, simple, manageable

(6)

Simple tactics to make your life easy

KISS principle still stands

Normal mechanisms stand, but control is the key part

Keep named user control around role based access

Limit options for access rights – operators DON’T need write to rules!

Group by general use / log source type / purpose – your choice!

Use the numbering structures / schemes

Remember the use case process and captured data

Build out on deliverables

Build out on threat / risk

(7)

© Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. 7

ArcSight use cases

Under used previously – been present since ESM 4.5

Much more content and documentation around for ESM 6.0c and Express 4.0

Look at focused content built around specific data sets

Usually focused around several active lists – imported or used as standard

Linked resources for filters, active channels etc – common naming, structure etc

(8)
(9)

© Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. 9

Steps to build use cases

1. Problem statement

2. Define objectives

3. Identify data sources

4. Define thresholds

5. Identify the deliverables

6. Evaluate & refine as needed

(10)

Example use case

Problem statement:

Identify unauthorized privileged user access to critical servers

Define the objective:

Ensure we have the ability to identify when unauthorized access is:

Attempted

Succeeds

Occurs without authorization

Identify unusual behavior

(11)

© Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. 11

Example use case

Identify the data sources:

Servers

Network devices

Other?

But also need to identify supporting data sources:

Who is an privileged user?

Can we identify them easily?

How can we identify if they are allowed / authorized or not?

Change control system? Change window?

(12)

Example use case

Data source -> list

Log data -> event

Alert -> rule

Consider supporting

information

Critical servers – asset list

Privileged users – external list

(13)

© Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. 13

Example use case

Define the thresholds

How to trigger rules?

What content to build out?

Where does the information go?

Individuals?

Team to process?

Tracking list?

(14)

Example use case

Identify deliverables

Content to show

what we want

Dashboards

Reports

Alerts

How to use the data?

Dashboards

Investigation

Ease of use?

(15)

© Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. 15

Example use case

Evaluate and refine

How to improve?

Where to refine and get better?

What content can be extended?

Focus on key data / log sources – better privileged user information

Integrate automated data feeds – export / import

Improve data, quality and content

(16)

Building Meaningful Use Cases

Review of use case approach

Formalized approach to understand what is required

Define, develop, build and use focused content

Process helps define what is needed:

Problem Statement

Define Objectives

Identify Data Sources

Define Thresholds

(17)

© Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. 17

Summary

User

Monitoring

Threat

Intelligence

Perimeter

Monitoring

Insider

Threat

App

Monitoring

Social

Media

Feed

Server

Admin

Monitor

Third

Party

Monitor

Network

Anomaly

Detection

Baseline

Monitoring

Advanced

Malware

Monitor

(18)

Please fill out a survey.

Hand it to the door monitor on your way out.

Thank you for providing your feedback, which

helps us enhance content for future events.

Session TB3057 Speaker Paul Brettle

(19)

© Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.

(20)

References

Related documents

Refusals are sent in the optional Comment file. Please bear the following in mind when sending in refusals or receiving output flat files from NYSIIS.. a) The NYSIIS system will

Source: Covello, 2003 Risk Communication Risk Communication Environmental Risk (UV) Risk Perception (Skin Damage) Risk-reducing Behavior (Sun Protection).. Risk

This study reported the design and development of a Hardware-in-the-Loop simulation platform with illustration of the development and demonstration as applied to a candidate

In both intervention groups, patients received their oral antidiabetics in the RTMM medication dispenser and had their medication use registered in real time during a period of

Program Evaluation Division North Carolina General Assembly • Reducing staffing by six positions will. produce annual savings of over $250K • Program can meet

perceptions of their preparation for professional work; (ii) design of engineering practice portfolio to inform students about engineering practice; (iii) an investigation

Program in Criminal Justice Policy and Management, Kennedy School of Government, Harvard University (November 1993).. “When Good Cops Turn Rotten.” New York Times op-ed (November

Players can create characters and participate in any adventure allowed as a part of the D&D Adventurers League.. As they adventure, players track their characters’