• No results found

Find the needle in the security haystack

N/A
N/A
Protected

Academic year: 2021

Share "Find the needle in the security haystack"

Copied!
44
0
0

Loading.... (view fulltext now)

Full text

(1)

Technology Day Oslo 1

Find the needle in the security haystack

Gunnar Kristian Kopperud

Principal Presales Consultant

(2)

Find the needle in the security haystack

• Manually deep dive into logs, or manage your risk with confidence?

• As we saw in the two previous sessions your servers and clients are under continuous attack.

• Most companies today have experienced incidents with

malware, and many are even unaware that they have malware infected clients and servers in their network.

• This session will show how, related to the sessions above, one can automate and streamline analysis, correlation, alerting and reporting of incidents and deviations.

(3)

Haystacks in the old days...

(4)

Modern Haystacks

(5)

Haystacking...

(6)

Where is the needle...

(7)

And more advanced threats

(8)

8

IT Analytics for

Symantec Endpoint Protection

(9)

What is IT Analytics?

9 Leverages Business Intelligence • Advanced ad-hoc data-mining • Analyze Trends and historical information • Graphical dashboards and easy reporting Expands on Traditional Reporting • User friendly custom reports • Export to multiple formats

• Pivot tables and charts

Utilizes Standard Technologies

• SQL 2005/2008 Analysis Services & Reporting Services Leverages OLAP Cubes • Business intelligence via multi-dimensional data exploration

(10)

Product Overview

10 Multi-Dimensional Ad-hoc/Pivot Table Reporting 4 Pivot Chart Functionality with Excel Export 5 Traditional Reporting 1 IT Analytics 2 Robust Graphical Dashboard 3 Alerts Cube

(11)

11

Client Dashboard

11

(12)

12

Virus Alert Trend Report

12

(13)

13

Scan Cube Pivot Table

13

(14)

14

Key Performance Indicators

14

(15)

Technology Day Oslo 15

Security Information & Event

Management (SIEM)

(16)

Aggregate and Prioritize

16 Antivirus …Other log data

Intrusion Prevention Firewall

Device and Application Control

Network Access Control

Aggregation and Correlation

Multiple Data Sources Prioritization Alerts Reports Remediation

Millions of Unprioritized

Events

Reduced Number of Prioritized Incidents Data Normalized into Common Formats Central Visibility to Critical Threats

(17)

Symantec Security Information Manager

“Optional” Intelligence Feed (GIN) Universal Collector Other sources… Firewall Intrusion Prevention Windows Events Syslog Collectors Correlation Manager Manager Console Pre-built Queries LiveUpdate Service Log Archiving Infrastructure Components Reports and Dashboards 150+ Pre-defined Reports

All Inclusive Solution

(18)

Technology Day Oslo 18

Managed Security Services (MSS)

(19)

MSS is Making Security Simple

The Symantec Difference

 Share the unique perspective of our

Global Intelligence

 Provide a World Class

Customer Engagement  Service Governance to ensure mature, consistent delivery  Increase detection through Edge to Endpoint Visibility  Provide actionable information relevant to Business Context

 Protect our customers proactively

19

(20)

The Keys to Successful Security Monitoring:

Edge to Endpoint Visibility

Network IDS Alerts • Limited to activity identified

by IDS vendor signatures • Limited 0-day threat detection

Firewall Logs

• Increased trending capability • Scan detection • Emerging threat and early

warning indicators

Proxy Logs

• Reputation-enabled analysis • Identification of malicious

web based activity

Endpoint Alerts • Confirmation of attack status

• Identification of malicious user activity.

20

Network IDP Alerts Network IDP Alerts

Firewall Analysis: Scan Detection Firewall Analysis: Hot IP Detection Firewall Analysis: IP Reputation Firewall Analysis: Anomalous Traffic Detection

Network IDP Alerts

Firewall Analysis: Scan Detection Firewall Analysis: Hot IP Detection Firewall Analysis: IP Reputation Firewall Analysis: Anomalous Traffic Detection Web Proxy Analysis:

Custom Threat Signatures Web Proxy Analysis:

URL Reputation

Network IDP Alerts

Firewall Analysis: Scan Detection Firewall Analysis: Hot IP Detection Firewall Analysis: IP Reputation Firewall Analysis: Anomalous Traffic Detection Web Proxy Analysis:

Custom Threat Signatures Web Proxy Analysis:

URL Reputation Endpoint Protection:

AV Alerts

Endpoint Protection: Host IDP Alerts

Endpoint Protection: Firewall Analysis

(21)

Firewalls Security Analyst Expert Query Engine Data mine Progressive Threat Model Relational Database OS & Apps Endpoints IDS Web Proxy

Successful Monitoring:

People, Process, Technology

Identification Validation

Classification

Incidents Escalated

21

(22)

Security Operations Centers

22

Reading, Chennai, Sydney, Hemdon

(23)

Homepage

(24)

Dashboard

(25)

Search for Logs – Managed Security Services (MSS)

Technology Day Oslo 25

Logs

(26)

Reporting – Managed Security Services (MSS)

(27)

Technology Day Oslo 27

(28)

SPC Enterprise – Data Collection and Analytics Platform

SPC Mobile – Executive Security Dashboard

Symantec Protection Center

Technology Day Oslo 28

Solution Overview Symantec Connectors Security Metrics Central Data Repository Business Asset System 3rd Party Connectors Security Workflows

(29)

Symantec Protection Center Enterprise

• Provide business centric analysis of

security information

• Ensure a complete view by integrating your entire security portfolio

• Quick deployment with prebuilt security metrics and connectors

• Provide a central

solution for roles based information sharing • Automate security

remediation via action plans

Technology Day Oslo 29

(30)

From this...

(31)

To this...

(32)

To this with Symantec Protection Center

(33)

Summary

• Be more PROACTIVE against advanced external threats

• Soft Appliance (on premise) Symantec Security Information Manager (SIEM) to manage/prioritize INTERNAL policies/rules • Symantec Managed Security Services (MSS) to help you

manage/prioritize EXTERNAL Threats

• Use HYBRID Solution when you need to do both internal policy/rules reporting and manage external threats

• Present security LEVEL to the business with Symantec Protection Center

(34)

QUESTIONS?

(35)

Symantec Protection Center

Summary

Technology Day Oslo 35

Boardroom Scrutiny

Consolidates security data and applies advanced correlation and analysis

Integrates DeepSight threat intelligence

Connect security information to business assets Clearly communicate key metrics by business

Broad range of supported solutions Pre-built connectors and metrics for quick integration

Better

Security

Decisions

Tablet based view of security metrics

Facilitates communication with both IT and business peers

Evolving Threats Relevant to Business

(36)

Technology Day Oslo 36

DEMO

(37)

37

(38)

38

(39)

39

(40)

40

(41)

Find the needle in the security haystack

• Manually deep dive into logs, or manage your risk with confidence?

• As we saw in the two previous sessions your servers and clients are under continuous attack.

• Most companies today have experienced incidents with

malware, and many are even unaware that they have malware infected clients and servers in their network.

• This session will show how, related to the sessions above, one can automate and streamline analysis, correlation, alerting and reporting of incidents and deviations.

(42)

Kontakt oss på:

• Symantec Brukerforum

– http://www.symantec.com/connect • Symantec Norge på Facebook

– http://www.facebook.com/SymantecNorge

• Norton Norge på Facebook

– http://www.facebook.com/nortonnorge

• Symantec Norge på Twitter

– http://twitter.com/SymantecNorge

• Lisenser og Support

– Tips: rapporter på web - ring etterpå – http://my.symantec.com/

(43)

43

(44)

Thank you!

Copyright © 2012 Symantec Corporation. All rights reserved. Symantec and the Symantec Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in

the U.S. and other countries. Other names may be trademarks of their respective owners.

This document is provided for informational purposes only and is not intended as advertising. All warranties relating to the information in this document, either express or implied, are disclaimed to the maximum extent allowed by law. The information in this document is subject to change without notice.

Technology Day Oslo 44

Gunnar Kristian Kopperud

[email protected]

References

Related documents

Public organizations are increasingly hybrid and complex, trying to attend to numerous and partly conflicting structures and cultural elements at the same time. The different

These Rules shall also apply, as specified in this text and the relevant provisions of the Staff Regulations, to those members of the Secretariat called upon to assist the panel

We argue that peacekeeping missions with higher overall troop quality are better able to protect civilians because they are better equipped, both logistically and

This normalized value of speci fi c consumption can help identifying an order of priority of retro fi t interventions to improve energy e ffi ciency, while the annual consumption is

If the argument of an application is not a value, we can postpone its evaluation by wrapping it into a closure that treats the argument expression as a lambda.. abstraction

When the stator is connected to the rated supply with the field excitation unchanged, the flux per pole in the machine is found to be 20 mWb while the motor is running on no

Under the above-quoted provision of Republic Act 529, if the obligation was incurred prior to the enactment of the Act and require payment in a particular kind of coin or currency

The Unified Data Server (UDS) controller enables secure data exchange between Adexa’s iCollaboration applications running your enterprise supply chain and other enterprise