<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>supervision - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/supervision-en/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/supervision-en/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Thu, 02 Jan 2020 14:29:25 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>supervision - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/supervision-en/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>SOAR, UEBA, CASB, EDR and others: which tools do you need for you SOC? (3/3)</title>
		<link>https://www.riskinsight-wavestone.com/en/2019/04/new-tools-soc-33/</link>
		
		<dc:creator><![CDATA[Amaury Coulomban]]></dc:creator>
		<pubDate>Thu, 18 Apr 2019 10:41:38 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[Machine learning]]></category>
		<category><![CDATA[SOAR]]></category>
		<category><![CDATA[supervision]]></category>
		<category><![CDATA[Threat intelligence]]></category>
		<category><![CDATA[tool]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=11853</guid>

					<description><![CDATA[<p>After the first article which covered &#8220;Extending the scope of detection to new perimeters” (see here), and the second, dedicated to “Enhancing detection through new approaches” (available here)&#8230; this is the conclusion to this (epic!) saga. This last installment will...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/04/new-tools-soc-33/">SOAR, UEBA, CASB, EDR and others: which tools do you need for you SOC? (3/3)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>After the first article which covered &#8220;<em>Extending the scope of detection to new perimeters</em>” (see <a href="https://www.riskinsight-wavestone.com/en/2019/04/new-tools-soc-13/">here</a>), and the second, dedicated to <em>“Enhancing detection through new approaches”</em> (available <a href="https://www.riskinsight-wavestone.com/en/2019/04/new-tools-soc-23/">here</a>)&#8230; this is the conclusion to this (epic!) saga. This last installment will cover the last two strategic areas.</p>
<p>&nbsp;</p>
<h2>Improving knowledge of threats and attackers</h2>
<h3>Cyber-threat intelligence (CTI) platforms</h3>
<p>Cyber-Threat Intelligence (CTI or Threat Intel) is a discipline that brings together <strong>the collection, consolidation, and exploitation of all information on cyber-threats</strong>. “Know your enemy&#8221; says Sun Tzu in the Art of War. Although this quote refers to &#8220;physical&#8221; wars, the principle remains true, and is probably even more true when it comes to &#8220;cyber&#8221; battles.</p>
<p>Today, a large number of security approaches rely on <strong>knowledge of attacks</strong>: the signature-based approach of antivirus and IDS solutions, targeted detection scenarios, etc. Even though this trend is reversing (in particular with the detection of anomalies) the vast <strong>majority of security products still rely—and will continue to rely—on the principles of Threat Intelligence</strong>.</p>
<p>With companies’ needs becoming more specific, and attackers ever more specialized, Threat Intel solutions are becoming increasingly popular, with services being offered directly to companies. In addition to commercial offerings, more and more exchange platforms and partnerships are enabling direct collaboration with other companies (in the same sector or geographical area, etc.).</p>
<p>Threat Intel offers a range of services. On the one hand, <strong>‘strategic’ Threat Intel </strong>helps an SOC better understand the context and <strong>specific threats to the company.</strong> To do this, the risks from various ecosystems are studied: geographical, political, ideological, sectoral, etc. This information enables security teams to better understand the threats they face and guides their decisions to define <strong>&#8220;long-term&#8221; strategy</strong> (solutions to be deployed, etc.).</p>
<p>On the other hand, <strong>‘tactical’ Threat Intel</strong> provides more precise information on attackers&#8217; methods, allowing the SOC to facilitate detection and tailor existing measures: new threat scenarios to monitor, ports to block, etc.</p>
<p>In addition to these approaches, <strong>‘technical’ Threat Intel</strong> contributes greatly to the <strong>analysis of security events</strong> by providing, on request (from SOAR in particular—see below), elements that enable the veracity of an alert to be judged: an IP belonging to a botnet, a file hash corresponding to a known virus, etc.</p>
<p>Threat Intelligence approaches are therefore among an SOC’s most versatile tools, enabling it to make the most of existing devices, by remaining up to date and prioritizing the threats to be detected, as well as identifying future tools and measures to be deployed.</p>
<p><strong><u>Examples of Threat Intelligence publishers:</u></strong></p>
<figure id="post-11854 media-11854" class="align-none"><img fetchpriority="high" decoding="async" class="size-medium wp-image-11854 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-0-2-354x191.png" alt="" width="354" height="191" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-0-2-354x191.png 354w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-0-2-71x39.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-0-2.png 691w" sizes="(max-width: 354px) 100vw, 354px" /></figure>
<p>&nbsp;</p>
<h2>The standardization and automation of the response process</h2>
<h3>Security Orchestration, Automation and Response</h3>
<p>Security Orchestration, Automation and Response (SOAR) is derived from the combination of three SOC tools: <strong>Security Incident Response Platforms (SIRPs</strong>—more details <a href="http://www.securityinsider-wavestone.com/2016/12/sirp-la-panacee-de-la-reponse-incident.html">here),</a> <strong>Security Orchestration Automation</strong> <strong>(SOA—</strong> orchestration and automation solutions) and some of the functionality of <strong>Threat Intelligence</strong> platforms. In summary, these are platforms <strong>that provide help and automate responses</strong> to security incidents. The solutions are similar to traditional ticketing tools (ITSMs) but include functionalities specific to cybersecurity issues. SOARs offer three main capabilities, each linked to one of the three types of tools from which they are derived.</p>
<p>First, like SIRPs, they allow the <strong>definition of response processes</strong> that are tailored to each security event. These are based on <strong>pre-defined playbooks provided by the publisher,</strong> <strong>published by the community</strong> using the solution, or <strong>created manually</strong> to better tailor things to the needs of the business. In particular, this task requires response teams to establish a clearly defined process that encourages them to ask themselves the right questions when they create response procedures, as well as to capitalize on and retain the knowledge gained.</p>
<p>The benefits of a SOAR, however, come more from the automation of the various stages that follow detection. During the analysis phase, the tool will <strong>automatically</strong> <strong>enrich knowledge about a security event by</strong> <strong>retrieving contextual information about the IS</strong> (identity in the AD, criticality of a resource, etc.), and <strong>querying external Threat Intelligence services</strong> (<em>via</em> APIs) or those that are offered as part of the solution. In addition to automating the enrichment and analysis steps, SOARs <strong>also facilitate the work of analysts: </strong> the investigation of terminals, the interrogation of VirusTotal etc. in one click—when their involvement is required.</p>
<p>But automation doesn’t stop there! Although controversial, the <strong>automation of the response</strong> (via the connection to security equipment, a legacy of SOA) can represent an important gain for security teams: the blocking of a URL, the generation of the signature of a file and its propagation to antivirus tools, the blacklisting of an IP, etc.</p>
<p>The goal of SOARs is clear: to make it easier for the teams in charge of analysis and response, by helping them to define processes and automate tasks to the greatest extent possible. Although SOARs are very adaptable and can therefore help in response to any type of attack, they really shine when it comes to <strong>automating the treatment of common attacks</strong> (such as ransomware, phishing, etc.), which are very repetitive and tie up the resources of response teams.</p>
<p>Once these tasks have been automated, the security teams responsible for responding can <strong>focus on more complex alerts</strong>, where their knowledge adds real value.</p>
<p>Provided they are prepared to put in the initial effort (the formalization of processes, etc.), the likely <strong>reactivity and load gains</strong> are significant. SOARs will change the way SOC teams work, especially with respect to top-level analysts. Even though these solutions are still rarely deployed in France, they are set to become an essential tool for SOCs in the coming years.</p>
<p><strong><u>Examples of SOAR publishers:</u></strong></p>
<p><img decoding="async" class="size-medium wp-image-11856 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-1-1-437x98.png" alt="" width="437" height="98" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-1-1-437x98.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-1-1-768x172.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-1-1-71x16.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-1-1.png 785w" sizes="(max-width: 437px) 100vw, 437px" /></p>
<p>&nbsp;</p>
<figure id="post-11858 media-11858" class="align-none">
<figure id="post-11865 media-11865" class="align-none"><img decoding="async" class="aligncenter wp-image-11865 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-0-4.png" alt="" width="828" height="485" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-0-4.png 828w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-0-4-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-0-4-326x191.png 326w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-0-4-768x450.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-0-4-67x39.png 67w" sizes="(max-width: 828px) 100vw, 828px" /></figure>
</figure>
<p>&nbsp;</p>
<p><em>Even though tools are only part of equipping an SOC, each of these solutions has distinct advantages that can help detection teams keep up to date in terms of the evolution of ISs and threats.</em></p>
<p><em>All the tools are promising, and some are coming to maturity. However, it’s important to keep in mind that current toolkits already raise a raft of alerts, which presents a challenge when it comes to processing. It’s therefore advisable to complete the deployment and automation of what exists (using SOARs, for example), before turning toward new solutions.</em></p>
<p><em>And, as for any innovative product, a cool head is needed: the deployment of a new solution must be the result of well-defined needs.</em></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/04/new-tools-soc-33/">SOAR, UEBA, CASB, EDR and others: which tools do you need for you SOC? (3/3)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>SOAR, UEBA, CASB, EDR and others: which tools do you need for you SOC? (2/3)</title>
		<link>https://www.riskinsight-wavestone.com/en/2019/04/new-tools-soc-23/</link>
		
		<dc:creator><![CDATA[Amaury Coulomban]]></dc:creator>
		<pubDate>Thu, 18 Apr 2019 09:56:28 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[Deceptive security]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[Machine learning]]></category>
		<category><![CDATA[SOC]]></category>
		<category><![CDATA[supervision]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[UEBA]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=11835</guid>

					<description><![CDATA[<p>After the first article, which covered &#8220;Extending the scope of detection to new perimeters&#8221; (available here), this second installment is the next in our summer series about the SOC&#8230; &#160; Enhancing detection with new approaches Think identity to detect suspect...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/04/new-tools-soc-23/">SOAR, UEBA, CASB, EDR and others: which tools do you need for you SOC? (2/3)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>After the first article, which covered &#8220;Extending the scope of detection to new perimeters&#8221; (available <a href="https://www.riskinsight-wavestone.com/en/2019/04/new-tools-soc-13/">here</a>), this second installment is the next in our summer series about the SOC&#8230; </em></p>
<p>&nbsp;</p>
<h2>Enhancing detection with new approaches</h2>
<h3>Think identity to detect suspect behaviors: UEBA</h3>
<p>User and Entity Behavioral Analysis (UEBA—previously known as UBA) technologies are among the latest tools being used to enhance SOC’s detection arsenals. As their name suggests, they take a specific approach—leaving aside the technical considerations of current solutions (SIEM, etc.), and, instead, analyzing the <strong>behavior of users and entities</strong> (including terminals, applications, networks, servers, connected objects, etc.).</p>
<p>The principle is simple, but its implementation much less so. To be effective, UEBA approaches require a diversity of sources, and a <strong>variety of data formats</strong>. Traditional sources, such as SIEM and log manager(s), are employed and, in addition, certain resources (such as ADs, proxies, BDDs, etc.) are often used directly.</p>
<p>But, to perfect their detection capabilities, UEBA solutions also draw on new sources: <strong>information on users</strong> (HR applications, badge management, etc.), exchanges between employees (chats, video exchanges, emails, etc.), or any other relevant sources (business applications that need to be monitored, etc.).</p>
<p>Taking all this information together, UEBA solutions analyze the behavior of users (and entities) to identify potential threats. They can use static rules, in the form of <strong>signatures to be detected</strong> (which are often already implemented in SIEM solutions): simultaneous connections from two different locations, or unusual times of use, etc.</p>
<p>But the real strength of UEBA lies in the use of Machine Learning algorithms to detect <strong>changes in the behavior</strong> of users or services: suspicious business-function operations, access to critical, previously unused applications during holidays, unusual data transfers, etc.</p>
<p>Although UEBA was initially conceived to counter fraud, its role has gradually broadened to cover some areas that typically pose problems for SIEM: data theft, compromise or loan of application accounts, terminal or server infection, privilege abuse, etc.</p>
<p>Thus, today, UEBA is positioning itself as complementary to SIEM, adding to the latter’s &#8220;technical&#8221; approach by providing &#8220;user&#8221; visibility, and bringing an additional layer of intelligence to the analysis.</p>
<p>The market’s view is that, in the coming years, UEBA solutions will probably cease to exist in their present form. Instead, they’ll be integrated into existing solutions (SIEM, EDR, etc.), changing their form from products to functionalities.</p>
<p><strong><u>Examples of UEBA publishers:</u></strong></p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-11837 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image1-1-437x159.png" alt="" width="437" height="159" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image1-1-437x159.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image1-1-768x280.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image1-1-71x26.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image1-1.png 1339w" sizes="auto, (max-width: 437px) 100vw, 437px" /></p>
<p>&nbsp;</p>
<h3>Trapping attackers: deceptive security</h3>
<p>Deceptive Security can be considered as a move to <strong>a higher form of the Honey Pot approach</strong>. Here, <strong>decoys</strong>, in the form of data, agents, or dedicated environments, are distributed widely throughout all, or part of, the IS.</p>
<p>Depending on the needs and solutions, Deceptive Security tools can serve two purposes. By <strong>diverting the attention of attackers away from real resources</strong> and leading them down false trails, they can act as a means of <strong>protection</strong>.</p>
<p>But above all, monitoring these decoys can <strong>detect</strong> threats that are spreading within the IS. In fact, the decoys have no other use than to <strong>lure potential attackers or to provide false information</strong>; any communication with them is then, by definition, suspect.</p>
<p>This type of solution isn&#8217;t a replacement for existing measures but addresses very specific use cases where conventional detection approaches are ineffective: APTs, which are specially designed to circumvent them, and, more broadly, horizontal movements within the IS.</p>
<p>For more detail on Deceptive Security solutions, read our dedicated article <a href="https://www.riskinsight-wavestone.com/en/2017/11/deceptive-security-comment-arroser-larroseur/">here</a>.</p>
<p><strong><u>Examples of Deceptive Security publishers:</u></strong></p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-11839 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/Image2-2-437x185.png" alt="" width="437" height="185" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/Image2-2-437x185.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/Image2-2-768x326.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/Image2-2-71x30.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/Image2-2.png 1308w" sizes="auto, (max-width: 437px) 100vw, 437px" /></p>
<p>&nbsp;</p>
<h3>Detecting weak signals on the network: machine learning sensors</h3>
<p>Traditional detection sensors (IDPSs), based on traffic analysis and comparisons with known attack signatures, are not particularly effective when it comes to <strong>detecting subtle attacks</strong> (APTs, etc.) <strong>or unknown</strong> <strong>threats</strong> (0-day, etc.). To overcome this problem, new-generation IDPSs integrate Machine Learning capabilities (sometimes presented as Artificial Intelligence) into their detection arsenals.</p>
<p>Depending on the solution, two types of use for Machine Learning can be distinguished. On the one hand, the use of these algorithms in <strong>supervised mode</strong> to learn to <strong>recognize the behavior of certain attacks</strong>, or phases of attack (during the active phases): command and control, scans, lateral movements, data leakage, etc.</p>
<p>On the other, once the sensor has been deployed, adjustment of the detection thresholds to the client context is also based on Machine Learning algorithms (something already used by many traditional IDPS solutions).</p>
<p>This mode of operation enables rapid deployment (solutions that can be used out-of-the-box with shorter learning phases), and a better ability to detect previously characterized attacks. Conversely, the detection of attacks that have not been subject to learning, or are completely unknown, remains difficult.</p>
<p>In contrast to this approach, some solutions rely on <strong>unsupervised learning</strong> to detect attacks. Here, during deployment, sensors are positioned on the network to observe the traffic and learn how to recognize what constitutes legitimate traffic.</p>
<p>Once the learning phase is over, the sensors can <strong>detect anomalies</strong> and raise alerts when suspicious behavior occurs. This approach enables the detection of unknown attacks, but generally requires a longer learning phase if it is to be effective and achieve an acceptable false alert rate.</p>
<p>In both cases, the &#8220;Machine Learning<em>&#8220;</em> sensors make it possible to enhance an SOC’s arsenal (which, today, is mostly aimed at detecting known attacks) through detection capabilities that can <strong>discern complex, unknown attacks</strong>, or those designed to circumvent conventional security approaches.</p>
<p>Initial feedback from the field shows that these technologies can indeed detect threats that bypass conventional security measures. False positives, however, are very common (the learning curve varies widely, depending on solutions and contexts), and it remains difficult to judge how comprehensively threats are being detected.</p>
<p>&#8220;Machine Learning&#8221; sensors therefore have a definite future among SOC tools, even if they need to further mature to reach their full potential.</p>
<p><strong><u>Examples of Machine Learning sensor publishers:</u></strong></p>
<figure id="post-11841 media-11841" class="align-none"><img loading="lazy" decoding="async" class="size-medium wp-image-11841 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image3-2-437x76.png" alt="" width="437" height="76" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image3-2-437x76.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image3-2-768x134.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image3-2-71x12.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image3-2.png 1377w" sizes="auto, (max-width: 437px) 100vw, 437px" /></figure>
<p>&nbsp;</p>
<p><em>You can find our third, and final, article in this series <a href="https://www.riskinsight-wavestone.com/en/2019/04/new-tools-soc-33/">here</a>.</em></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/04/new-tools-soc-23/">SOAR, UEBA, CASB, EDR and others: which tools do you need for you SOC? (2/3)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>SOAR, UEBA, CASB, EDR and others: which tools do you need for you SOC? (1/3)</title>
		<link>https://www.riskinsight-wavestone.com/en/2019/04/new-tools-soc-13/</link>
		
		<dc:creator><![CDATA[Amaury Coulomban]]></dc:creator>
		<pubDate>Thu, 18 Apr 2019 09:00:30 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[AD]]></category>
		<category><![CDATA[CASB]]></category>
		<category><![CDATA[détection]]></category>
		<category><![CDATA[EDR]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[SOC]]></category>
		<category><![CDATA[supervision]]></category>
		<category><![CDATA[tool]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=11826</guid>

					<description><![CDATA[<p>SOC teams are finding it more and more difficult to detect increasingly complex attacks that take place over ever larger perimeters. At the same time, they are bearing the full brunt of the explosion in the number of alerts to...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/04/new-tools-soc-13/">SOAR, UEBA, CASB, EDR and others: which tools do you need for you SOC? (1/3)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>SOC teams are finding it more and more difficult to detect increasingly complex attacks that take place over ever larger perimeters. At the same time, they are bearing the full brunt of the explosion in the number of alerts to process (especially due to the myriad of technologies in use and the false positives they generate), the strengthening of the regulatory framework, and the need for more granular and rapid detection&#8230;</em></p>
<p><em>Against a backdrop of an acute shortage of cybersecurity skills, these issues cannot be addressed solely by increasing the size of SOC teams. The use of <strong>new tools</strong>, based on <strong>four strategic areas</strong>, is essential in enabling SOCs to stay ahead of threats.</em></p>
<p>&nbsp;</p>
<figure id="post-11844 media-11844" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-11844 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-0-1.png" alt="" width="1464" height="318" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-0-1.png 1464w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-0-1-437x95.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-0-1-768x167.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image-0-1-71x15.png 71w" sizes="auto, (max-width: 1464px) 100vw, 1464px" /></figure>
<p>&nbsp;</p>
<p><em>Here, <strong>extending the scope of detection</strong> enables the protection of new areas of the IS that are not sufficiently secure (such as the cloud) and of resources that are increasingly being chosen as targets (through ransomware attacks on terminals, targeted attacks using ADs, etc.).</em></p>
<p><em>At the same time, <strong>new approaches need to be adopted</strong> to detect targeted attacks (0-day, &#8220;low signal&#8221;, etc.), whose increasing sophistication is undermining existing security measures.</em></p>
<p><em>In addition to these new detection tools, <strong>an</strong> <strong>advanced knowledge of threats</strong> <strong>and attackers</strong> can improve existing detection capabilities, help prioritize incidents to be dealt with, and increase the effectiveness of the response.</em></p>
<p><em>But SOC teams are already struggling to process the events generated by existing tools. As a result, it’s essential to <strong>standardize and automate</strong> interactions between teams and systems, and, wherever possible, <strong>the sequence of analysis and response</strong>.</em></p>
<p><strong><em>Follow our series on the topic and learn how to tool up in these four strategic areas!</em></strong></p>
<p>&nbsp;</p>
<h2>Extending the scope of detection to new perimeters</h2>
<h3>A unique solution to secure all clouds: CASB</h3>
<p>Cloud Access Security Brokers (CASBs) address an area of the IS that is poorly served by traditional security measures: <strong>the cloud</strong>. The very nature of the cloud means that protection in this area requires a different approach to that used for a conventional IS; <strong>there is little or no control of resources</strong> (infrastructure, OSs, or applications—depending on the type of offering), <strong>assets are located outside the IS</strong>, etc.</p>
<p>CASBs aim to <strong>centralize </strong>and <strong>ensure that security policies are applied</strong>. Some <strong>cloud providers offer their own</strong> CASB security services (for example, Microsoft’s <em>Cloud App Security</em>); but, depending on the needs, it may be preferable to use <strong>third-party solutions</strong>, even though there is a cost to adding in another player. While CASBs aim to ensure security levels in the cloud, relying on the cloud service providers to perform this monitoring role can be counterproductive: it’s preferable to make use of a &#8220;trusted third party&#8221;.</p>
<p>In all cases, CASBs offer a diversity of solutions that can include a very large number of services—their degree of maturity depending on the solution&#8217;s publisher, the cloud provider, and the type of hosting (IaaS, PaaS, SaaS, etc.).</p>
<p>On the one hand, CASB solutions make it possible to deal with <strong>specific cloud issues</strong>, by <strong>addressing the lack of visibility in these environments</strong> (through shadow IT detection, usage statistics, etc.) and ensuring that they are <strong>compliant</strong> (verification of configurations, etc.).</p>
<p>On the other hand, they play a part in the application of traditional security measures in this cloud. In particular, <strong>data security</strong> issues (such as DLP and encryption measures, which are of special concern to regulators) and <strong>threat detection</strong> (centralization of cloud logs for transmission to SIEM, detection of abnormal behavior using UEBA (see our dedicated article on this), etc.) are parts of a CASB traditional capabilities. In addition, some stakes associated with <strong>IAM</strong> can also be addressed by these solutions (SSO, access contextualization, etc.).</p>
<p>There are two main modes of deployment when putting these features in place, each with its advantages and disadvantages. <strong>Proxy-type</strong> <strong>solutions</strong> are placed between users and the cloud service.</p>
<p>In contrast, when using <strong>API-type solutions</strong>, which are sometimes called “out-of-band”, the cloud service’s consumers communicate directly with it. Each time it’s accessed, the service queries the CASB’s APIs to evaluate the risks and authorize (or prohibit) the consumption of the service. However, to operate, API solutions rely on the interfaces offered by the cloud provider, which may limit the options.</p>
<p>At present, CASBs are relatively new and immature solutions, and their deployment is limited. However, given the increasingly broad adoption of cloud services (already well advanced), CASBs undoubtedly have a bright future. They’ll enable SOC teams to extend their surveillance to this area, which will soon represent a large proportion of any IS.</p>
<p><strong><u>Examples of CASB publishers:</u></strong></p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-11827 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image1-437x119.png" alt="" width="437" height="119" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image1.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image1-71x19.png 71w" sizes="auto, (max-width: 437px) 100vw, 437px" /></p>
<p>&nbsp;</p>
<h3>The new Swiss army knife for securing terminals: endpoint detection and response (EDR)</h3>
<p>Endpoint Detection and Response (EDR) solutions are set to enhance SOC’s detection and response capabilities <strong>for terminals</strong> (PCs, servers, etc.).</p>
<p>As the name implies, EDRs play a part in <strong>detecting</strong> attacks. In fact, they are plugging the gaps in anti-virus solutions (and other HIPSs) which make use of specific attack signatures and are therefore unsuited to detecting certain attack types—in particular advanced attacks (APTs). EDRs are based on other detection methods, with publishers generally offering a combination of techniques commonly used elsewhere.</p>
<p>Among these techniques, a large number of solutions <strong>detect the exploitation of known vulnerabilities</strong> or <strong>attack patterns</strong> (the opening of suspicious ports to dubious addresses, etc.), the <strong>analysis of files</strong> using a sandbox (local emulation, submission in the cloud, etc.), and <strong>behavioral approaches</strong> based on Machine Learning (in particular UEBA solutions—see the dedicated chapter on this). Depending on the SOC’s needs, the alerts produced can be integrated as SIEM sources, or made available directly from the solution management console.</p>
<p>In addition to their advanced detection capabilities, EDR solutions also result in a considerable <strong>increase in visibility on devices</strong>: lists of processes and services launched, lists of files in certain system directories, as well as other information that <strong>facilitates investigation</strong> in cases where an alert is raised. Some solutions go beyond mere recovery of the state of the terminal at the time of the request, enabling its history to be recovered too: generation of logs, recovery of deleted files, etc.</p>
<p>But EDRs’ features don’t end at the detection and analysis phase. In fact, these solutions enable <strong>remote remediation</strong> actions to be performed, and the complexity of these depends on the publisher: deleting or quarantining files, ending processes, quarantining the terminal from the network, modifying registry keys, etc.</p>
<p>EDRs, thus, are comprehensive solutions that come into play at every stage of the process: from detection, through analysis, to response. However, they are <strong>not intended to replace anti-virus solutions</strong>: it’s always more effective to block known attacks, even though publishers are increasingly offering solutions that combine these two types of functionality.</p>
<p><em>For more details on EDR solutions, read our dedicated article <a href="https://www.riskinsight-wavestone.com/en/2018/03/edr-nouveau-challenger-dans-la-protection-des-endpoints/">here</a>.</em></p>
<p>&nbsp;</p>
<p><strong><u>Examples of EDR publishers:</u></strong></p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-11829 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/Image2-1-333x191.png" alt="" width="333" height="191" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/Image2-1.png 333w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/Image2-1-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/Image2-1-68x39.png 68w" sizes="auto, (max-width: 333px) 100vw, 333px" /></p>
<p>&nbsp;</p>
<h3>Protecting the keys to the kingdom: Active Directory supervision</h3>
<p>Directories are among an <strong>IS’s</strong> <strong>most critical</strong> components. They provide the authentication and authorization functionality for almost all IS resources—both technical and business function—including the most critical ones. It’s therefore not surprising that compromising the AD is one of the most frequent attack methods used, since it opens numerous doors to an attacker.</p>
<p>Despite this criticality, and the fact that AD architectures are well known and have evolved little in recent years, <strong>their security has scope to improve</strong>. This is due, in particular, to their specific mode of operation (OUs, domains, trees, forests, users, etc.), which renders traditional protection and surveillance methods ineffective; a significant concern given that any vulnerability can represent a major risk for the rest of the IS.</p>
<p>AD surveillance solutions aim to overcome this problem by supervising (in real time, or during an audit) the specificities of directories (configuration, status of accounts, etc.) and <strong>detecting vulnerabilities </strong>that could result in them being compromised. To do this, AD supervision solutions have a highly detailed knowledge of how ADs function, and, in particular, the associated security issues.</p>
<p>When the solution detects a vulnerability, <strong>it raises an alert</strong> (via the SIEM, or directly) and can provide <strong>remediation advice</strong> to facilitate the work of the teams responsible for rectifying the problem.</p>
<p>AD supervision tools also enable the SOC to <strong>detect any changes in configuration</strong> (legitimate, accidental, or malicious) and continuously assure security levels for these critical components. In doing so, they make the task of numerous attackers decidedly more complex.</p>
<p>In addition to directly strengthening the AD’s security levels, such solutions can also be used to ensure <strong>compliance with standards or regulatory requirements</strong> (for example PCI DSS, etc.).</p>
<p>These solutions are not widely applied today, and their use is generally limited to one-off audits. However, given the considerable security improvements associated with the provision of detection and remediation advice, and their ease of use, such solutions have strong potential and are likely to find their place among the tools used by SOCs.</p>
<p><strong><u>Examples of AD supervision publishers:</u></strong></p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-11831 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image3-1-437x111.png" alt="" width="437" height="111" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image3-1.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/04/image3-1-71x18.png 71w" sizes="auto, (max-width: 437px) 100vw, 437px" /></p>
<p><em>You can find our second article in the series <a href="https://www.riskinsight-wavestone.com/en/2019/04/new-tools-soc-23/">here</a>.</em></p>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/04/new-tools-soc-13/">SOAR, UEBA, CASB, EDR and others: which tools do you need for you SOC? (1/3)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
