SIEM, SOC and Threat Hunting

Choose the Best Preventative Security Measures

Your infrastructure creates a lot of logs. Hidden inside these logs can be evidence of wrongdoing – be it external criminals or employees planning or committing fraud.

How do you extract evidence of illegal behaviour when it’s buried and concealed within millions, if not billions of records of perfectly legitimate business activity?

There are a number of ways to sift through data to ascertain security exposure: Security Information and Event Management (SIEM), Security Operations Centre (SOC) and Threat Hunting are all variations of the same concept. That is, a process for storing logs and other forensic evidence, and ignoring the good to investigate only the bad. Knowing which one is right depends on how your evidence is generated and what your tolerance level for breaches is.

A SIEM is mostly an automated log solution with out-of-the-box and customisable correlation rules. If out of the box, the rules don’t take into account your risks, the value of your assets and how your business processes interact with your IT but can take some fairly good assumptions about detected hacking activity.

A SIEM, for example, can detect when an account has had multiple failed logins, followed by a successful login. It can then follow the activity of the user after the login ready for a security analyst to determine whether someone forgot his or her password or the account was ‘brute forced’.

However, a SOC goes further to provide real time response to events. Rather than logging and correlating all activity after successful login, the SOC operator can determine the most reasonable course of action: Call the employee? Lock the account or watch the account activity in real time?

Threat Hunting uses the same infrastructure but takes it further again. After the SIEM has missed a relevant event or a SOC operator has dismissed an event as benign, threat hunting looks for patterns of behaviours that may indicate a compromise. Was an admin account created through a command prompt? That’s not common. Is a computer visiting a blank website every 60 seconds? That’s more likely a remote access Trojan phoning home than a user with precise timing.

Contact us to learn more

48877512_l.jpg

Choosing the right security control depends on the following:

  • A SIEM is a great way to boost your preventative security controls. It’s for your organisation if you are only expecting general and untargeted threats, and you’re unlikely to suffer catastrophic losses should a threat slip through. Setup costs tend to be reasonable, and ongoing operational efforts are minimal.
  • A SOC is a bigger investment if you store sensitive information. If a criminal is extracting your entire credit card database on Friday night, you will not want to wait until Monday morning to act. Running a 24 x 7 SOC can be expensive if you do it in-house. However, you can outsource these services to gain substantial economies of scale.
  • Threat hunting is for your organisation if you’re at serious risk of being compromised. For example, criminals wanting to sell fake but verifiable degrees can compromise university registrars. The criminal is more interested in inserting falsified records than extracting information. To protect you against this type of attack requires ongoing access. Organisations that expect stealthy, persistent attacks such as banks and governments are also ideal users of threat hunting.

Ask an Expert For Help

The forensic review of security information, whether through a SIEM, SOC or threat hunt, provides valuable intelligence on how well your preventative security controls are coping with contemporary threat landscapes. If you feel you aren’t getting the most out of your current preventative security controls, contact Content Security to help you deliver the appropriate level of information security assurance.

Need help choosing the best preventative measures?

Contact us to learn more

Browse our other Network Security solutions:

Subscribe to our newsletter