Top Banner
© 2020 SPLUNK INC. Full Speed Ahead With Risk-Based Alerting (RBA) Kyle Champlin Principal Product Manager | Splunk Jim Apger Staff Security Strategist | Splunk
48

Full Speed Ahead With Risk-Based Alerting (RBA)

Jan 12, 2022

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

© 2 0 2 0 S P L U N K I N C .

Full Speed Ahead With Risk-Based Alerting (RBA)

Kyle ChamplinPrincipal Product Manager | Splunk

Jim ApgerStaff Security Strategist | Splunk

Page 2: Full Speed Ahead With Risk-Based Alerting (RBA)

During the course of this presentation, we may make forward‐looking statements regarding future events or plans of the company. We caution you that such statements reflect our current expectations and estimates based on factors currently known to us and that actual events or results may differ materially. The forward-looking statements made in the this presentation are being made as of the time and date of its live presentation. If reviewed after its live presentation, it may not contain current or accurate information. We do not assume any obligation to update any forward‐looking statements made herein.

In addition, any information about our roadmap outlines our general product direction and is subject to change at any time without notice. It is for informational purposes only, and shall not be incorporated into any contract or other commitment. Splunk undertakes no obligation either to develop the features or functionalities described or to include any such feature or functionality in a future release.

Splunk, Splunk>, Data-to-Everything, D2E and Turn Data Into Doing are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names or trademarks belong to their respective owners. © 2020 Splunk Inc. All rights reserved

Forward-LookingStatements

Page 3: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Agenda1) More MITRE ATT&CK

Improvements

2) Threat Objects and SOARIntroduction

3) Customer WinCompelling

4) Enterprise SecurityAcceleration

Page 4: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Staff Security Strategist | Splunk

Jim Apger

Page 5: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

ALERT FATIGUEfacepalm

Page 6: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

ALERT SUPRESSIONdouble facepalm

Page 7: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

The Business of SOCTraditional Approach

“Highly illogical.” — Spock

Analytics (Correlation Rules)

Ope

ratio

nal C

osts

Endpoint/EDRDNS Cloud

Page 8: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

The Business of SOCRBA

"Logic is the beginning of wisdom, not the end." -- Spock

“Logic is the beginning of wisdom, not the end.” — Spock

Analytics (Correlation Rules)

Ope

ratio

nal C

osts

Endpoint/EDRDNS Cloud

Page 9: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

RBA Milestones

Early Adopters2018

Risk Rules

Risk Scoring

MITRE ATT&CK

Risk Index

Risk Notables

.Conf18 talk

Accelerated Adoption2019

SA-RBA Reference App

(4) .Conf19 talks

SANS and ISC2 talks

Evolution2020

MITRE ATT&CK

Threat Objects

SOAR

Attack Web Viz

Turnkey Enterprise Security2020

PM Updates

3-Year Journey

Page 10: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

MITRE ATT&CKMap to Technique

Page 11: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

MITRE ATT&CKAdd ATT&CK Context

Page 12: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

MITRE ATT&CK

https://raw.githubusercontent.com/mitre/cti/master/enterprise-attack/enterprise-attack.json

-OR-

-OR-

Page 13: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

MITRE ATT&CK

Page 14: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

MITRE ATT&CK

Page 15: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

MITRE ATT&CKSlow-and-Low

days or even weeks

Page 16: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

MITRE ATT&CKImproved Detections!

days or even weeks

Page 17: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

MITRE ATT&CKInvestigation

Page 18: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

IOCs as Threat Objects

URL

Command

Domain

Protocol

IP

Filehash

Registry

Username

Page 19: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Threat ObjectsPer Risk Rule

Tactic

Score Threat Object

user

destsrc

Risk Object

Page 20: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Threat ObjectsSet the Stage

Tactic

Score Threat Object

user

destsrc

Risk ObjectTactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Score

TacticThreat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Page 21: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Threat ObjectsDetect and Carry Forward

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

TacticTactic

Tactic

Tactic

Notable Events• Risk Object• Risk Score• ATT&CK Context

+ Threat Object

Page 22: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Tactic

Score Threat Object

user

destsrc

Risk Object

Score

TacticThreat Object

user

destsrc

Risk Object

Threat ObjectsRelated Objects

src

Threat Object

src

Threat Object

Page 23: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Threat ObjectsVisualize

"Fascinating.” -- Spock

Page 24: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Threat ObjectsRisk Notables Into Phantom

Page 25: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Threat ObjectsAutomation

Page 26: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Professional Services

“As a security practitioner and network defender, the RBA methodology is dramatically streamlining the amount of effort security analysts spend triaging security alerts, and finally giving them the opportunity to zero in on high fidelity, high confidence risk alerts that are absolutely worth their time and effort.”

– Marquis Montgomery, Principal Security Architect, Global Security Services at Splunk

Page 27: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Provided by Viasat and the Viasat CSOC

Page 28: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Provided by Viasat and the Viasat CSOC

Page 29: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Provided by Viasat and the Viasat CSOC

Page 30: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Provided by Viasat and the Viasat CSOC

Page 31: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

More RBA Content

RBA/Phantom Content Links in the Speaker Notes

Page 32: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Principal Product Manager | Splunk

Kyle Champlin

Page 33: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Chartsand Tables

Page 34: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Page 35: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Risk Based Alerting

Do you suffer from any of these symptoms?• alert fatigue, ballooning allow/deny lists, situational numbness

Are you• An existing ES user who wants to get ES more "operationalized”?• Brand new ES customers who would benefit from a more turn-key SIEM experience?• A smaller SOC team that wants a solution that will mature and grow with them?

Is It Right For Me?

Page 36: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Risk Based Alerting

• Shipped out-of-box Correlation Searches mapped to MITRE ATT&CK annotations (ESCU inclusive!)

• Shipped out-of-box Correlation Searches that deploy the new "Risk” adaptive response action (existing and new, ESCU inclusive!)

• Shipped out-of-box dashboards and panels that provide a risk-centric investigative experience

• Shipped new Correlation Searches that mine the risk index for notables (risk incident rules)

What Are We Doing In ES?

Page 37: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

SA-RBA to ESMap to Technique

Page 38: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Risk AnnotationsAnnotate correlation searches directly in the CS editorATT&CK techniques are pre-populated

Page 39: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Risk Annotations

Always kept up to date with the latest from MITRE

Page 40: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

SA-RBA to ESDynamic Scoring & Multiple Risk Objects

Page 41: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Risk Action

Score multiple objects per correlation

Extensible Object Type List

Page 42: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Risk Factors

Manage your risk factors

Create simple or advanced matching lconditions, as well as stack conditions w/in a single factor

Page 43: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

SA-RBA to ESThreat Object Support

Page 44: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Updated Risk Data Model

Scores are calculated via factors during DMARisk & Threat Object

Support

Additional MITRE ATT&CK enrichment

Page 45: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

SA-RBA to ESAuto-Enrichment Of ATT&CK data

Page 46: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Updated Risk Data ModelRisk events are now auto-enriched for any data model searches and risk index searches

Page 47: Full Speed Ahead With Risk-Based Alerting (RBA)

© 2 0 2 0 S P L U N K I N C .

Updated Risk Analysis Dashboard Panels

New panels showing risk modifiers by ATT&CK technique

New panels showing risk modifiers by ATT&CK technique

Page 48: Full Speed Ahead With Risk-Based Alerting (RBA)

SESSION SURVEYPlease provide feedback via the

© 2 0 2 0 S P L U N K I N C .

“Live long, and prosper.” — Spock