Project DiSIEM: Diversity Enhancements for Security Information and Event Management

No ratings

Presented at BSidesLisbon 2018 by

This talk presents the DiSIEM EU H2020 Project (http://disiem-project.eu/) with a special focus on its impact in terms of innovation and the current results of the project development.The DiSIEM project aims to address the limitations of SIEMs already deployed in production. Instead of proposing novel architectures for future SIEMs or modifications to existing ones, the project addresses these limitations by extending current systems, leveraging their built-in capacity for extension and customisation. The core idea of the project is to enhance existing SIEM systems with several diversity mechanisms, representing five main advances in the state of the art: 1. Integrate diverse OSINT (Open Source Intelligence) data sources available on the web. This data needs to be fetched, analysed, normalised and fused to identify relationships, trends and anomalies and hence help reacting to new vulnerabilities to the infrastructure or even predict possible emerging threats against the infrastructure monitored by the SIEM. 2. Develop novel probabilistic security models and risk-based metrics to help security analysts to decide which infrastructure configurations offer better security guarantees and increase the capacity of SOCs to communicate the status of the organisation to C-level managers. 3. Design and deploy novel visualisation methods to present the diverse live and archival data sets, to better support the decision-making process by enabling the extraction of high-level security insight from the data which will be used by the security analysts working with SOCs that operate the SIEM. 4. Integrate diverse, redundant and enhanced monitoring capabilities to the SIEM ecosystem, to increase the value of the events fed to the system. Likewise, we propose to deploy and integrate novel behavioural anomaly detectors for business-critical applications and thus improve the SIEM’s visibility into the functional security status of these monitored applications. 5. Add support for long term archival of events in public cloud storage services. In order to satisfy the security requirements of such data (which contains a lot of sensitive information), we will store such events in diverse cloud providers (e.g., Amazon, Windows Azure, Google), employing techniques such as secret sharing and information dispersal. These contributions are materialised through a set of tools and components, in the form of plugins, that can be integrated into existing SIEM systems. For example, redundant diverse analysis and trends obtained through OSINT sources can be fed to the SIEM, while new visualisation and analysis tools can be integrated by fetching data from the SIEM event database. The talk will provide an overview of the components that have been implemented in DiSIEM. Keynote: How to build your own Infosec Company - An Ode to the Boutique, not the BehemothMario Heiderich N/AN/AHate your job, hate your boss, hate your coworkers even more, cannot stand getting up every morning at seven, just to commute right into an office full of nightmares? Worry no more, rescue is near.This keynote will give you an overview on how to best get started with first building and the running your own security company. Without going insane or even bankrupt in the process.The speaker, whose handsomeness is obviously growing proportionally with his age, will share his own experiences in this realm, tell you about the pitfalls and death traps that accompany this process, and get you ready for the magic moment - you looking at your own small security company.This talk will be quite honest, so don't expect the usual start-up convention garbage presentation for "serial entrepreneurs" and similar folks.