Detection at Scale

No ratings

Presented at BSidesCairo 2019 by

Security detection often feels like being stuck in an endless cycle. Acquire new data, sift through the data, get overloaded, drive new automation initiatives to get us out of our backlog, and then we break stuff all over again. What if detection at scale wasn’t this at all? What if our job wasn’t to process logs at all? The Google Detection & Response team would like to show you how we are reframing our perspective of what security engineers should be experts in. Stepping back from the day to day analysis of endless log sources. Instead, we research new detection ideas and codify those into a framework supported by end to end testing. Examples of how real Google security engineers approach this idea included. Side DiscussionsN/AN/AN/AN/A