Example: confidence

AUTOMATING CYBER RISK DETECTION AND PROTECTION …

AUTOMATING CYBER RISK DETECTION AND PROTECTION WITH SOC challenges faced by CYBER security monitoring and response teams Increased threat landscape Shortage of skills Insufficient cybersecurity budget allocation Complexity in regulatory compliance Unaware employees and insider threats CloudificationCyberattack and DETECTION : Attack stages and DETECTION techniquesWhat tools help identify cyberattacks efficiently?Happiest Minds CYBER Risk PROTECTION Platform (CRPP): SOC architecture Proactive Adaptive PredictiveCyber Risk PROTECTION CenterHow does SOC address challenges that customers face? Increasing threat landscape Insufficient CYBER security budget Shortage of skills Multi-platform environment Other benefitsFinal thoughtsCONTENTSAUTOMATING CYBER RISK DETECTION AND PROTECTION WITH SOC has transformed the way business s function.

exposed to. Proactive threat simulation helps check the effectiveness of security controls, detection tools, and the response process. Simulated phishing and vishing techniques help educate and strengthen the weak links within the organization. Deception: SOC 2.0 uses deception to lure cyber criminals to attack their enterprise network, giving

Tags:

  Control, Organization

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of AUTOMATING CYBER RISK DETECTION AND PROTECTION …

1 AUTOMATING CYBER RISK DETECTION AND PROTECTION WITH SOC challenges faced by CYBER security monitoring and response teams Increased threat landscape Shortage of skills Insufficient cybersecurity budget allocation Complexity in regulatory compliance Unaware employees and insider threats CloudificationCyberattack and DETECTION : Attack stages and DETECTION techniquesWhat tools help identify cyberattacks efficiently?Happiest Minds CYBER Risk PROTECTION Platform (CRPP): SOC architecture Proactive Adaptive PredictiveCyber Risk PROTECTION CenterHow does SOC address challenges that customers face? Increasing threat landscape Insufficient CYBER security budget Shortage of skills Multi-platform environment Other benefitsFinal thoughtsCONTENTSAUTOMATING CYBER RISK DETECTION AND PROTECTION WITH SOC has transformed the way business s function.

2 With the evolution of technologies, attackers are also evolving. They are finding innovative and more invasive ways to attack organizations. Due to this, the organization 's security operations center (SOC) is expected to be more agile and dynamic in detecting and responding to attacks. Most organizations' security operations and incident response teams are overworked due to high volumes of security threats and alerts that they need to manage every day. Often, tools & technologies employed are not efficient enough to isolate true positives, rather adding to the workload. As enterprises increasingly shift to cloud and hybrid environments with digital adaptation, SOCs need to be empowered with the right tools and strategies to address complex cyberattacks efficiently.

3 They should be able to focus on priority initiatives with the help of technology. SOC and security incident response teams (SIRT) should look for ways to reduce time spent on repetitive, low-priority activities. They should build artificial intelligence and machine learning capabilities to become more efficient in handling security incidents. KEY CHALLENGES FACED BY CYBER SECURITY MONITORING AND RESPONSE TEAMS Managing the complex threat landscape with multiple security solutions can be overwhelming. Today, SOCs face a multitude of THREAT LANDSCAPEThe complexity of CYBER threats and attacks in the form of malware, ransomware, phishing, and distributed denial of service (DDoS) is witnessing a significant rise.

4 Effective, round-the-clock security monitoring becomes imperative, a challenge for many organizations. SHORTAGE OF SKILLSH aving the right skills to identify and counter attacks is as important as deploying the right tools. While the demand for skilled staff is on the rise, organizations are facing a shortage of analysts with expertise in managing CYBER threats and attacks. The number of unfilled positions continues to increase, and enterprises constantly struggle to hire the right people to maintain the balance of skill and CYBERSECURITY BUDGET ALLOCATIONAs most cybersecurity solutions help protect the organization and its stakeholders from the impact of cybersecurity breaches and attacks, justifying the budget and returns on investment (ROI) often becomes a challenge for security officers.

5 In many organizations, budget allocations are made after experiencing a security CYBER RISK DETECTION AND PROTECTION WITH SOC per MITRE ATT&CK framework there are about ~200 techniques out of which 157 techniques use Process monitoring 90 use File monitoring, and 87 used by Process command line parametersCOMPLEXITY IN REGULATORY COMPLIANCEO rganizations engage with multiple service providers or vendors to fulfill their cybersecurity requirements. However, they can face challenges linked to regulatory compliance. For example, a Europe-based organization may want specific information within the European Union, but this could be challenging if the service provider is US-based. Similarly, they may also have to meet other regulatory requirements like the GDPR, PCI, HIPA, etc.

6 , this again limits the organization 's security teams in choosing the right service providers. UNAWARE EMPLOYEES AND INSIDER THREATSMany a time, there isn't enough awareness among employees about cybersecurity. There are multiple instances of employees becoming victims of phishing scams, virus attacks, etc., which affect the entire organization . These could have been avoided if they were more aware. Despite training programs, organizations are finding it challenging to drive situational awareness among their faster time to market or elasticity to accommodate business needs, the adoption of cloud technology has increased. Organizations are embracing different platforms such as Azure AWS etc.

7 , and SaaS platforms are also gaining popularity. Most enterprises are running a hybrid model. While keeping track of the digital footprint is a challenge, choosing security monitoring solutions that can seamlessly integrate with the hybrid environment and provide comprehensive coverage is another AND DETECTION : ATTACK STAGES AND DETECTION TECHNIQUESCYBERATTACK AND DETECTION : ATTACK STAGES AND DETECTION TECHNIQUESI nitial access File monitoring Initial AccessProduct Initial Access Var Social engineering Credentials in Darkweb Social phasessecruoSataDsecruosnoitceteD Threat Intelligence, Digital riskmgmt. Vulnerability scans EDR,IPSsExecutionPersistencePrivilege escalationDefense evasionCredentialaccessDiscoveryLateralm ovementCollectionCommand& controlExfiltrationImpactAttackVerifyPos t AttackBreach File monitoring API monitoring Processmonitoring Authentication logs Windows Registry Privilege Escalation Product Execution Product Windows Registry Execution Var Persistence Product DLL monitoring Network device logs Systemcalls Defense Evasion Product ProcessCommandline EDR NIPS HIPS AV PIM/PAM Active directory NetFlow analyzer/NDR Firewalls WAF DDoS File monitoring Authentication logs API monitoring Discovery Product Application Logs Host network interface Discovery Var Lateral Movement Product NIDS.

8 Network processflow/protocol analysis Process monitoring Windows Registry Processcommand line SSL/TLS inspection Command and control Product Netflow/Enclave netflow Packet capture User interface Exfiltration Product Exfiltration Var EDR NIPS HIPS AV PIM/PAM Active directory NetFlow analyzer/NDR Firewalls WAF DDoS DLP EDR, Data lake, Forensics logs, DLPC entralized monitoring and detectionSIEMBig data analyticsSOARAUTOMATING CYBER RISK DETECTION AND PROTECTION WITH SOC utilize the latest tools and techniques to launch attacks on enterprises. To understand how attackers work, it is important to first understand the different stages involved in an attack and various techniques that will help detect the attacks.

9 The MITRE ATT&CK framework contains exhaustive details of tactics and techniques used by cybercriminals to get into a network. The framework lists multiple phases involved in a need to have the required data sources/toolsets to identify suspicious activity/behavior at different stages, which help detect security incidents efficiently. Most organizations may not have an exhaustive list of data sources to identify an attack in every phase. Still, It's important to identify what solutions or tools in your environment can help you do that and establish a road map to bring those technologies that could enhance your DETECTION example, the team may fail to detect the initial access phase, where a user clicks on a link that installs a program on the user's machine.

10 However, as the attack progresses and there's a lateral movement where the machine is trying to communicate with another machine, the SOC team may detect suspicious behavior and the possibility of an attack based on the available data example could be, under process monitoring, if new .exe or any other new file gets installed on a system, an additional process gets added to the overall processes list. An alert is generated so the team can monitor if it is a required process. Now, for the SOC team to detect such incidents, they will need appropriate information in their central security monitoring tool. They will need technologies that can identify such occurrences either on the system or in the infrastructure and forward them to the SOC platforms, so they can be acted upon.


Related search queries