NEED OF SIEM TOOL FOR ORGINIZATION

 Threat Intelligence Best Practices for Your SIEM Integration - Davos  Networks - We protect your data!


What is SIEM?

SIEM stands for Security, Information and Event Management and it's pronounced SIM, "E" is silent when pronouncing. The main purpose of SIEM is, it is a system that collects log files, security alerts and events into one place. So security teams can more easily analyze data. An in another way you can think of a SIEM as a log management system specialized for security.

How does SIEM work?

SIEM collects all the information from other security systems like endpoint security, endpoint security, firewalls, intrusion detection systems. The logs and alerts from these systems needed to be stored centrally. So that analysts didn't have to go to each individual security product to conduct the investigations.

Download Whitepaper - Security Information and Event Management (SIEM)
Above image shows the tasks done from SIEM tool. SIEM offer powerful log search features, the ability to trigger alerts using rules and reports that organizations can provide to auditors to demonstrate compliance with various regulations. The new SIEM is updated with the new two technologies.

  1.  UEBA
  2.  SOAR.

UEBA stands for User and Entity Behaviour Analytics. It is an analytical slayer that tracks normal and abnormal behaviour for users and entities, like databases, servers and devices. It helps analysts spot abnormal behaviours like logins from an unusual location or machines uploading large amounts of information for the first time. Basically, UEBA helps the analyst by showing malicious activity that they should show attention. 

SOAR stands for Security, Orchestration, Automation and Response. SOAR automates what security analysts need to do to respond to security incidents. Before SOAR, analysts need to pay attention to the security incident. But because of SOAR, that task is also eliminating. As an example let's say there is a malware found on a laptop. The analyst would normally go to the Endpoint security system and quarantine the computer. Then maybe search for the source of the malware in an IDS (Intrusion Detection System)  or an IPS (Intrusion Prevention System) to make sure no one else is affected. But with the new feature SOAR, the analyst can automate the quarantine action from the SIEM. They do not need to log into the endpoint security system.  with UEBA, the system automatically detect that the malware came from a phishing link is an email. So now, the analyst wants to block that link in other emails.

SOC and SIEM

For the Security Operation Center (SOC), you can still use the SIEM. To demonstrate compliance with regulations like SOX, HIPPA and GDPR. But a more advanced use would be zero-day detection where unusual behaviour would help detect something. Some organization use SIEM for insider threat detection or threat hunting. This is a proactive search for unusual activities inside an organization. Actually, SIEM help to automate the SOC from detection through investigation and response. Many SOCs are looking to automate to make their operations more efficient and reduce their overall risk.

No matter how much large, your organization is. It is necessary to have SIEM for your organization from unknown attackers. It will help to catch malicious activities which can damage your whole business.


References:

  • https://www.youtube.com/watch?v=IeN-wjHetfA&feature=emb_logo
  • https://digitalguardian.com/blog/what-security-operations-center-soc
  • https://searchsecurity.techtarget.com/definition/security-information-and-event-management-SIEM#:~:text=A%20SIEM%20system%20also%20enhances,prevent%20the%20attacks%20in%20progress.
  • https://www.csoonline.com/article/2124604/what-is-siem-software-how-it-works-and-how-to-choose-the-right-tool.html
  • https://digitalguardian.com/blog/what-user-and-entity-behavior-analytics-definition-ueba-benefits-how-it-works-and-more#:~:text=User%20and%20entity%20behavior%20analytics%2C%20or%20UEBA%2C%20is%20a%20type,the%20normal%20conduct%20of%20users.&text=In%20UEBA%2C%20you%20do%20not,and%20entities%20in%20your%20system.
  • https://www.fireeye.com/products/helix/what-is-soar.html#:~:text=The%20benefits%20of%20SOAR,response%20and%20security%20operations%20automation.
  • https://www.youtube.com/watch?v=GbFtSDnPZBQ



Comments

  1. Good article. Can you suggest some popular SIEM tools used in the industry?

    ReplyDelete
    Replies
    1. Appreciate your comment, SolarWinds Security event manger, DataDog security monitoring, Manage engine event Log analyzer, SPLUNK Enterprise security, and OSSEC are the top 5 SIEM tools in 2020.

      Delete
    2. Nice flow Rajitha. But I'm wondering are the factors we should consider when acquiring a good SIEM tool to an organization and approximately how much will it cost?

      Delete
    3. This comment has been removed by the author.

      Delete
    4. The cost can be divided into following several parts Ruvishka.

      Hardware - SIEM appliance costs or server costs for installation of SIEM software
      Software - Costs of SIEM software or agents for data collection
      Support = Annual costs of maintenance of software and appliance
      Professional Services - Professional services for installation and ongoing tuning
      Intelligence Feeds - Threat intelligence feeds that provide information on adversaries
      Personnel - Cost of personnel to manage and monitor a SIEM implementation
      Personnel Annual Training - Cost of training the personnel annually on security certifications or other security-related training courses

      cost for SIEM tool is very high.

      Delete
  2. Replies
    1. Really appreciate your comments, It's motivate me to write more articles.

      Delete
  3. Informative article Rajitha.Can you explain about important facts to consider when choosing a commercial SIEM tool for an organization?

    ReplyDelete
    Replies
    1. Thank you Dilesha, when selectin SIEM for an organization we should check whether following details are included.

      Threat Intelligence and Analytics Capabilities.
      Ability to Manage Logs.
      Correlate Security Incidents.
      Timeliness.
      Reporting.
      Forensics Capabilities.
      Going for a POC.
      The Ability to Ingest and Process Network Logs.

      Delete
  4. SIEM is an integral component in the modern Cyber Security Operations Centers. An informative article which covers broad aspects of SIEM.

    ReplyDelete
  5. Educative post Rajitha. Keep up the good work....

    ReplyDelete

Post a Comment

Popular posts from this blog

REVOLUTION TO 5G

SOCIAL ENGINEERING