{"id":32693,"date":"2018-07-31T22:00:11","date_gmt":"2018-07-31T14:00:11","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=32693"},"modified":"2018-07-31T22:01:35","modified_gmt":"2018-07-31T14:01:35","slug":"reinventing-the-soc-solutions-for-improving-security-and-curing-the-alert-fatigue-epidemic","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2018\/07\/31\/reinventing-the-soc-solutions-for-improving-security-and-curing-the-alert-fatigue-epidemic\/","title":{"rendered":"Reinventing the SOC: Solutions for improving security and curing the alert-fatigue epidemic"},"content":{"rendered":"<p><strong>By Lionel Snell<\/strong><br \/>\n<strong>Editor, NetEvents<em>\u00a0<\/em><\/strong><\/p>\n<p><strong>Call it alert fatigue. Call it information overload. Call it mind-killing and soul-destroying. The sheer number of alerts coming into a modern security operations center (SOC) can overwhelm even the most dedicated security analysts.<\/strong><\/p>\n<p>Alerts pour in from many dashboards and security information and event management (SEIM) platforms, with some focused on the network, others on endpoints, some on the firewall and outside-facing servers, and others on critical infrastructure. And with the vast majority of alerts being (fortunately) false alarms, it can be easy to overlook the real warning signs\u2026 which may be subtle indications of malicious reconnaissance or an actual breach.<\/p>\n<p>As <em>SC Magazine<\/em>\u2019s Greg Masters writes in \u201c<a href=\"https:\/\/www.scmagazine.com\/crying-wolf-combatting-cybersecurity-alert-fatigue\/article\/667677\/\">Crying wolf: Combatting cybersecurity alert fatigue<\/a>,\u201d nearly three-quarters of security teams stated they were overwhelmed by the volume of vulnerability maintenance work assigned to them. When security teams were queried about contending with threat alerts, 79% said they were overwhelmed by the volume.<\/p>\n<p>And according to Ryan Francis in \u201c<a href=\"https:\/\/www.csoonline.com\/article\/3191379\/data-protection\/false-positives-still-cause-alert-fatigue.html\">False positives still cause threat alert fatigue<\/a>,\u201d published in CSO, \u201cThe Cisco 2017 Security Capabilities Benchmark Study found that, due to various constraints, organizations can investigate only 56 percent of the security alerts they receive on a given day. Half of the investigated alerts (28 percent) are deemed legitimate; less than half (46 percent) of legitimate alerts are remediated. In addition, 44 percent of security operations managers see more than 5000 security alerts per day.\u201d<\/p>\n<p>What can you do? What <em>must<\/em> you do? Reinvent the SOC. Business as usual simply can\u2019t cut it. Fortunately, there are companies working on this very challenge. <a href=\"https:\/\/www.cylance.com\/en_us\/home.html\">Cylance<\/a> pioneered the application of artificial intelligence (AI), algorithmic science, and machine learning to prevent the most sophisticated security threats. <a href=\"https:\/\/www.demisto.com\/\">Demisto<\/a>\u2019s security operations platform combines security orchestration and incident management with machine learning from analyst activities, and interactive investigation. <a href=\"https:\/\/jask.com\/\">JASK<\/a> too applies enhanced AI and machine learning to automate the correlation and analysis of threat alerts.<\/p>\n<p>Other companies like <a href=\"https:\/\/www.ca.com\/us.html\">CA Technologies<\/a> have specialist departments addressing these issues. CA\u2019s SVP Central Software Group, Dr Vinod Peris, points out that data has typically been something to look back on with hindsight: \u201cWhat we are doing with AI is to be more predictive. We&#8217;re looking not just at what you&#8217;ve missed as red flags, but alerting you that you&#8217;re likely to miss\u201d. In the case of card payment security, they use behavioural analytics to assess the gap between the transaction and expected behaviour and warn the bank.<\/p>\n<h2>People first<\/h2>\n<p>Neither Demisto nor JASK make alert fatigue their starting point. Their first concern is human resources \u2013 the lack of qualified security analysts, and a company\u2019s sheer inability to recruit, retain, and afford them. And of course, keep them from burning out.<\/p>\n<p>\u201cThe biggest problem that SOCs are having right now is talent,\u201d says Greg Fitzgerald, Chief Marketing Officer at JASK. \u201cOne is recruiting just people. Second of all is having the skillsets to just place in those jobs, and then the third piece is the experience, those that actually know what to do when they find something inside the SOC.\u201d<\/p>\n<p>Demisto\u2019s CEO, Slavik Markovich, agrees. \u201cWhen you talk with analysts and you see them day in and day out, just handling all those incoming alerts, and going through, like, tens of different tools, it burns them out.\u201d<\/p>\n<p>Markovich continues, \u201cWe looked at how analysts are working, and man, they\u2019re not happy. After six months, they\u2019re ready to run away. The average, probably, for an analyst is less than two years. The reason is that, because they\u2019re doing the same thing over and over again. Just, nobody wants to operate like that.\u201d<\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/07\/JASK.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-32694\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/07\/JASK.jpg\" alt=\"\" width=\"620\" height=\"445\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/07\/JASK.jpg 620w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/07\/JASK-300x215.jpg 300w\" sizes=\"auto, (max-width: 620px) 100vw, 620px\" \/><\/a><\/p>\n<p>In addition to the tedium, says Fitzgerald, is the lack of opportunity in many organizations. While there are many analysts, there aren\u2019t many spots for promotions. \u201cWhat needs to happen is the same thing that would happen in any job, which is they want career advancement.,\u201d he says. \u201cWhat we are seeing today is that the security operations person who has that initial job, once they get educated to understand both the process and the experience, even with a year or two, quickly leave the company. So, organizations spend a lot of time and effort getting a person up to speed, and then they leave.<\/p>\n<p>The solution there, Fitzgerald says, \u201cMake it so they have an upward career path within where they are so they can get out of the mundane job, and start doing something much more proactive about threat hunting, or actually just seeking resolution to the problem they have, or being a part of an incident response team. It\u2019s much more like the elite staff that any IT and security personnel wants to do.\u201d<\/p>\n<h2>Addressing Alert Overload<\/h2>\n<p>You\u2019ve got to address alert fatigue. Before enterprises can offer more interesting and challenging projects for security analysts, that fire hose of SEIM notices and log anomalies must be made more manageable \u2013 both in quantity and in the ratio of false alerts to real incidents.<\/p>\n<p>In the words of Greg Martin, JASK CEO and Co-Founder we need: \u201cto filter the advanced attacker from all of the noise of automated lower-level cybercrime attacks. This is where the industry is really struggling right now: how do I identify what I should care about versus the malware that I see every Monday?\u201d<\/p>\n<p>Cylance\u2019s Kumad Kalia pointed out that, despite the publicity about sophisticated attack innovations, the more common tactic is simply to overwhelm security with a flood of more basic attacks: \u201cMultiple exploits put together so, even if you detect one, you might not think to look in the other place. Sometimes, one attack will be used to overwhelm some resources to hide another stealthier attack underneath\u201d.<\/p>\n<p>Such automated attacks are best dealt with by automated response: \u201cThe future is going to be where AI is at the heart of the solution so that you&#8217;re not being overwhelmed by that amount of information, that the AI engine in the prevention tool is doing all that heavy lifting.\u201d<\/p>\n<p>\u201cTechnologies for preparing and triaging and responding automatically,\u201d are key for Demisto\u2019s Markovich. \u201cThose technologies orchestrate and automate across hundreds of different security tools, and bring the data, fully prepared and analyzed, to the analyst.\u201d<\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/07\/Demisto.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-32695\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/07\/Demisto.jpg\" alt=\"\" width=\"620\" height=\"445\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/07\/Demisto.jpg 620w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/07\/Demisto-300x215.jpg 300w\" sizes=\"auto, (max-width: 620px) 100vw, 620px\" \/><\/a><\/p>\n<p>With that data, the analyst can review the recommendation from the security tool, and either allow automation to continue to handle the incident, or choose human intervention. \u201cTriage would be look at the threat intelligence info about the incident, look at the file properties, maybe detonate the file, do all of those things,\u201d adds Markovich. \u201cThen the analyst says, okay, yeah, I think it\u2019s malicious, and then the response automation should be, okay, eradicate this email, block this end-point, block this IP, and so on and so forth.\u201d<\/p>\n<p>The upshot: The technology takes boring, tedious manual labor out of the equation, and \u201cand just allows the analyst to focus on what he\u2019s good at, which is the decision-making and the actual smart hunting and thinking about security,\u201d says Markovich.<\/p>\n<p>Smarter tools can also help with a key element of triage: choosing which alerts to focus on first. \u201cAnalysts are overwhelmed with what they have to see today, and they need some sort of prioritization,\u201d says JASK\u2019s Fitzgerald. \u201cIt\u2019s not just what\u2019s important. It\u2019s also where to start. Because an attack or a compromise can be caught at any point in the sequence, and so they need some guidance to say, help me, and that\u2019s what happening.\u201d<\/p>\n<h2>AI to the Rescue<\/h2>\n<p>Leading cybersecurity companies are leveraging artificial intelligence and machine learning in their next-generation SOC platforms. These technologies will enable automatic filtering of threat reports, allow correlation of alerts across platforms, evaluate the dangers, present recommendations \u2013 and lead to automatic remediation.<\/p>\n<p>Machine learning is a key component, because malware moves too fast to allow security systems to be trained after the event. Kumad Kalia gave the example of a Cylance system that had not been updated for two years yet could still detect the latest attack patterns. \u201cThat&#8217;s a profound demonstration of the efficacy of AI within cybersecurity\u2026 our code had never seen these types of software \u2013 probably hadn&#8217;t even been written in the combinations that were then released for attack \u2013 and the software stopped these on machines.\u201d<\/p>\n<p>Where will this go? To a solution that reinvents the SOC, with triage and front-line reporting done in real time by software \u2013 not by burned-out humans.<\/p>\n<p>Imagine, says Markovich, a SOC with a single pane of glass where the analyst gets alerts already ordered in a queue. All the alerts are already processed by AI, and are presented with all the context and data needed for a human judgment. \u201cThe analyst makes a quick decision, almost like Tinder: Swipe left, swipe right, block or it\u2019s okay.\u201d<\/p>\n<p>The action is then done by the SOC platform, so the entire response is being done automatically. Goodbye, non-stop information overload. Goodbye, mind-numbing and soul-destroying alert triage. Finally, we can cure the alert-fatigue epidemic.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The sheer number of alerts coming into a modern security operations center (SOC) can overwhelm even the most dedicated security analysts.<\/p>\n","protected":false},"author":7,"featured_media":30737,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"video","meta":{"footnotes":""},"categories":[26],"tags":[54,96],"class_list":["post-32693","post","type-post","status-publish","format-video","has-post-thumbnail","hentry","category-opinions","tag-security","tag-technology","post_format-post-format-video"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/32693","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=32693"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/32693\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/30737"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=32693"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=32693"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=32693"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}