Investigating with Data Flashcards
SIEM
Security Information and Event Monitoring
What does a SIEM do?
Combination of different data sources into one tool that provides real-time analysis of security alerts generated by security applications and hardware
Why are log reviews important?
Critical for security assurance and logs should be reviewed regularly and routinely, not just after an incident or as part of an instant responseS
SIEM Functionality
Correlates and analyzes log data, consolidates data from various systems into a centralized database or repository, Consolidates data from various systems into a centeralized database or repository, Detects patterns indiciating security threats, and generates alerts for security teams to investigate
Agent-Based vs. Agentless SIEM
Agent-Based and Agentless
Agent-based
Software agents that are installed on each system to collect and send log data and it provides real-time data and detailed information
Agentless
Log data is collected directly from systems using standard protocols and reduce maintenance but may not collect real-time or detailed data
SIEM Implementations considerations
Log all relevant events and filter out irrelevant data, establish and document the scope of events, develop use cases to define threats, plan incident response actions for different events, establish a ticketing process to track flagged events, schedule regular threat hunting to detect unnoticed events, and provide auditors and analysts with an evidence trail
Common SIEM Solutions
Splunk, ELK (Elastic Stack0. ArcSight, and QRadar
Splunk
Big data information gathering and analysis tool, offers connectors for various data systems, and provides search processing language for data analysis
ELK
Collection of free and open-source SIEM tools such as Elastic Search, Logstash, Kibana, and Beats
ArcSight
SIEM log management and analytics software, suitable for compliance reporting for regulations like HIPAA, SOX, and PCI DSS
QRadar
A SIEM log management, analytics, and compliance reporting platform created by IBM and it offers a dashboard for data visualization and analysis