NREN SIEM Deployment Project Speakers: Alex Dow, Barb Carra, Jill - - PowerPoint PPT Presentation

nren siem deployment project
SMART_READER_LITE
LIVE PREVIEW

NREN SIEM Deployment Project Speakers: Alex Dow, Barb Carra, Jill - - PowerPoint PPT Presentation

Conference 2018 Conference 2018 NREN SIEM Deployment Project Speakers: Alex Dow, Barb Carra, Jill Kowalchuk, Todd Williams and Ivor MacKay Speakers Alex Dow, Consultant Mirai Security Barb Carra, Chief Operating Officer Cybera Jill


slide-1
SLIDE 1

Conference 2018

Conference 2018

NREN SIEM Deployment Project

Speakers: Alex Dow, Barb Carra, Jill Kowalchuk, Todd Williams and Ivor MacKay

slide-2
SLIDE 2

Conference 2018

Speakers

Alex Dow, Consultant Mirai Security Barb Carra, Chief Operating Officer Cybera Jill Kowalchuk, NREN Coordination Manager CANARIE Inc. Todd Williams, Executive Director ACORN Ivor MacKay, Manager, Information Technology BCNET

2

slide-3
SLIDE 3

Conference 2018

Agenda

6

  • 1. Background and terminology
  • a. What is SIEM (Security Information and Event

Management). Why is it important to cybersecurity?

  • b. What is the NREN?
  • 2. NREN SIEM Deployment Project
  • a. Background on how the project came about;
  • i. why the NREN is interested in security;
  • ii. why the SIEM project was chosen.
  • b. Description of the first phase of the project;
  • c. Description of second phase;
  • d. Future considerations;
slide-4
SLIDE 4

Conference 2018

Agenda cont’d

3

  • 3. How is Cybera approaching the SIEM Project?
  • 4. How is ACORN-NS approaching the SIEM project?
  • 5. How is BCNET approaching the SIEM project?
  • 6. Q&A
  • 7. Workshop On SIEM

Thursday 9:00 am

slide-5
SLIDE 5

Conference 2018

Background and Terminology

What is SIEM (Security Information and Event Management) why is it important to cybersecurity?

5

Data Sources Analytics Consumption Indexing Collection

Security Analyst

Normalization & Enrichment Transport

ODBC File

WMI/SMB

Syslog API Caching, encryption, compression, bandwidth management Asset/Network Models, DNS, GeoIP, Vuln Database, etc

slide-6
SLIDE 6

canarie.ca | @canarie_inc

NREN SIEM Deployment Project

Jill Kowalchuk, NREN Coordination Manager | BCNET Conference | April 24, 2018

slide-7
SLIDE 7

canarie.ca | @canarie_inc

7

The NREN connects Canada’s research, education, and innovation communities via ultra high-speed (up to 100G) networks.

slide-8
SLIDE 8

canarie.ca | @canarie_inc

8

The NREN makes access to global research instruments and vast data stores seamless so that distance is irrelevant.

  • 30 Meter Telescope
  • Large Hadron Collider
  • Canadian Light Source
  • Genomics Databases
  • Neptune 2.0
  • Worldwide sensor

networks

slide-9
SLIDE 9

canarie.ca | @canarie_inc

9

How does the NREN operate?

Governed and managed by: NREN Governance Committee

(presidents of the provincial and territorial networks and of the federal partner, CANARIE)

Initiatives guided by: NREN Strategic Plan

(priority projects that evolve the NREN and maximize its value for stakeholders)

slide-10
SLIDE 10

canarie.ca | @canarie_inc

10

NREN Security

slide-11
SLIDE 11

canarie.ca | @canarie_inc

11

Security Information and Event Management (SIEM) Deployment Project

People Process Technology

slide-12
SLIDE 12

canarie.ca | @canarie_inc

12

SIEM Deployment Project

NREN Internet

RAN(s) Infrastructure End-User Institutions RAN Member(s) RAN(s) Network

SIEM Log Collectors SIEM Console

SIEM

Operational SIEM

SIEM Admin

IT Security Skills & Training

Monitored

Logs

Alarms IT Security Event Response

slide-13
SLIDE 13

canarie.ca | @canarie_inc

13

SIEM Deployment Project & Institutions

NREN Internet

RAN(s) Infrastructure End-User Institutions RAN Member(s) RAN(s) Network

SIEM Log Collectors SIEM Console

SIEM

Operational SIEM

SIEM Admin

IT Security Skills & Training

Monitored Logs Alarms IT Security Event Response Monitored Logs

slide-14
SLIDE 14

canarie.ca | @canarie_inc

14

Future Considerations

Imag Image e source: e: https://gbhac acker ers.com

slide-15
SLIDE 15

canarie.ca | @canarie_inc

slide-16
SLIDE 16

Conference 2018

The Other Regional Network Approaches

3

§

How is Cybera approaching the SIEM Project? § How is ACORN-NS approaching the SIEM project? § How is BCNET approaching the SIEM project?

slide-17
SLIDE 17

Conference 2018

Q & A

slide-18
SLIDE 18

Conference 2018

Workshop On SIEM Thursday 9:00 am