SIEM 101 Workshop
Optimize IT with Security Information and Event Management
Alex Dow Chief Research Officer – Mirai Security Inc. GCIH|SCF|CISSP|OPST Alex.Dow@miraisecurity.com https://www.miraisecurity.com
SIEM 101 Workshop Optimize IT with Security Information and Event - - PowerPoint PPT Presentation
SIEM 101 Workshop Optimize IT with Security Information and Event Management Alex Dow Chief Research Officer Mirai Security Inc. Alex.Dow@miraisecurity.com GCIH|SCF|CISSP|OPST https://www.miraisecurity.com Agenda What is SIEM? Why
Alex Dow Chief Research Officer – Mirai Security Inc. GCIH|SCF|CISSP|OPST Alex.Dow@miraisecurity.com https://www.miraisecurity.com
Normalized Data
Collector Agents
Indexes and Analytics Engine
Operating System Network Device Security Device Authentication
Event Collection & Event Management Event Correlation
Anti-X Applications
and pretty much anything ASCII!
, HTTPS/API, WMI, SMB/CIFS, FTP , ODBC, etc
Normalized Data
Collector Agents
Indexes and Analytics Engine
1 2 3 4 5
Operating System Network Device Security Device Authentication
Event Collection & Event Management Event Correlation
Anti-X Applications
, asset/network models, categorization/tagging, DNS lookups, etc
Normalized Data
Collector Agents
Indexes and Analytics Engine
1 2 3 4 5
Operating System Network Device Security Device Authentication
Event Collection & Event Management Event Correlation
Anti-X Applications
Normalized Data
Collector Agents
Indexes and Analytics Engine
1 2 3 4 5
Operating System Network Device Security Device Authentication
Event Collection & Event Management Event Correlation
Anti-X Applications
Data Sources Analytics Consumption Indexing Collection
Security Analyst
Normalization & Enrichment Transport
ODBC File
WMI/SMB
Syslog API Caching, encryption, compression, bandwidth management Asset/Network Models, DNS, GeoIP, Vuln Database, etc
Correlation Engine
ArcSight Console and Command Centre (Administrative)
Security Analyst
Primary DC Regular Remote Site
ArcSight Command Centre (Read Only Web)
Operations Team
Secondary DC Small Remote Site User Zone Security Zone Remote Sites
Virtualized Virtualized Virtualized Virtualized Virtualized Virtualized Virtualized Virtualized Virtualized
ArcSight Communications TCP8443 Event Transport TCP 8443 ArcMC C&C Communications TCP 9000-9050 Event Collection TCP 445, 1433, 443 UDP 514, 161
Legend
Virtualized Virtualized Virtualized Virtualized Virtualized Virtualized
Data Sources Master Modes Analytics Data Nodes Shipper Message Bus Collection & Parsing
ODBC File
WMI/SMB
Syslog API
Security Analyst
staff, less support from vendors