
As you all know SOC is known as a security operations center and is purely meant for operations, we all rely on SOC for detecting threats. But do you know how to plan next gen soc? And when to implement SIEM?
Everyone knows only SIEM (with traditional correlation engine), SIEM tool collects logs and events from hundreds of security tools and organizational systems and generates actionable security alerts, to which the SOC team can analyze and respond. but there are other very important aspects to achieving full Next Generation SOC functionality for detecting the threats apart from the existing SIEM functionality. UEBA (User entity behavior analytics), Network traffic analysis (NTA), tools leveraging AI-ML Capabilities for risk analytics & fraud analytics with full forensics trail, Security Orchestration and Automated Response (SOAR), Open Choice of Database for Risk Analytics, and EDR/XDR (Endpoint Detection and Response)/ (Extended Detection and Response) are some of the competing technologies to make the SOC more effective and bring a lot of automation.
It is a general practice that SOC Planning is performed after deploying the SIEM solution. Whereas it should be the other way around i.e., when buying a SIEM solution, organizations heavily depend on various external research reports (such as Gartner, Forrester, etc.) It can’t be generalized that research reports are not good. Sometimes it may or may not be useful for organizations. Organizations must see which SIEM fit their requirement and which service provider has easy quick support and delivery capabilities.
Before buying a SIEM solution, Organizations should consider planning a SOC first. NexGen SOC acts as a hub or central command post, receiving telemetry data from the entire IT infrastructure of your organization, including networking devices, appliances, and information stores, regardless of resource location. The proliferation of advanced threats places great importance on collecting context from a variety of sources. In essence, SOC is the correlation point for all logged events within the organization. For each of these events, the SOC must decide how to manage and handle it.
“Without a NexGen SOC, isolated and incomplete visibility is often present, weakening the security regime.”
Below are some of my key observations in my experience working in India, the Middle East, and Africa
Most SOC does not integrate all required log sources. The biggest challenge is to decide which device to add for security monitoring. Most organizations take the only internet-facing assets/servers under monitoring. Organizations should not miss any security device logs which are critical in identifying the threats.
Maximum SIEM solutions provide a lot of standard use cases, which are used as they are; very few customize or develop new use cases. Organizations should develop new use cases/rules based on the business requirements and prioritize alerts.
This is one of the challenges observed for custom applications. Insufficient logging mechanism or difficulty to integrate with the SIEM solution, writing custom parsers contribute to the challenge. Moreover, database logs are not integrated with SIEM solutions for risk analytics. Organizations should have capabilities for monitoring the database activity and integrating the custom applications logs.
This again is one of the most ignored aspects of SOC Monitoring, because of the lack of automation and fine-tuning of the triggered false positives. Organizations can consider AI-ML-based next-gen tools for detecting threats to minimize false positives.
The fact is everyone does not have paybooks/runbooks written. If it is available, not reviewed. Organizations should have playbooks/runbooks, and review and update periodically.
Managing small number of assets will be easier without inventory. However, it becomes difficult to manage as this number grows. Organizations should have the inventory updated on addition to new log sources.
Unwillingness to adhere to policies and processes. Incomplete KT to the new resources. Not reviewing the operation Policies and Processes periodically. Organizations should review SOC documentation and review for adherence.
Mean time to detect and Mean time to respond is not achieved by the organizations or they don’t take it as a serious concern of calculation & improvement. It can be achieved by automation of alerts & continuous improvement of SOC Use cases, processes, and response playbooks. Organizations should also consider the resolved time calculation in SOC metrics.
As per the recent report, 80% of the 190+ techniques by MITRE ATT&CK framework are not detected by traditional SIEM tools. We should have a solution that detects most of the MITRE ATT&CK TTPs.
EDR/XDR can enhance the visibility of your endpoints and allows faster response time.
As per the observation, Organizations integrate the SIEM module first and later think of scaling with other components. In a situation, if you buy a SIEM (no other associated SOC components) without considering the scalability factor could cost a lot of money separately, and the integration challenge comes in.
For example, if we have a SIEM of A vendor and we’re considering implementing the SOAR component from vendor B, then there will be a challenge of implementing SOAR.
Consider a solution that is highly scalable, and easily integrated with other SOC components to improve the defense Capabilities.
ML/AI Based Security Analytics and Incident Response, Next-Gen Security Information and Event Management (SIEM), User and Entity Behavior Analytics (UEBA), Open Extended Detection and Response (XDR), Identity and Access Analytics, Network Traffic Analysis (NTA), Security Orchestration Automation and Response (SOAR), Fraud Analytics, MITRE ATT&CK Framework, Zero Trust Security, Medical Device Discovery and Monitoring, Hybrid SOC, Cloud SOC, and more!
5 Signs You Need an Insider Threat Program
Dwell Time: The No.1 Opponent of XDR and SIEM