Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163
Showing posts with label Security Intelligence-as-a-Service. Show all posts
Showing posts with label Security Intelligence-as-a-Service. Show all posts

Thursday, December 13, 2012

More on SILAS: Security Intelligence-as-a-Service

In a previous blog post of mine I introduced our HPL/HP work on the Security Intelligence-as-a-Service (SILAS) solution and the fact we achieved an important milestone, in collaboration with HP business groups: a full working implementation is available.


Thanks for your questions. I am providing some additional details. The SILAS solution can now be showcases to HP customers and (potential) business partners.

As previously mentioned, SILAS consists, at the very base, of an Analytics Technology that provides: statistical analysis of data; predictions based on simulations.

There is currently a major gap in organizations’ security lifecycle management processes. On the one hand, organizations carry out strategic, long-term risk assessment activities - at the business level - to identify threats and mitigate them with suitable policies and controls. This involves periodic re-assessment of their security investments. On the other hand, they heavily invest in monitoring and Security Information and Event Management solutions (SIEM - e.g. HP ArcSight) to collect information from their IT infrastructure, for compliance and governance purposes. However information gathered at this level is seldom leveraged for higher-level strategic security risk assessment, except by means of expensive and manual processes. It is primarily used at the IT Operational levels. There is increasing demand for better integration and simplification of these processes in order to maximize investments and improve the overall risk assessment.

This gap is even more evident in the context of managed services and/or disaggregated IT in the Cloud, where the organisation further loses control on their IT along with related information flows. SILAS aims at addressing this gap.

A typical scenario (where SILAS can be deployed to add value) consists of a multitenant Security Operation Center (SOC), as shown in the following picture:





In this scenario the SOC manages incidents and IT operation issues for multiple customers. SILAS calculates and provides a wide variety of strategic metrics:

• customer metrics, reflecting the effectiveness of their processes (e.g. vulnerability and threat management - VTM, identity and access management - IAM, etc.), based on the data they shared with the SOC; metrics related to external threat environments (e.g. derived from information collected from HP ArchSight, HP TippingPoint, DV Labs, OSVDB, etc.);

• metrics providing an assessment of SOC processes, e.g. how effectively they identify incidents, close alerts, deal with false positives;

• what-if analysis and predictive metrics.

SILAS is meant to:

• provide estimation of strategic (security, risk and business) metrics to decision makers and customers, in multi-tenancy, multi-customer contexts, such as Security Operation Centers and Cloud Operation Centers

• use these metrics to enable predictive and what-if analysis, by leveraging the HP/HPL Security Analytics Solution (based on modelling and simulation techniques)

• provide customers with strategic reports - based on processed metrics and prediction - to illustrate historical trends and benchmarks

• leverage Cloud infrastructure for data processing and metric estimations

The following picture illustrates the SILAS core capabilities and high-level architecture:



SILAS is not meant to be a reactive, real-time analytic solution. It leverages existing solutions such as HP ArchSight, HP TippingPoint/ThreatLinq, OSVDB, etc. to gather the relevant data. As unique differentiation, it provides longer-term estimates of critical metrics and uses them to make predictions. It provides decision support capabilities to key stakeholders (risk management teams, customers, etc). As such it nicely complements current HP SW offerings.

We are currently trialling this solution in collaboration with HP business groups.

A few screenshots of a public version of SILAS (we use for demonstration purposes) follow:




Figure 1: SILAS main dashboard. Links to various metric processing, prediction and reporting capabilities




Figure 2: SILAS metric estimation. Example of estimation of "patch take-up curve" metric estimation (i.e. how quickly an organisation patches its systems against a vulnerability), over a period of time, calculated on data collected from HP ArcSight




Figure 3: SILAS predictions and "what-if" analysis. Example of prediction to vulnerability "risk exposure", calculated with HP/HPL Security Analytics models and related simulations. Models are instantiated with previously calculated SILAS metrics, e.g. the "patch take-up curve" metric.




Figure 4: SILAS Report. Example of customer report illustrating, for a given time period, the "patch take-up curve" metric and compareing it against an anonymised version of the same metrics (in the same time period)/benchmark,  calculated by using information collected from other customers (in a multi-tenant SOC).




Figure 5: SILAS Report. Another example of customer report showing the outcomes of various "what-if" analysis, calculated with HP/HPL Security Analytics models and related simulations. Models are are instantiated with both previously calculated SILAS metrics, e.g. the "patch take-up curve" metric and the various "what-if" assumption to be explored (e.g. using specific IT security controls).




Figure 6: SILAS Report. Another example of customer report showing the historical trends of some relevant SOC process metrics indicating how effectively a SOC handles customer's incidents (e.g. in terms of time to close an alert, identify false positives or identify an incident). The report shows historical trends and anonymised benchmarks against similar, aggregated metrics, obtained from other customers.



--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---





Friday, November 30, 2012

HPL Security Intelligence-as-a-Service (SILAS)

As discussed in previous posts, our HPL Security Intelligence-as-a-Service (SILAS) solution consists, at the very base, of R&D Analytics Technology that provides: statistical analysis of data; predictions based on simulations.
We now have achieved an important milestone in collaboration with HP business groups: a full working implementation is available.

Additional details and a few screenshots of the public, R&D version of SILAS are available online. Below I attach a screenshot of the SILAS main dashboard.





A typical scenario (where SILAS can be deployed and add value) consists of a multitenant Security Operation Center (SOC),

In this scenario the SOC manages incidents and IT operation issues for multiple customers. SILAS calculates and provides a wide variety of strategic metrics: customer metrics, reflecting the effectiveness of their processes (e.g. vulnerability and threat management - VTM, identity and access management - IAM, etc.), based on the data they shared with the SOC; metrics related to external threat environments (e.g. derived from information collected from HP ArchSight, HP TippingPoint, DV Labs, OSVDB, etc.); metrics providing an assessment of SOC processes, e.g. how effectively they identify incidents, close alerts, deal with false positives; what-if analysis and predictive metrics. All these metrics can be conveyed to customers (and/or other stakeholders) via reports, by highlighting trend analysis and benchmarks.

SILAS is meant to:

• provide estimation of strategic (security, risk and business) metrics to decision makers and customers, in multi-tenancy, multi-customer contexts, such as Security Operation Centers and Cloud Operation Centers

• use these metrics to enable predictive and what-if analysis, by leveraging the HP/HPL Security Analytics Solution (based on modelling and simulation techniques)

• provide customers with strategic reports - based on processed metrics and prediction - to illustrate historical trends and benchmarks

• leverage Cloud infrastructure for data processing and metric estimations

SILAS is not meant to be a reactive, real-time analytic solution. It leverages existing solutions such as HP ArchSight, HP TippingPoint/ThreatLinq, OSVDB, etc. to gather the relevant data. As unique differentiation, it provides longer-term estimates of critical metrics and uses them to make predictions. It provides decision support capabilities to key stakeholders (risk management teams, customers, etc.). As such it nicely complement current HP SW offerings.

We are currently trialling this solution in collaboration with HP business groups.


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---





Tuesday, September 11, 2012

HP SILAS: Security Intelligence-as-a-Service

We are making good progress in the development of the HP SILAS service (Security Intelligence-as-a-Service), a project in collaboration with HP Enterprise Security Services.




SILAS aims at providing key decision makers within organisations with strategic metrics, predictions and “what- if” analysis (leveraging HP Security Analytics) for risk assessment, scenario planning and decision support.



SILAS uses information provided by current SIM/SEM solutions (e.g. HP ArcSight), threat intelligence services (e.g. HP DV Labs and HP TippingPoint/TreatLinq) and other logging systems to ground the statistical estimation of risk metrics and to provide input parameters to HP Security Analytics’ predictive metrics and simulations.



We are currently considering the deployment of SILAS within Security Operation Centres (SOCs). SOC customers will receive strategic reports consisting of trend analysis and benchmarks (against other customers in a community) on key, agreed metrics.



Current risk metrics relate to organisation processes (e.g. vulnerability management processes, incident management & user account provisioning/deprovisioning), assessment of SOC incident management processes (of relevance to the customer), external threats (e.g. Zero Day Threats) and predictive metrics (related to all the above areas).



They are meant to be delivered to key decisions makers (C*O). Looking forward to get suggestions about additional metrics that might be of relevance – at that level - in the security context and beyond it.



--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Friday, June 15, 2012

Next Steps: Security Intelligence-as-a-Service (SILAS)

Thanks for your interest in my previous blog post, related to the HP Labs R&D work we are carrying out (in collaboration with a business group) in the area of Security Intelligence-as-a-Service (SILAS).




As mentioned before, the next steps involve trialling the solution in a Security Operation Centre (SOC) environment to refine its capabilities and provide value-added risk assessment and what-if analysis capabilities to the involved decision makers.



SILAS currently processes inputs provided by various data sources (including HP ArcSight, HP TippingPoint and OSVDB) to generate meaningful, strategic risk metrics and predictions. We are planning to expand the areas where to provide these predictions and what-if analysis (via HP Security Analytics), beyond the current IAM, VTM, Web Infection and Incident Management areas.



--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---



Friday, June 8, 2012

More on Security Intelligence-as-a-Service (SILAS)

As previously mentioned in a blog of mine, we (HP Labs in collaboration with an HP business group) are making quick progress in implementing a Security Intelligence as a Service (SILAS) solution:


“SILAS (Security Intelligence-as-a-Service): this R&D work aims to build a service that provides strategic metrics and risk assessment to customers (potentially in a federated SOC environment). It gathers information from the IT infrastructure (including SIM/SEM solution, e.g. HP ArcSight, HP TippingPoint, etc.) and uses it to provide statistical analysis, support predictive risk assessment and what-if scenario analysis (via HP Security Analytics), as well as trends and benchmarking across customers. Security Analytics (predictive) models are instantiated with the data collected from the field, to provide accurate predictions and animate what-if scenarios”

One of the coming objectives is trialing this solution in a Security Operation Centre (SOC). We already have identified one but I am welcoming any expression of interest by potential customers/early adopters. In addition I welcome inputs about security risk metrics and potential what-if analysis scenarios that might be of interest/relevance. Currently we have identified a few core metrics and scenarios in the space of IAM, VTM and SOC Incident Management Processes but I am very keen in getting a wider portfolio. Please contact me for more information and/or provide your input.







--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---