Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163
Showing posts with label analytics. Show all posts
Showing posts with label analytics. Show all posts

Friday, August 9, 2013

On Big Data for Security and Analytics Technologies


I found an interesting report, by Enterprise Strategy Group, called “The Evolution of Big Data Security Analytics Technology” providing an overview of the market landscape.  In my view, two key areas are open to research and innovation:

 

·         Real-time big data security analytics

·         Asymmetric big data security analytics

From a security perspective, whilst an increasing number of new tools, solutions and frameworks are emerging in these areas, there are a few key challenges that need to be addressed.  They relate to the quality and effectiveness of big data analytics: how to make sense of big (security) data and provide meaningful insights in order to identify new threats and security issues; how to capture this knowledge into repeatable and simplified capabilities that can be used by a wide range of stakeholders.

 

These are going to be key R&D aspects to be addressed in the future, in addition to the well-known big data issues i.e. dealing with velocity, volume and variety of data.

 

In particular HP and HP Labs are in a unique position to make progress here, also thanks to opportunity to leverage key HP assets in the space of security and big data management i.e. HP ArcSight, HP Vertica and HP Autonomy.  

 

 

 

--- Posted by Marco Casassa Mont (here and here)  ---

--- NOTE:  use this mirror blog if you prefer posting on an external blog site  ---

--- NOTE:  my original HP blog can be found here  ---

 

 

Sunday, July 28, 2013

My Tweets of the Week (22-26 July 2013)


My tweets of the week (22-26 July 2013) at https://twitter.com/MCasassaMont:

 


·         Three different roads to the 3-nanometer chip - theregister.co.uk/2013/07/25/pro… #in

·         With big data comes big responsibility - ft.com/cms/s/0/1c3e27… #in

·         “Big Data” Is Not “Big Data” Unless It Gives You Actionable Insight - searchengineland.com/big-data-is-no… #in


·         Researchers spot new breed of infected Android apps in the wild - infoworld.com/t/android/rese… #in

·         Graph analysis will make big data even bigger - infoworld.com/d/big-data/gra… #in

·         CFOs Ignore Big Data at Their Peril - online.wsj.com/article/SB1000… #in

·         Competing businesses encouraged to share incident data as the attackers do - scmagazineuk.com/competing-busi… #in

·         FTSE 350 companies demonstrate very poor security manners - scmagazineuk.com/ftse-350-compa… #in

·         Stop 80 percent of malicious attacks now - infoworld.com/d/security/sto… #in

·         SDN 101: Software-defined networking explained in 10 easy steps - infoworld.com/slideshow/1117… #in

·         Big Data Security Analytics: It Takes a Village - networkworld.com/community/node… #in

·         Software employment rises 45% in 10 years, as angst in engineering grows - computerworld.com/s/article/9240… #in

·         Happy birthday, OpenStack! Now change - networkworld.com/news/2013/0722… #in

·         True tales of (mostly) white-hat hacking - infoworld.com/d/security/tru… #in

·         Five Roles You Need on Your Big Data Team - blogs.hbr.org/cs/2013/07/fiv… #in

·         SIM card DES flaw could affect up to 500 million users - scmagazineuk.com #in

·         Are we in an enterprise startup bubble? - infoworld.com/t/startups/are… #in

 

--- Posted by Marco Casassa Mont (here and here)  ---

--- NOTE:  use this mirror blog if you prefer posting on an external blog site  ---

--- NOTE:  my original HP blog can be found here  ---

 

Friday, July 19, 2013

On Big Data for Security


I am currently focusing my R&D work in the space of “Big Data for Security”.

This is a fascinating area and, currently, a green field.

 

How to effectively leverage huge amount of collected IT information (ranging from IT logs to application and service information as well as external intelligence)  to identify new security threats, issues and provide valuable information to organisations to mitigate current and foreseeable risks?

 

HP already has core assets in the security and “Big Data” space: HP ArcSight suite (SIEM solution for event logging, storage and correlation); HP Vertica (highly parallelised, columnar database solution for storage and analytics of structured big data) and HP Autonomy (storage, indexing and retrieval of massive amount of unstructured data).

 

I am currently exploring how these capabilities could be fully leveraged in the context of big data for security, in particular in a few security verticals and types of critical security data. In addition, I am interested in exploring how the massive amount of required computation and analytics can be performed by adopting innovative solutions in the cloud (private and hybrid cloud).

 

I am looking for public use cases, case studies and requirements in this space, in particular for analytics based on big security data and anecdotes on how “big data” has been helping to address security issues.

 

 

--- Posted by Marco Casassa Mont (here and here)  ---

--- NOTE:  use this mirror blog if you prefer posting on an external blog site  ---

--- NOTE:  my original HP blog can be found here  ---

 

Wednesday, January 9, 2013

More on Safe Information Sharing in the Cloud

With the adoption of services in the Cloud, organisations inevitably lose control on their IT and might lack the critical information required to assess a variety of (business, performance and security) risks.


Traditional approaches based on SLAs and contractual agreements only partially address the above issues, as they provide only a “predefined” and static “view” of the situation which does not cope well against fully dynamic, ever changing IT operations and threat landscapes.

In this context, enabling more dynamic, controlled information sharing in the Cloud is key to improve situational awareness and address the above issues. This involves dealing with tension points between information sharers and sharees (about what to share, why to share, how to control information flows, etc.) along with trust and assurance issues.
More R&D is required in this area, in particular on how to provide safe information sharing and the relevant controls on the information flows.
At HP Labs, Cloud and Security Lab (CSL), we work in this space: we aim at shaping the vision and providing concrete solutions to be used in the market.
In previous blogs of mine, I provided an overview of our vision and related demonstrators we developed to convey it, in the space of Situational Awareness and Information Sharing in the Cloud, in particular in the context of Disaggregated IT.

I also briefly discussed the R&D work we do to provide better predictive analytics based on collected and shared data, in particular in the area of strategic security risk assessment (see our work on SILAS - Security Intelligence-as-a-Service).

I am looking for additional, concrete examples and case studies illustrating how current cloud adopters cope with situational awareness and assessment of the involved IT operation and business risks – including pros and cons or current approaches. Your input in terms of requirements, scenarios and feedback is welcome.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---