Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Friday, August 9, 2013

My Tweets of the Week (05-09 August 2013)


My tweets of the week (05-09 August 2013) at https://twitter.com/MCasassaMont:

 


·         RAM wars: RRAM vs. 3D NAND flash, and the winner is...us - http://www.computerworld.com/s/article/9241488/RAM_wars_RRAM_vs._3D_NAND_flash_and_the_winner_is...us … #in

·         Enterprise whales leave R&D to the startup minnows - http://www.theregister.co.uk/2013/08/09/you_will_be_assimilated/ … #in


·         The 7 Steps Of Big Data: How To Make It Work - http://www.forbes.com/sites/netapp/2013/08/07/7-steps-of-big-data/ … #in



·         Detect the undetectable: Start with event logs - http://www.infoworld.com/d/security/detect-the-undetectable-start-event-logs-224173 …? #in

·         Banks seek big data, analytics and security start-ups for tech accelerator - http://www.zdnet.com/banks-seek-big-data-analytics-and-security-start-ups-for-tech-accelerator-7000018986/ … #in

·         Malware-as-a-service blossoms in Russia, vendor research finds - http://www.networkworld.com/news/2013/080513-lookout-malware-272528.html?hpg1=bn … #in

·         DMARC: another step forward in the fight against phishing? - http://isc.sans.edu/diary/DMARC+another+step+forward+in+the+fight+against+phishing+/16297 … #in


·         Big Data strategy essentials for business and IT - http://www.ft.com/cms/s/0/e1a68da8-fb98-11e2-8650-00144feabdc0.html#axzz2b5Eqopic … #in

·         A strategic approach to cloud integration - http://www.networkworld.com/news/tech/2013/080213-cloud-integration-272502.html?hpg1=bn … #in

·         There's a tide of unstructured data coming - start swimming - http://www.theregister.co.uk/2013/08/05/unstructured_data/ … #in

 

 

--- Posted by Marco Casassa Mont (here and here)  ---

--- NOTE:  use this mirror blog if you prefer posting on an external blog site  ---

--- NOTE:  my original HP blog can be found here  ---

Sunday, July 28, 2013

Big Data for Security: On Using DNS Logs for Security Threat Detection


I am particularly interested in the area resulting from the intersection of the following topics: big data for security, big data analytics, distributed programming and data analysis solutions, security and cloud.

 

In particular I am interested in public case studies, business cases and trials involving the usage of (large amounts of) DNS data to detect new security threats and issues.

 

Here are some key related work and approaches:

·         EXPOSURE: Finding Malicious Domains Using Passive DNS Analysis;

·         Large scale DNS analysis





·         DNS-based Detection of Scanning Worms in an Enterprise Network



  

--- Posted by Marco Casassa Mont (here and here)  ---

--- NOTE:  use this mirror blog if you prefer posting on an external blog site  ---

--- NOTE:  my original HP blog can be found here  ---

My Updated Work and Personal Web Sites


I recently updated my personal and HP Labs web sites with news, deliverables and achievements, in the space of Security, Cloud and Big Data:

·         My HP Labs Web Page

·         My Personal Web Page

 

--- Posted by Marco Casassa Mont (here and here)  ---

--- NOTE:  use this mirror blog if you prefer posting on an external blog site  ---

--- NOTE:  my original HP blog can be found here  ---

My Tweets of the Week (22-26 July 2013)


My tweets of the week (22-26 July 2013) at https://twitter.com/MCasassaMont:

 


·         Three different roads to the 3-nanometer chip - theregister.co.uk/2013/07/25/pro… #in

·         With big data comes big responsibility - ft.com/cms/s/0/1c3e27… #in

·         “Big Data” Is Not “Big Data” Unless It Gives You Actionable Insight - searchengineland.com/big-data-is-no… #in


·         Researchers spot new breed of infected Android apps in the wild - infoworld.com/t/android/rese… #in

·         Graph analysis will make big data even bigger - infoworld.com/d/big-data/gra… #in

·         CFOs Ignore Big Data at Their Peril - online.wsj.com/article/SB1000… #in

·         Competing businesses encouraged to share incident data as the attackers do - scmagazineuk.com/competing-busi… #in

·         FTSE 350 companies demonstrate very poor security manners - scmagazineuk.com/ftse-350-compa… #in

·         Stop 80 percent of malicious attacks now - infoworld.com/d/security/sto… #in

·         SDN 101: Software-defined networking explained in 10 easy steps - infoworld.com/slideshow/1117… #in

·         Big Data Security Analytics: It Takes a Village - networkworld.com/community/node… #in

·         Software employment rises 45% in 10 years, as angst in engineering grows - computerworld.com/s/article/9240… #in

·         Happy birthday, OpenStack! Now change - networkworld.com/news/2013/0722… #in

·         True tales of (mostly) white-hat hacking - infoworld.com/d/security/tru… #in

·         Five Roles You Need on Your Big Data Team - blogs.hbr.org/cs/2013/07/fiv… #in

·         SIM card DES flaw could affect up to 500 million users - scmagazineuk.com #in

·         Are we in an enterprise startup bubble? - infoworld.com/t/startups/are… #in

 

--- Posted by Marco Casassa Mont (here and here)  ---

--- NOTE:  use this mirror blog if you prefer posting on an external blog site  ---

--- NOTE:  my original HP blog can be found here  ---

 

Friday, July 19, 2013

On Big Data for Security


I am currently focusing my R&D work in the space of “Big Data for Security”.

This is a fascinating area and, currently, a green field.

 

How to effectively leverage huge amount of collected IT information (ranging from IT logs to application and service information as well as external intelligence)  to identify new security threats, issues and provide valuable information to organisations to mitigate current and foreseeable risks?

 

HP already has core assets in the security and “Big Data” space: HP ArcSight suite (SIEM solution for event logging, storage and correlation); HP Vertica (highly parallelised, columnar database solution for storage and analytics of structured big data) and HP Autonomy (storage, indexing and retrieval of massive amount of unstructured data).

 

I am currently exploring how these capabilities could be fully leveraged in the context of big data for security, in particular in a few security verticals and types of critical security data. In addition, I am interested in exploring how the massive amount of required computation and analytics can be performed by adopting innovative solutions in the cloud (private and hybrid cloud).

 

I am looking for public use cases, case studies and requirements in this space, in particular for analytics based on big security data and anecdotes on how “big data” has been helping to address security issues.

 

 

--- Posted by Marco Casassa Mont (here and here)  ---

--- NOTE:  use this mirror blog if you prefer posting on an external blog site  ---

--- NOTE:  my original HP blog can be found here  ---

 

HP Labs Research


HP Labs has updated its Research web page, providing an overview of its 5 key research focus areas. More information is available here.

 

--- Posted by Marco Casassa Mont (here and here)  ---

--- NOTE:  use this mirror blog if you prefer posting on an external blog site  ---

--- NOTE:  my original HP blog can be found here  ---

On HP Moonshot Server Solutions


Recently HP launched the HP Moonshoot server solutions.

An interesting video titled “Meet the Innovators behind HP Moonshoot” is available online, here.

 

--- Posted by Marco Casassa Mont (here and here)  ---

--- NOTE:  use this mirror blog if you prefer posting on an external blog site  ---

--- NOTE:  my original HP blog can be found here  ---

Wednesday, January 9, 2013

More on Safe Information Sharing in the Cloud

With the adoption of services in the Cloud, organisations inevitably lose control on their IT and might lack the critical information required to assess a variety of (business, performance and security) risks.


Traditional approaches based on SLAs and contractual agreements only partially address the above issues, as they provide only a “predefined” and static “view” of the situation which does not cope well against fully dynamic, ever changing IT operations and threat landscapes.

In this context, enabling more dynamic, controlled information sharing in the Cloud is key to improve situational awareness and address the above issues. This involves dealing with tension points between information sharers and sharees (about what to share, why to share, how to control information flows, etc.) along with trust and assurance issues.
More R&D is required in this area, in particular on how to provide safe information sharing and the relevant controls on the information flows.
At HP Labs, Cloud and Security Lab (CSL), we work in this space: we aim at shaping the vision and providing concrete solutions to be used in the market.
In previous blogs of mine, I provided an overview of our vision and related demonstrators we developed to convey it, in the space of Situational Awareness and Information Sharing in the Cloud, in particular in the context of Disaggregated IT.

I also briefly discussed the R&D work we do to provide better predictive analytics based on collected and shared data, in particular in the area of strategic security risk assessment (see our work on SILAS - Security Intelligence-as-a-Service).

I am looking for additional, concrete examples and case studies illustrating how current cloud adopters cope with situational awareness and assessment of the involved IT operation and business risks – including pros and cons or current approaches. Your input in terms of requirements, scenarios and feedback is welcome.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

On Policy Decision Support for Big Data

When dealing with big data (inclusive of hybrid and unstructured one), it is very hard to understand the implications and impact of defining (security, business, sharing, privacy, etc.) policies on this data.
Which data is actually affected by the policies? Are these policies comprehensive? Are there corner cases that are not covered? Further complexity is introduced by the fact that analytics can be performed on big data, whose outcomes and implications are unknown at priori, as well.
Decision support tools are required to help policy makers to explore the implications of defining policies on big data and related analytics. In my view, these tools must provide synthetic visualization of big data as well as real-time feedback on the implications of defining specific policies and related constraints.
I am looking for:

- Tools providing synthetic, visualization of big data as well as potential analytics

- Public documentation, approaches, case studies, solutions, etc. describing how businesses currently cope with the consequences of defining (security, business, privacy, sharing, etc.) policies on big data



--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Thursday, December 13, 2012

More on SILAS: Security Intelligence-as-a-Service

In a previous blog post of mine I introduced our HPL/HP work on the Security Intelligence-as-a-Service (SILAS) solution and the fact we achieved an important milestone, in collaboration with HP business groups: a full working implementation is available.


Thanks for your questions. I am providing some additional details. The SILAS solution can now be showcases to HP customers and (potential) business partners.

As previously mentioned, SILAS consists, at the very base, of an Analytics Technology that provides: statistical analysis of data; predictions based on simulations.

There is currently a major gap in organizations’ security lifecycle management processes. On the one hand, organizations carry out strategic, long-term risk assessment activities - at the business level - to identify threats and mitigate them with suitable policies and controls. This involves periodic re-assessment of their security investments. On the other hand, they heavily invest in monitoring and Security Information and Event Management solutions (SIEM - e.g. HP ArcSight) to collect information from their IT infrastructure, for compliance and governance purposes. However information gathered at this level is seldom leveraged for higher-level strategic security risk assessment, except by means of expensive and manual processes. It is primarily used at the IT Operational levels. There is increasing demand for better integration and simplification of these processes in order to maximize investments and improve the overall risk assessment.

This gap is even more evident in the context of managed services and/or disaggregated IT in the Cloud, where the organisation further loses control on their IT along with related information flows. SILAS aims at addressing this gap.

A typical scenario (where SILAS can be deployed to add value) consists of a multitenant Security Operation Center (SOC), as shown in the following picture:





In this scenario the SOC manages incidents and IT operation issues for multiple customers. SILAS calculates and provides a wide variety of strategic metrics:

• customer metrics, reflecting the effectiveness of their processes (e.g. vulnerability and threat management - VTM, identity and access management - IAM, etc.), based on the data they shared with the SOC; metrics related to external threat environments (e.g. derived from information collected from HP ArchSight, HP TippingPoint, DV Labs, OSVDB, etc.);

• metrics providing an assessment of SOC processes, e.g. how effectively they identify incidents, close alerts, deal with false positives;

• what-if analysis and predictive metrics.

SILAS is meant to:

• provide estimation of strategic (security, risk and business) metrics to decision makers and customers, in multi-tenancy, multi-customer contexts, such as Security Operation Centers and Cloud Operation Centers

• use these metrics to enable predictive and what-if analysis, by leveraging the HP/HPL Security Analytics Solution (based on modelling and simulation techniques)

• provide customers with strategic reports - based on processed metrics and prediction - to illustrate historical trends and benchmarks

• leverage Cloud infrastructure for data processing and metric estimations

The following picture illustrates the SILAS core capabilities and high-level architecture:



SILAS is not meant to be a reactive, real-time analytic solution. It leverages existing solutions such as HP ArchSight, HP TippingPoint/ThreatLinq, OSVDB, etc. to gather the relevant data. As unique differentiation, it provides longer-term estimates of critical metrics and uses them to make predictions. It provides decision support capabilities to key stakeholders (risk management teams, customers, etc). As such it nicely complements current HP SW offerings.

We are currently trialling this solution in collaboration with HP business groups.

A few screenshots of a public version of SILAS (we use for demonstration purposes) follow:




Figure 1: SILAS main dashboard. Links to various metric processing, prediction and reporting capabilities




Figure 2: SILAS metric estimation. Example of estimation of "patch take-up curve" metric estimation (i.e. how quickly an organisation patches its systems against a vulnerability), over a period of time, calculated on data collected from HP ArcSight




Figure 3: SILAS predictions and "what-if" analysis. Example of prediction to vulnerability "risk exposure", calculated with HP/HPL Security Analytics models and related simulations. Models are instantiated with previously calculated SILAS metrics, e.g. the "patch take-up curve" metric.




Figure 4: SILAS Report. Example of customer report illustrating, for a given time period, the "patch take-up curve" metric and compareing it against an anonymised version of the same metrics (in the same time period)/benchmark,  calculated by using information collected from other customers (in a multi-tenant SOC).




Figure 5: SILAS Report. Another example of customer report showing the outcomes of various "what-if" analysis, calculated with HP/HPL Security Analytics models and related simulations. Models are are instantiated with both previously calculated SILAS metrics, e.g. the "patch take-up curve" metric and the various "what-if" assumption to be explored (e.g. using specific IT security controls).




Figure 6: SILAS Report. Another example of customer report showing the historical trends of some relevant SOC process metrics indicating how effectively a SOC handles customer's incidents (e.g. in terms of time to close an alert, identify false positives or identify an incident). The report shows historical trends and anonymised benchmarks against similar, aggregated metrics, obtained from other customers.



--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---