Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Friday, April 29, 2011

Applying Security Analytics in the Space of SOC and Incident Management

Here is another exciting area in the space of Security Analytics.

I and colleagues of mine have been carrying out a few case studies, jointly with HP Customers and HP businesses, in the space of situational awareness by using Security Analytics.

This is an exciting area, very suitable for the HP Labs and HP IS Security Analytics methodology and tools, as it involves modelling critical processes, people behaviours and dealing with risk assessment issues.

The aim is to provide decision support to strategic decision makers (CISOs, CIOs, risk managers, etc.) and support the definition of related security policies.

Of particular interest and relevance is the application of our modelling & simulation methodology (along with related tools) to the processes involved in Security Operations Centres (SOCs) and related Incident Management & Remediation.

Specifically, we aim at assessing the risk exposure of organisations due to their SOC/incident management processes and the involved performance (e.g. time wasted in handling false positives). A series of metrics have been identified to measure the involved risks, e.g. time to fully manage incidents (the higher the wider the risk exposure window).

We used our analytics models to explore “what-if” scenarios e.g. the impact of changing SOC/incident management process steps, introducing automation and/or changing the number of involved personnel.

Interesting trade-offs are currently explored based on the priorities of decision makers, e.g. costs vs productivity vs security risks.



--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Identity and Security Analytics: Paper Accepted at IEEE Policy 2011 Symposium

We got a paper accepted at the IEEE Policy 2011 Symposium focusing on the Identity and Security Analytics work we did with a major HP customer:

“Marco Casassa Mont, Richard Brown
Risk Assessment and Decision Support for Security Policies and Related Enterprise Operational Processes”

The abstract of the paper follows:

“This paper presents and discusses our work to provide organizations with risk assessment and decision support capabilities when dealing with their strategic security policies. We aim at achieving this by using a rigorous and scientific methodology (and tools) which leverages modeling and simulation techniques. This methodology helps organizations to assess their risk exposure. It factors in policy implementation at the operational level along with relevant threats, processes, interactions and people behaviors. It provides “what-if” analysis by illustrating the consequences of making policy changes and investments. We introduce our methodology and tools and then illustrate how this approach has been successfully used in a real case study with one of our major customers. This case study focused on the organization’s access management processes and related policies: it helped to inform strategic security policies and support changes of current processes. Additional work is planned in this space.”


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

EnCoRe General Meeting in Venice and Networking Event for EU Framework 7 Call 8

On April 12th-14th we had an excellent General Meeting of the EnCoRe project, in Venice.

Good discussions on the third case study, system framework design and architectural aspects.

In this context, a networking event has been held to explore collaboration opportunities for the coming EU FP7 Call 8. It has been a very successful meeting with exciting opportunities, in particular in the area of “Cloud Accountability”.


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

EnCoRe Project – 11th Quarter Summary

A summary of the project’s 11th quarter activities is available here.

In this context, the EnCoRe Architecture v.2 has now been fully completed and a related document will be published shortly. This release will feature new capabilities, including Obligation Management, support for Sticky Policies and improved Internal and external workflows for the management of consent and revocations.


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Wednesday, March 9, 2011

Conference – Centre for Cybercrime and Computer Security Conference

I have been invited to give a presentation at the coming Conference at the Centre for Cybercrime and Computer Security, 15 March 2011, Newcastle.

I will be giving a presentation on “Risk Exposure to Social Networks in Enterprises”.

This is a great opportunity to network with experts in this area and to share thoughts about related HP Labs R&D activities that we have been carrying out in Bristol, UK.

Please consider attending.


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Security and Identity Analytics

I have got a paper accepted at the coming IEEE Policy 2011 Symposium.

This paper is based on a recent HPL Technical Report I published, on “Risk Assessment and Decision Support for Security Policies and Related Enterprise Operational Processes”.

Looking forward at presenting this work.

Interestingly, this paper describes work that we did jointly with a major HP customer, in the space of Security Analytics and Identity Access Management.

This work de-risked Security Analytics in this area: it is now one of the Security Analytics capabilities offered as a service by HP Information Security.



--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

UK Cyber Security Challenge 2011

I have been involved (as part of the HP Labs team) in the recent final of the UK Cyber Security Challenge 2011.

It has been a very interesting experience observing and engaging with the various participants. Very good fun.

I would really encourage the readers to engage in the coming editions.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

On the value of being part of Conference Program Committees

In the last years I have been invited to be part of many Program Committees of conferences and workshops. Just in the last month I had to deal with paper reviews for MobiSec 2011 and SECRYPT 2011.

Some statistics: based on my experience, I would say that only 25-30% of the papers that I review are usually worth their publication, because of the innovation and new insights they provide.

Nevertheless, I believe this is a great opportunity to stay in touch and up-to-date with key R&D topics. In my case, in the space of security, privacy, IAM and risk management.


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Making good progress in the UK EnCoRe Project

The UK collaborative EnCoRe project is making good progress towards achieving a key set of objectives.

I have been deeply involved in finalising the new version of the EnCoRe Architecture that will support the coming case studies and (hopefully) a pilot with a major UK company. It will be soon publicly released.

We are currently working on an “EnCoRe System Framework” that will enable grounding this architecture at the system, compliance and regulatory levels – to enable the above mentioned case studies and pilot.




--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Thursday, February 3, 2011

New HP Labs Report: Risk Assessment and Decision Support for Security Policies and Related Enterprise Operational Processes

We recently published a new HPL Technical Report illustrating the practical usage of Security Analytics in a case study involving one of our major customers:
“Marco Casassa Mont, Richard Brown - Risk Assessment and Decision Support for Security Policies and Related Enterprise Operational Processes”
The paper abstract follows:
“This paper presents and discusses our work to provide organizations with risk assessment and decision support capabilities when dealing with their strategic security policies. Traditional work in the policy management space primarily focuses on technical languages and frameworks to manage and enforce operational policies. These contributions are important but they do not address strategic decision makers’ needs and questions such as: What business and security risks is my organization exposed to, due to the current security policies and related operational processes? How effectively are these policies enforced at the operational level? What is the impact of changing them? We aim at providing strategic decision support in this space by using a rigorous and scientific methodology (and tools) which leverages modeling and simulation techniques. This methodology helps organizations to assess their risk exposure. It factors in policy implementation at the operational level along with relevant threats, processes, interactions and people behaviors. It provides “what-if” analysis by illustrating the consequences of making policy changes and investments. We briefly introduce our methodology and tools and then ground the discussion by illustrating how this approach has been successfully used in a real case study with one of our major customers. This case study focused on the organization’s access management processes and related policies: it helped to inform strategic security policies and support changes of current access management processes. Additional work is planned in this space to further validate our approach and build template solutions for different types of organizational policies and processes.”


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

New IEEE Computer Article - Using Modelling and Simulation to Evaluate Enterprises’ Risk Exposure to Social Networks

In collaboration with Penn State University, we recently published an IEEE Computer article (Research Feature) illustrating how Security Analytics can help to evaluate risks in the context of Social Networking:
“Anna Squicciarini, Sathya Dev Rajasekaran, Marco Casassa Mont – Using Modelling and Simulation to Evaluate Enterprises’ Risk Exposure to Social Networks”
The abstract follows:
“An analytic methodology involving modeling and simulation could help decision makers determine how their employees' use of social networks impacts their organization, identify how to mitigate potential risks, and evaluate the financial and organizational implications of doing so.”


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

UK Cyber Security Challenge

The UK Cyber Security Challenge has been recently announced:
“The Cyber Security Challenge is a series of national online games and competitions that will test the cyber security abilities of individuals and teams from every walk of life. It is designed to excite and inspire anyone considering a career in the cyber security industry.”
Please consider getting involved. Read here why you should to.


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Submissions to 8th International Conference TrustBus 2011

Please consider submitting a paper to the 8th International Conference on Trust, Privacy and Security in Digital Business - TrustBus 2011

The submission deadline is 27 February 2011. The Call for Papers is available online:

“The advances in the Information and Communication Technologies (ICT) have raised new opportunities for the implementation of novel applications and the provision of high quality services over global networks. The aim is to utilise this ‘information society era’ for improving the quality of life for all citizens, disseminating knowledge, strengthening social cohesion, generating earnings and finally ensuring that organisations and public bodies remain competitive in the global electronic marketplace. Unfortunately, such a rapid technological evolution cannot be problem free. Concerns are raised regarding the "lack of trust" in electronic procedures and the extent to which "information security" and "user privacy" can be ensured. In answer to these concerns, the 8th International Conference on Trust, Privacy and Security in Digital Business (TrustBus '11) will provide an international forum for researchers and practitioners to exchange information regarding advancements in the state of the art and practice of trust and privacy in digital business. TrustBus '11 will bring together researchers from different disciplines, developers, and users all interested in the critical success factors of digital business systems.”

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Thursday, December 16, 2010

On the Benefits of Combining Security Analytics with SIEM Solutions

In previous posts of mine I discussed the importance of Security Information and Event Management (SIEM) solutions in providing organisations with compliance and assurance capabilities, hence improving organisation’s situational awareness.

I often referred to these solutions as based on a bottom-up approach, i.e. starting from the collection of data, correlations and subsequent deductions of alarms, trends and analysis of organisation’s risk exposure.

In other posts I compared and contrasted this approach against the top-down approach provided by Security analytics (in particular in the IAM space – “HP Labs Identity Analytics – What is this all about?”), where models and simulations are used to provide strategic decision support. These models need to be grounded by using empirical data.

I actually believe that these two approaches can be combined to get greater benefits:

  • A key part of Security Analytics activities, is to identify the most relevant parameters, measures and metrics relevant to assess risks, provide suitable decision support and what-if analysis. Now, this information can be used to drive the configuration of SIEM solutions, by recommending which measures and metrics to focus on and their impact in enabling risk assessment and deductions;
  • SIEM solutions can collect, aggregate and process large amounts of data. This capability can be used to provide up-to-date empirical data to fuel Security Analytics models;
  • Finally, Security Analytics can be used to provide strategic decision support in the area of event and incident management, situational awareness compliance. By modelling and simulating processes related to the collection and manipulation of data, correlation of information, deduction, incident and change management, it is possible to explore the presence of potential weaknesses, faults and check for the appropriateness of the allocated resources. This would help to inform security policies and investments


Related to the third point, Security Analytics can enable the exploration of questions such as: “Are the current SIEM investments and related processes appropriate?”; “Am I focusing on the collection of the relevant data? Are my processes adequate to detect and handle specific threats?”; “What are the consequences of changing some of the processes/investing more in specific solutions and resources?”


I indeed believe that an interesting R&D area to work on is exploring how to leverage and combine these two approaches.


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

HP Information Security, Security Analytics and IAM

As mentioned in a previous post, HP Information Security has been recently launched.

Security Analytics is one of the new services provided in the context of Business Ready Security Innovation.

Aspects of the work done by HP Labs in the space of Identity Analytics - i.e. applying Security Analytics to the Identity and Access Management space - have been factored in this service:

“By combining our research and practical experience in information security, we are able to offer repeatable, short-term engagements that help you address the people, process, policy, and technology involved in your security management. These engagements cover two key areas:

  • Vulnerability and threat management (VTM)
  • Identity and access management (IAM)

Through these consultations, we’ll explore your (VTM or IAM) system, with prediction and “what-if” capabilities, get a shared multi-stakeholder understanding of the business and security trade-offs, and give you the analytics you need for justified decision-making.”


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---