25
BREAKING OUT OF THE SILO: THE NEED FOR BROAD SECURITY AUTOMATION Justin Pagano Julian DeFronzo

BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

  • Upload
    others

  • View
    0

  • Download
    0

Embed Size (px)

Citation preview

Page 1: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

BREAKING OUT OF THE SILO:THE NEED FOR BROAD SECURITY AUTOMATION

Justin PaganoJulian DeFronzo

Page 2: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

About Us

2

Julian

Justin

Page 3: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Siloed Automation

3

PREVENT

DETECT

CORRECT

Page 4: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Broad Automation

4

PREVENT

DETECT

CORRECT

Page 5: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Problems

5

DefendersaregettingbetterAttackersaregettingbetterfaster(VerizonDBIR2016*)*2015,2014,2013,2012,2011,2010,2009,and2008

Staffshortage(Peninsula,Cisco)

Page 6: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Industry Background & Status Quo

6

1990s– Early2000s

Page 7: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Industry Background & Status Quo

7

Late2000s Early2010s

Page 8: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Prevent Detect

Correct*

Detect

Correct

Prevent

*Solution: Broad Automation

8

*Oneofmany

Page 9: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Basic Assumptions

9

• Open APIs

• Programming skills

• Time

Page 10: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Strategies

10

• Automate therepeatableprocesses

• Automate acrosstoolsandteams

• Automate rollbacks

• Usemanualstepssparingly

Page 11: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Vulnerability/Patch Management

11

Detectvuln

ServiceRequest

ChangeRequest

Queuepatches Notify Patch! Rescan Close

tickets

=Manual

=Automated

Page 12: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Vulnerability/Patch Management

12

Detectvuln

ServiceRequest

ChangeRequest

Queuepatches Notify Patch! Rescan Close

tickets

Page 13: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Vulnerability/Patch Management

13

Detectvuln

ServiceRequest

ChangeRequest

Queuepatches Notify Patch! Rescan Close

tickets

Quarantine

Page 14: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Vulnerability/Patch Management

14

Detectvuln

ServiceRequest

ChangeRequest

Queuepatches Notify Patch! Rescan Close

tickets

QuarantineDisparatesystems• Vulnerabilityscanner• ITSM• Patchmanagement• Firewall/NetworkManagementDevice

Approve

Page 15: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Configuration Management: Firewalls

15

DefinePolicies&Standards

AuditPoliciesandRules

ReacttoDeviations

ConfigureFirewallRules

Page 16: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Configuration Management: Firewalls

16

DefinePolicies&Standards

AuditPoliciesandRules

ReacttoDeviations

Disparatesystems• ITSM• Config ManagementRepo• Firewall

ConfigureFirewallRules

Rollback

Page 17: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Configuration Management: AWS

17

Page 18: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Phishing Analysis

18

Analyzemetadata

Analyzelinks+

attachments

GrabScreenshots

MessageTrace

DeleteEmails

Notifyuserswho"read"

email

Notifyabusecontacts

Updateprevention+detection

Page 19: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Phishing Analysis

19

Analyzemetadata

Analyzelinks+

attachments

GrabScreenshots

MessageTrace

DeleteEmails

Notifyuserswho"read"

email

Notifyabusecontacts

Updateprevention+detection

Disparatesystems• AVscanner• Email/spamserver• Malwaresandbox• SIEM• Webproxy• ThreatIntel

PushButton

Page 20: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

BONUS: Screenshots

20

Page 21: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

21

Page 22: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Production System Access Management

22

UserRequestsAccess

ApprovalChain

UserProvisioned

AuditActivity?

RemoveAccess

PushButton

Page 23: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Production System Access Management

23

UserRequestsAccess

ApprovalChain

UserProvisioned

AuditActivity

RemoveAccess

Page 24: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

Policies & Compliance

24

Senddocsviaemail

Sendreminders Escalate RecordACKs Real-time

dashboards

Disparatesystems• Email• Documentmanagementsystem• Identity&AccessManagementsystem• HRIS

Quarantine

Page 25: BREAKING OUT OF THE SILO - Boston University · (Verizon DBIR 2016*) * 2015, 2014, 2013, 2012, 2011, 2010, 2009, and 2008 Staff shortage (Peninsula, Cisco) Industry Background & Status

25