{"id":3872,"date":"2016-09-15T06:54:26","date_gmt":"2016-09-15T06:54:26","guid":{"rendered":"https:\/\/www.happiestminds.com\/blogs\/?p=3872"},"modified":"2024-04-10T06:59:10","modified_gmt":"2024-04-10T06:59:10","slug":"security-operations-center-the-heart-of-effective-detection","status":"publish","type":"post","link":"https:\/\/www.happiestminds.com\/blogs\/security-operations-center-the-heart-of-effective-detection\/","title":{"rendered":"Security Operations Center \u2013 The Heart of Effective Detection"},"content":{"rendered":"<div id=\"bsf_rt_marker\"><\/div><p style=\"text-align: justify;\">Organizations around the world are facing cyber-attacks at regular frequency. Technology is evolving and so are safe guards, however, the threat perception is changing only for the worse. Even the latest security software and solutions have still not been able to substantially reduce either the frequency or the damage caused by IT security breaches. Experts have started thinking on those lines that are a bit different from the conventional IT security wisdom. Conventional <a title=\"IT security\" href=\"https:\/\/www.happiestminds.com\/services\/it-security-services\/\" target=\"_blank\" rel=\"noopener\">IT security<\/a> was focused on prevention but now; the focus has shifted to timely detection. The key parameter that is being looked at to reduce the damage caused by the cyber attacks is \u201cdwell time\u201d, that is, the time that the malicious agent gets inside the network to cause damage or steal whatever they want. A reduction in dwell time will seriously limit the ability of the cyber criminals to cause huge damage.<\/p>\n<p style=\"text-align: justify;\">In order to reduce this \u201cdwell time\u201d it is imperative to detect the breach in the system in the quickest possible time, it is essential to have as high visibility into the network to the extent possible and this is where the <a title=\"Security Operations center\" href=\"https:\/\/www.happiestminds.com\/wp-content\/uploads\/2016\/07\/SOC-infrastructure-setup-with-SIEM-solution.pdf\" target=\"_blank\" rel=\"noopener\">Security Operations center<\/a> (SOC) comes into play. A Security Operations center ( SOC ) in its most basic form is a dedicated nodal point inside an organization\u2019s security set up that has a team fully devoted to analyzing and correlating information. It has a \u201cnear exclusive\u201d focus on timely detection of data breaches and reducing the dwell time of the adversary, inside the network. Security operation centers monitor and analyze security round the clock across all the possible enterprise information interfaces like web sites, applications, databases, data centers, servers, networks, desktops and other such areas. A SOC is referred with other different names like &#8211; <span style=\"text-decoration: underline;\">Security Defense Center<\/span> (SDC), Security Analytics Center (SAC), Network Security Operations center (NSOC), Security Intelligence Center, <a title=\"Cyber Security\" href=\"https:\/\/www.happiestminds.com\/services\/cyber-security\/\" target=\"_blank\" rel=\"noopener\">Cyber Security<\/a> center, Threat defense center, Security Intelligence and Operations Center (SIOC).<\/p>\n<p style=\"text-align: justify;\">The foundational concept around which a SOC is usually built is \u201c<a title=\"security information and event management\" href=\"https:\/\/www.happiestminds.com\/casestudies\/security-information-and-event-management.pdf\" target=\"_blank\" rel=\"noopener\">security information and event management<\/a> (SIEM)\u201d. It deals with the aggregation of data to ensure that data from multiple sources is aggregated in a manner that makes sure all the crucial red flags or suspicious events are never missed. It correlates event information based on common characteristics like similar applications, interfaces, vectors, and vulnerabilities. This whole analysis and correlation creates alerts that are sent to all the relevant stakeholders. These alerts can be provided in the form of direct e-mails or centralized dashboards. Automated gathering of compliance data and creating actionable reports about the existing processes related to security, governance and audit, assure compliance. All the data and reports are retained for a long term for carrying out forensic analysis. The forensic analysis capability usually ensures that event logs can be searched across different platforms and time periods with any predefined criteria. This will help in finding expected patterns which can highlight any suspicious departure from the norm and generate an alert.<\/p>\n<p style=\"text-align: justify;\">The SOC is generally manned by teams\/individuals who are experts in cryptography, networking, computer engineering, security and vulnerability analysis. Some of the most commonly seen qualifications amongst the SOC experts are the following &#8211; CISSP, CEH, CSFA, CDRE, Security+, CCNA Security, F5 Certified, GIAC. \u00a0Some of the most common capabilities desired in a SOC include but are not limited to :<\/p>\n<p style=\"text-align: justify;\"><strong><em>Incident analysis<\/em><\/strong> \u2013 Breach analysis, reporting the comparison of the pre-breach &amp; post breach environments and suggestions on the possible best practices to avoid recurrence.<\/p>\n<p style=\"text-align: justify;\"><strong><em>Monitoring<\/em><\/strong> \u2013 Looking for phishing agents and Malware<\/p>\n<p style=\"text-align: justify;\"><strong><em>Cloud based applications<\/em><\/strong> \u2013 DDoS and Web application fire walls<\/p>\n<p style=\"text-align: justify;\"><strong>Insider threat analysis and mitigation<\/strong> \u2013 Combined use of existing policies, end point monitoring, and regular training to contain insider threats (both intentional and unintended)<\/p>\n<p style=\"text-align: justify;\"><strong><em>Threat intelligence \u2013 <\/em><\/strong><em>Extensive u<\/em>pdated information about all latest malware, evolving threats and vulnerabilities with their origin, signatures and the full extent of the damage that they can cause. This information will also include the information on internal technology risks like design, configuration, patch application status, etc.<\/p>\n<p style=\"text-align: justify;\"><strong><em>Analysis of Suspicious Hubs<\/em><\/strong> \u2013 There are certain servers which are used to uploading stolen account information and credentials by cyber criminals across the world so that they can be retrieved and used by the cyber attackers when they plan their move on a specific network. These are called Drop zones.<\/p>\n<p style=\"text-align: justify;\"><a title=\"cyber risk management\" href=\"https:\/\/www.happiestminds.com\/solutions\/cyber-risk-protection-platform\/\"><strong>Risk management<\/strong> <\/a>&#8211; A framework that keeps track of all the identified security incidents, vulnerabilities &amp; threats and ensures that each one of them is closed.<\/p>\n<p style=\"text-align: justify;\">The clear delegation of responsibilities and a focused approach is essential to prevent cyber criminals from getting inside networks and staying there. An SOC will make it very hard for them to stay unnoticed because it gives the enterprise the most effective and the most difficult element to bring into cyber security practices, integrated approach and proactive character.<\/p>\n<p style=\"text-align: justify;\">\n<div class=\"pld-like-dislike-wrap pld-template-2\">\r\n    <div class=\"pld-like-wrap  pld-common-wrap\">\r\n    <a href=\"javascript:void(0)\" class=\"pld-like-trigger pld-like-dislike-trigger  \" title=\"Like\" data-post-id=\"3872\" data-trigger-type=\"like\" data-restriction=\"cookie\" data-already-liked=\"0\">\r\n                        <i class=\"fas fa-heart\"><\/i>\r\n                <\/a>\r\n    <span class=\"pld-like-count-wrap pld-count-wrap\">0    <\/span>\r\n<\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Organizations around the world are facing cyber-attacks at regular frequency. Technology is evolving and so are safe guards, however, the threat perception is changing only for the worse. Even the latest security software and solutions have still not been able to substantially reduce either the frequency or the damage caused by IT security breaches. Experts [&hellip;]<\/p>\n","protected":false},"author":144,"featured_media":1499,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[139],"tags":[400,918,1249,1251,1533,1535,406],"class_list":["post-3872","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cyber-security","tag-cyber-attack","tag-it-security","tag-it-security-services","tag-security-information-and-event-management","tag-security-operations-center","tag-security-services"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/posts\/3872","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/users\/144"}],"replies":[{"embeddable":true,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/comments?post=3872"}],"version-history":[{"count":1,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/posts\/3872\/revisions"}],"predecessor-version":[{"id":11996,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/posts\/3872\/revisions\/11996"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/media\/1499"}],"wp:attachment":[{"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/media?parent=3872"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/categories?post=3872"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/tags?post=3872"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}