{"id":4807,"date":"2017-09-25T12:15:41","date_gmt":"2017-09-25T12:15:41","guid":{"rendered":"https:\/\/www.happiestminds.com\/blogs\/?p=4807"},"modified":"2024-04-10T04:45:30","modified_gmt":"2024-04-10T04:45:30","slug":"siem-what-next","status":"publish","type":"post","link":"https:\/\/www.happiestminds.com\/blogs\/siem-what-next\/","title":{"rendered":"SIEM What Next?"},"content":{"rendered":"<div id=\"bsf_rt_marker\"><\/div><p>Over past decade we have seen the evolution of<strong> <a href=\"https:\/\/www.happiestminds.com\/Insights\/siem\/\">SIEM<\/a><\/strong> from simple log management to Next Generation SIEM. During this\u00a0evolution, OEM&#8217;s have invented and used lots of buzz words like SIM, SIEM, SOC-in-the-box, NexGen SIEM, etc.<\/p>\n<p>Remember those days when simple monthly report generation was nightmare. We also witnessed SIEM database starting\u00a0from structured to unstructured and currently use of <a href=\"https:\/\/www.happiestminds.com\/solutions\/big-data-analytics-platform\/\">big data platforms<\/a>.<\/p>\n<p>What Next&#8230;.<\/p>\n<p>There is proliferation of new threat vectors and they will grow much more in upcoming years. With this shift, technology must evolve and address the issues. To address these issues SIEM tool will need to have larger data inputs from entire pile of technologies. As there will be growth in volume and velocity of data inputs, big data platforms will be used in most of the places.<\/p>\n<p>Existing <em>SIEM platforms<\/em> may get a new layer on top of them to address growing security needs. These layers will consist\u00a0of Machine learning, Behavioral Analytics, <a href=\"https:\/\/www.happiestminds.com\/solutions\/anomaly-detection\/\">Anomaly detection<\/a>, security orchestration, custom\/focused threat intelligence\u00a0IoT\u2019s &amp; Automation. We may see chat-bots used for gathering information from systems. For example, an analyst may ask <a href=\"https:\/\/www.happiestminds.com\/Insights\/chatbots\/\"><em><strong>chat-bot<\/strong><\/em><\/a> to fetch system patch level or currently logged on users. Vendors\/OEM\/Service Providers will be collaborating these technologies under one frame work.<\/p>\n<p><a href=\"https:\/\/www.happiestminds.com\/services\/machine-learning\/\">Machine learning<\/a> may be used to learn typical responses by analysts to specific patterns observed over network and provide alert\/alarms as and when patterns are matched. Tools may try to have visibility\u00a0over network traffic and capture meta data for more granular detection.<\/p>\n<p>I can foresee that L1 level analysts may be replaced by automation tools. <strong>Automation tools<\/strong> will be used to identify and\u00a0respond to majority of auto generated triggers. For example, a known blacklisted IP addressing trying to probe into my\u00a0network, automation kicks in and blocks on perimeter device. With automation possibility of use case are many, SOC &amp; IR\u00a0team will be going to love this faster way of incident response.<\/p>\n<p>L1 Analyst team may be replaced but you may see emergence of Hunt team, reverse malware analyst and forensic\u00a0teams for post breach analysis. There is shortage of people with these skills. Existing SOC people\/team better start developing skills around these areas and be market ready.<\/p>\n<p>Below are few questions CISO, SOC Managers, CIO or Management should answer to see SOC at more matured state.<\/p>\n<ul>\n<li>Have you done security posture assessment?<\/li>\n<li>What are the gaps identified and remediation plan?<\/li>\n<li>What are the objectives SOC must accomplish to solve the current problems?<\/li>\n<li>What are your mile stones short &#8211; term and Vision for long-term?<\/li>\n<li>How your risk posture line up with business objectives and Vision?<\/li>\n<li>What (people, process, technology, governance, etc.) do you need to achieve the objectives?<\/li>\n<li>What should be done internally and what can be outsourced?<\/li>\n<li>What is the required initial investment, on-going costs of running\/developing\/maturing a SOC?<\/li>\n<li>How will you prove the value of the SOC?<\/li>\n<\/ul>\n<p>Overall SIEM or specifically Security operation center are going to get more mature with many tactical equipment\u00a0integrated together.\u00a0 It\u2019s time for Security Orchestration, Automation and Response.<\/p>\n<div class=\"pld-like-dislike-wrap pld-template-2\">\r\n    <div class=\"pld-like-wrap  pld-common-wrap\">\r\n    <a href=\"javascript:void(0)\" class=\"pld-like-trigger pld-like-dislike-trigger  \" title=\"Like\" data-post-id=\"4807\" data-trigger-type=\"like\" data-restriction=\"cookie\" data-already-liked=\"0\">\r\n                        <i class=\"fas fa-heart\"><\/i>\r\n                <\/a>\r\n    <span class=\"pld-like-count-wrap pld-count-wrap\">0    <\/span>\r\n<\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Over past decade we have seen the evolution of SIEM from simple log management to Next Generation SIEM. During this\u00a0evolution, OEM&#8217;s have invented and used lots of buzz words like SIM, SIEM, SOC-in-the-box, NexGen SIEM, etc. Remember those days when simple monthly report generation was nightmare. We also witnessed SIEM database starting\u00a0from structured to unstructured [&hellip;]<\/p>\n","protected":false},"author":161,"featured_media":4808,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[225,312,228,139,136],"tags":[390,1552],"class_list":["post-4807","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analytics","category-big-data","category-management","category-security","category-siem","tag-siem","tag-siem-solution"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/posts\/4807","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/users\/161"}],"replies":[{"embeddable":true,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/comments?post=4807"}],"version-history":[{"count":1,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/posts\/4807\/revisions"}],"predecessor-version":[{"id":11916,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/posts\/4807\/revisions\/11916"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/media\/4808"}],"wp:attachment":[{"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/media?parent=4807"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/categories?post=4807"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/tags?post=4807"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}