CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI...

39
CanSSOC: Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC

Transcript of CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI...

Page 1: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

CanSSOC:Sharing is Caring!Martin Loeffler – University of TorontoMI (IPS), CISSP, CISM, CISA, CRISC

Page 2: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

Who’s our audience?

Who’s in IT?

Who’s in IS?

Who’s in neither?

Page 3: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

We have a web site!

https://www.canssoc.ca

• Learn more about us• News, events, and

sign up for email notifications!

Page 4: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

What’s a‘SOC’?

A SOC is a ‘Security Operations Centre’

Like NASA’s Mission Control, but for catching hackers

Page 5: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in
Page 6: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

What does a SOC do?

Page 7: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

A SOC :

Collects data ..

Page 8: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

.. Normalizes data

Lorem ipsum is dummy text

Lorem ipsum is dummy text

L o r e m ip s u m is d u m m y t e x tLorem ipsum is dummy textLorem ipsum is dummy text

e Lorem ipsum is dummy texte Lorem ipsum is dummy texte Lorem ipsum is dummy texte Lorem ipsum is dummy texte Lorem ipsum is dummy text

Page 9: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

.. Enriches data📍 Lorem Ipsum

📍 Lorem Ipsum

📍 Lorem Ipsum

📍 Lorem Ipsum

📍 Lorem Ipsum📍 Lorem Ipsum

Page 10: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

.. Analyzes data

Page 11: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

.. Creates alerts

Page 12: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

.. And automated responses

Page 13: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

So, what is a ’CanSSOC’?

A can of socks? A Canadian clothing line?

A Canadian Shared Security

Operations Centre?

Page 14: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

What is a ’CanSSOC’?

The CanSSOC Project is a shared security operations centre

proof of concept between:

the University of Alberta, University of British Columbia,

McGill University, McMaster University, Ryerson University

and the University of Toronto.

Page 15: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

Why a ’Proof of Concept’?

Why not just build the thing?

• Technology is constantly changing

• It’s a Shared SOC – which means we have partners who need to be heard

• The technology is uncertain and, to a degree, untested

It’s not that easy ..

Page 16: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

Why build it at all?

Page 17: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

What challenges are you facing in your department?

Page 18: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

What possible

benefits of

partnership in your

space?

Page 19: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

Strategic Wins• Cyber Security Effectiveness

• Articulating return on investment

Finding budget

• Measurable metrics

• Research partnerships

Page 20: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

A Shared SOC brings more value than a stand-alone SOC

“Together we see more”

Global profile

Attracting talent

Economies of scale

Higher Ed focus

Page 21: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

Operational Wins

Analysis•Fewer erroneous alerts

than provided by current efforts – a manageable flow of information.

•Alerts prioritized by risk –asset value vs. likelihood of attack success.

Page 22: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

Operational Wins

Intelligence•A source of threat

information and early indicators of compromise

•A central source for sharing threat information

•Direct integration with institutions’ internal alert and control systems

Page 23: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

Operational Wins

Support• Relieving senior staff to respond to

incidents requiring context-specific understanding vs. spending time on junior-level analysis of raw data

• Automated responses to incidents• External resources to assist with

vulnerability identification and remediation

• Access to stored activity data / support for audit activity

Page 24: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

Operational Wins

• A communications clearing house, providing / sharing:• A broad understanding of threat

activity within the participating institutions’ environments

• Metrics for / trends of threat activity within the participating institutions’ environments

• Effective practices for risk management in use at other institutions

Communication

Page 25: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

Operational Wins

Other•Opportunities to participate

in virtual ‘centres of excellence’ to enhance professional practice

•Better value for cost than comparable commercial services – no profit motive

Page 26: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

“By partnering to share data, best practices, resources, and

infrastructure, effectiveness in identifying threats is increased,

overall costs from risk can be reduced, and broader threat-

intelligence sharing partnerships can be established.”

Page 27: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

Who else is doing this?

OmniSOC

University of Texas at Austin (CSOC)

Page 28: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

How long will it take to build?

Page 29: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

Project length is 18 months, ending in December 2019 ..

• Hire staff

• Set a project plan

• Set a budget• Develop project governance

• Establish data sharing agreements

• Meet with partners

• Develop a service catalog

• Develop architecture

• Evaluate alternatives

• Build prototypes• Run prototypes

• Test functionality• Measure performance

• Test integration

• Test reports and alerting

Page 30: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

Where are we now?

Page 31: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

.. in the middle of building something amazing

Page 32: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in
Page 33: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

Architecture

Page 34: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

ArchitectureCollect

Normalize

Enrich Analyze

Page 35: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

Threat Intelligence

Page 36: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

Monitoring

Page 37: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

CISO DashboardOverview

Customizable widgets with Metrics and KPI potentially covering everything from compliance, risk, average request times, labour costs etc. Configurable on a per user, per institution basis.

Page 38: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

CISO DashboardIncident Response Overview

Customisable widgets that show key Incident and Service Request Metrics ranging from time to contain, time to eradicate and types of incidents.

Page 39: CanSSOC: Sharing is Caring!€¦ · Sharing is Caring! Martin Loeffler – University of Toronto MI (IPS), CISSP, CISM, CISA, CRISC. Who’s our audience? Who’s in IT? Who’s in

Questions?