Data Analysis as a Defender
Get me all your dataaaaaaaaaa!
Last updated
Was this helpful?
Get me all your dataaaaaaaaaa!
Last updated
Was this helpful?
One of the most important things to defend is to know a little bit about statistics and how to ask questions about the vast data you have by that I mean it is the sheer amount of logs that you are ingesting to your SIEM.
Statistic is the key
Let's think about the data you have okay? you have
Network (External IP Address, Internal IP Address, Bytes In, Bytes Out, Port, Protocol, and DNS)
Host (Event Log which includes a lot of information, command line, process creation, registry, authentication,...)
Security Product (Alerts, signature,...)
Application/Web Server (Access log, error,...)
-> In the end you get the point, a lot of data is sitting there and waiting to be analyzed -> In my opinion doing statistics basically baseline the system so how to do it?