SIEM: Is It What Is SIEMs? Security Information and Event Management Summit at CSI 35th Conference

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

3 comments

Comments 1 - 3 of 3 previous next Post a comment

  • + anton_chuvakin Anton Chuvakin 7 months ago
    Thanks for the praise. Sadly, I spent a few years in that part of realm as well and had a chance to learn all the bizarreness and weirdness of SIM/SEM/SIEM swamp.
  • + guestdade263 guestdade263 7 months ago
    Not’n much to add to it apart from this: you, sir, are correct :-)

    Identity correlate this now!!!
  • + guest8a2582 guest8a2582 7 months ago
    looooooooooooooooooooool this is the most funniest presentation I’ve ever seen in my whole life and it’s like the old say -sad but true- vendors seriously need to stop overselling SIEM :) I’ve been in this crapy business for about 4 years now and I don’t believe in shit!!! ~compliance monitoring, fraud detection, automated threat analysis, identity correlation (my ass) – excuse the expression but this is the only way to explain this!!!
Post a comment
Embed Video
Edit your comment Cancel

Notes on slide 1

SIEM: Is It What Is SIEMs? Security Information and Event Management Summit at CSI 35th Conference Anton Chuvakin's presentation from "SIEM: Is It What Is SIEMs?" Security Information and Event Management Summit at CSI 35th Conference security SIEM SEM SIM management

1 Favorite

SIEM: Is It What Is SIEMs? Security Information and Event Management Summit at CSI 35th Conference - Presentation Transcript

  1. SIEM. Is It What Is “SIEMs”? Dr. Anton Chuvakin Chief “SIEM Advocatus Diaboli”  SIEM and Log Management Summit 35 th Annual CSI Conference
  2. What is SIEM?
    • SIM? /information/
    • SIM? /incident/
    • SEM?
    • SIEM?
    • “ ESM” – puuuulease 
  3. Brief History of SIEM
    • 1996 - first SIEM vendors launch
    • 2000 – “ SIEM winner ” ArcSight launches
    • 2002-2007 – some SIEM vendors are acquired
    • 2002 – 2007 – more vendors launched
    • What’s Next?
  4. Questions to Think About
    • Is SIEM relevant today, after 12 (!) years in biz?
    • Is SIEM evolving fast enough? Is it evolving?
    • What today’s problem does it solve?
    • Is SIEM for everybody ? Every large company?
    • Is SIEM a “ MUST HAVE ” now? Later?
    • SIEM vs/with/same as Log Management ?
    • Has SIEM over-reached what it can do?
    • Do you believe SIEM promise of a single intelligent security observation pane ?
  5. What I Wish More People “Get” About SIEM
    • Vendors : STOP (!!!!!!!!!!!!!!!!!) overselling it
    • Users : stop believing vendors that SIEM = ESM
    • Vendors : solve problems that users have TODAY (ideally, “… and tomorrow”)
    • Users: define what problems you plan to solve with SIEM before buying
  6. Let The Games Begin!
    • Comment!
    • Interrupt!
    • Criticize!
    • Inflame!
    • Ask!
    • Go!
  7. Hour 1: Lessons Learned
    • Who has the use cases? Problems vs use cases!
    • Vendor: What problem do you have? – Customer: What problem do you solve?
    • Human factor – SIEM is NOT a SOC in a box
    • Business case – vendor helps, not “does it for you”
    • NEVER talk “solutions” before you talk “problems”
    • What do you want? SIEM. No!!! Tell me what pains you and we figure whether SIEM solves it!
    • Making SIEM easy is NOT easy. Is it impossible?
  8. Hour 2: Lessons Learned
    • Crappy SIEM product -> in-house development -> back to commercial is actually pretty common, if sad, route
    • “ Fraud” is not just a remote future use case; people are starting to do it now
    • Customer want to see a commitment from vendors to improve and develop “ahead of problems”, not just respond to problems

+ Anton ChuvakinAnton Chuvakin, 2 years ago

custom

2822 views, 1 favs, 2 embeds more stats

Anton Chuvakin's presentation from "SIEM: Is It Wha more

More info about this document

© All Rights Reserved

Go to text version

  • Total Views 2822
    • 2747 on SlideShare
    • 75 from embeds
  • Comments 3
  • Favorites 1
  • Downloads 0
Most viewed embeds
  • 74 views on http://chuvakin.blogspot.com
  • 1 views on http://www.phonescoop.com

more

All embeds
  • 74 views on http://chuvakin.blogspot.com
  • 1 views on http://www.phonescoop.com

less

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel
File a copyright complaint
Having problems? Go to our helpdesk?

Categories