Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics //

Security Monitoring

5/15/2014
04:55 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

A State of Security Event Overload

As many as 150,000 security events are logged each day in some enterprises, new data shows.

Target isn't the only enterprise getting inundated with security events:  The average enterprise receives more than 10,000 events a day that may or may not be malware-related, and for some of the biggest enterprises, that number jumps to more than 150,000 per day, according to new data from Damballa Labs.

It could happen to anyone, but Target has become a poster child for how easy it is to dismiss the wrong event as a false positive among the heavy volume generated by today's security tools. Target's security team evaluated the "activity" that was flagged and concluded it was not relevant for action. "With the benefit of hindsight, we are investigating whether, if different judgments had been made, the outcome may have been different," a Target spokeswoman said in the aftermath.

Damballa Labs' new data on network events, logged in the first quarter of this year, demonstrates how easy it would be for information overload to complicate the ability to respond to real threats among the benign events.

"There are lots of events each day, and [organizations] can't check on each one" individually, says Brian Foster, CTO at Damballa. "There are not enough smart people to go around. The industry needs to make humans smarter and more efficient, and then they can deal with more events... It eventually leads to automatable defenses."

Foster says the risk of missing a real event among a bunch of false positives is such that some organizations are taking a more holistic approach that looks at risk, prevention and detection, and response. "How many active infections are those alerts resulting in?" he asks, and how much data is going out the door as the attackers steal it?

"Security teams must be able to automate infection 'hunting' and prioritize their response. Otherwise they will find the wolf is already inside their network," Damballa's new Q1 2014 State of Infections Report says.

The full report is available here for download.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
NHARTSELL787
50%
50%
NHARTSELL787,
User Rank: Apprentice
6/12/2014 | 10:49:27 AM
Re: Overload indeed.
The issue of training, pay and retention are certainly important.  But that is ultimately just short term supply and demand.  It doesn't really address the larger issue:

How many security staff do you have?  For a typical company...

Rev x % spend on IT x % of that spent on security x % of that spent on security staff x % of those doing actual analysis

For example....

$1B rev company x 5% x 10% x 30% X 25% = $375K

Assuming a loaded labor cost of $200K, that's about two headcount.

Now get these two guys to stay on top of 150,000 alerts a day - and also fix the CEO's expired password?

Versus...

Based on some research by the U.S. intelligence, the total number of registered hackers in China is approaching 400,000.  Source: http://securecyber.blogspot.com/2010/02/should-we-be-afraid-of-chinese-hackers_19.html  (Ok, it's a number, but even if it's off by an order of magnitude or two...you get the point)

And these guys only need ONE window a jar in your network...

So we are hugely outnumbered.

The only answer is leverage.  And leverage will have to come from machines that can learn to  tie together indicators of compromise (not produce more malware signatures) that increasingly get better at separating signal from noise. Then our two lone staff can be pointed to the right data (not big data, please), analyze it fast for patterns that - if presented visually -  enable humans to see an activity pattern faster than a machine, then teach the machine this new analytic.  Rinse and repeat as in GTD.

Shameless plug - this is what we are working on at clicksecurity.com.
AccessServices
50%
50%
AccessServices,
User Rank: Apprentice
5/19/2014 | 7:37:49 AM
Staffing and Training
I see inside a lot of companies.  The number one security issue I see is with staffing.  Companies will spend thousands to millions of dollars on tools that no one knows how to use.  Managers say, 'I don't want to train people because they leave'.  These qualified people leave because they make more elsewhere.  I don't buy the story about there are not enough qualified people.  Unemployment has been high for years and especially for new graduates.  HR needs to work with IT managers to have a plan to immediately give the high acheiving employees raises.  It could be bring in employees as contractors first at a low wage.  If they prove themselves by passing tests and receiving high marks by managers, they are brought on full time with a significant increase in income.  On line training is cheap. 


Companies are receiving too many alerts because no one has the time to take a long look at all the alerts and start filtering the noise.  Where is your critical data?  Know where it is and prioritize your alerts.  Take a day or two and think about what is really at risk in your organization then go protect what is important. 
Robert McDougal
50%
50%
Robert McDougal,
User Rank: Ninja
5/16/2014 | 11:53:22 AM
Overload indeed.
This is a major issue that faces all security professionals.  There is simply too much traffic to be able to evaluate it all.  Therefore, we must rely on signatures to detect security events.  Even that only narrows down the results from billions to hundreds of thousands.  As a result, many of those events are never investigated becauser there simply isn't enough man power to properly investigate.

Also, this doesn't even take into account the security events for which there are no signatures.
Zero-Factor Authentication: Owning Our Data
Nick Selby, Chief Security Officer at Paxos Trust Company,  2/19/2020
44% of Security Threats Start in the Cloud
Kelly Sheridan, Staff Editor, Dark Reading,  2/19/2020
Ransomware Damage Hit $11.5B in 2019
Dark Reading Staff 2/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7914
PUBLISHED: 2020-02-21
btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.
CVE-2016-4606
PUBLISHED: 2020-02-21
Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized actions. This may aid in other attacks.
CVE-2020-5243
PUBLISHED: 2020-02-21
uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent hea...
CVE-2019-14688
PUBLISHED: 2020-02-20
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial produc...
CVE-2019-19694
PUBLISHED: 2020-02-20
The Trend Micro Security 2019 (15.0.0.1163 and below) consumer family of products is vulnerable to a denial of service (DoS) attack in which a malicious actor could manipulate a key file at a certain time during the system startup process to disable the product's malware protection functions or the ...