Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

10/1/2019
10:00 AM
Randy Caldejon
Randy Caldejon
Commentary
Connect Directly
LinkedIn
RSS
E-Mail vvv
50%
50%

AIOps: The State of Full Packet Capture Enters the Age of Practicality

How machine learning and artificial intelligence are changing the game of acting on large volumes of network data in near real time.

It's a great time to be a security analyst, but those who serve in the role today are facing much higher expectations from their organizations compared with when I started out. Many are teetering on the edge of burnout because their companies need to get to the truth sooner, leaving analysts stuck with traditional approaches and tactics associated with full packet capture as the high-speed network's bandwidth increases by the day.

The state of full packet capture — fundamental to enabling security analysts to hunt for threats, discover anomalies, or respond to incidents — has seen a few incremental advancements over the several decades but nothing that has allowed the analyst to allocate less time to it because there is still a bit of heavy lifting required.

As a security analyst in the military, my first experience with full packet capture in the late '90s was the SHADOW system, an open source project dubbed an intrusion-detection system but really a full packet capture system designed for retrospective analysis, also known as threat hunting. The project was essentially a framework built with tcpdump and a collection of Perl scripts. However, SHADOW lacked any form of indexing, so mining the data was quite painful.

The next breakthrough in full packet capture was Time Machine, which introduced the notion of connection cutoff and indexing for faster search and retrieval. A sister project to Zeek (formerly known as Bro), Time Machine was an interesting project with lots of promise. Unfortunately, Time Machine did not scale beyond a few gigabits per second. Finally, there is Moloch, a full packet capture and search application integrated with advanced visualization that scales to 10Gbps and more. Moloch represents the state-of-the-art in open source, full packet capture, but it is yet to be determined if it can scale to 100Gbps.

These incremental improvements were made in the background while the high-speed network expanded and has grown in importance within the organization. While the number of servers on-premises might have decreased, the quantity of mobile devices, Internet of Things sensors and cloud applications that organizations are utilizing today to improve operations is increasing to create an even more complex network environment, making the traditional approaches to full packet capture even more impractical.

Adding to the problem is the recent rise in overall traffic. which is forecasted to continue. According to Cisco, companies can expect to see their network traffic triple by 2022. This will require organizations to make a proportional increase in data storage and maintain a brute force, record-everything approach for network forensics that will cost companies significantly more in terms of time and money. This runs counter to most companies' digital transformation journeys where the bigger objective is to save on operational costs, increase IT agility, and improve responsiveness.

Fortunately, full packet capture is finally entering the age of practicality because of the introduction of AIOps. Gartner defines AIOps as the application of machine learning (ML) and data science to IT operations problems. The firm also predicts that large enterprises use of AIOps tools will reach 30% by 2023. The adoption of AIOps will pave the way to security automation like intelligent packet capture. This is an exciting development that our company is pursuing, along with others in the industry, to enable security analysts to utilize AIOps for network forensics.

The advancement of machine learning (ML) and artificial intelligence (AI) is enabling new innovations in full packet capture to bring some needed relief to the security analyst. When a machine learning engine 'learns' to classify packets to predict those that need to be recorded, the security analyst benefits by having data with higher fidelity allowing he or she to conduct more meaningful and expedient forensics. As noted security analyst and trainer, Chris Sanders says in his blog post, "if you can distill a PCAP down to key events then you'll have a much more manageable set of data points to aid your investigation."

Thanks to AIOps, security analysts now have an opportunity to utilize more open source technologies and experiment with ML and AI to make packet capture work better for them and their organizations. Before it was unrealistic to expect a group of analysts in a security operations center to proactively ferret through petabytes of data in search of an anomaly or indicator of compromise in a timely manner. Normally, this would be — at best — a week-long exercise without ML or AI. Access to these enabling technologies represent a significant improvement in the state of full packet capture, making them practical and invaluable resources for security analysts.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "5 Disruptive Trends Transforming Cybersecurity."

Randy Caldejon leads the company's innovation and product development. Prior to CounterFlow, Randy was the CTO of Enterprise Forensics at FireEye. He is a widely-respected authority in network security monitoring and sensor technology. A military veteran, engineer, and serial ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
tdsan
50%
50%
tdsan,
User Rank: Ninja
10/10/2019 | 11:44:00 AM
Good Article
I thought there was an application NSA used similar to this which was called "ThinThread", William Bill Binney created this solution. From there TrailBlazer and finally Prism were created from this solution.

T

 
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
Black Hat Q&A: Hacking a '90s Sports Car
Black Hat Staff, ,  11/7/2019
The Cold Truth about Cyber Insurance
Chris Kennedy, CISO & VP Customer Success, AttackIQ,  11/7/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-16863
PUBLISHED: 2019-11-14
STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.
CVE-2019-18949
PUBLISHED: 2019-11-14
SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a chain of webpage redirections targeted to the user's browser configuration.
CVE-2011-1930
PUBLISHED: 2019-11-14
In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.
CVE-2011-1145
PUBLISHED: 2019-11-14
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
CVE-2011-1488
PUBLISHED: 2019-11-14
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon service by crashing the service via a sequence of repeated log messages sent withi...