This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Taking a Behavioral Approach to Security- How to Stay One Step Ahead of your Adversaries

Download resources

About this session

Jake McCabe, presales director at LogPoint, makes the case for adding behavioural detection to signature and IOC-based tooling. Indicators such as hashes and IP addresses catch known threats but grow without limit and are trivial for an adversary to change, as David Bianco's pyramid of pain illustrates; tactics, techniques and procedures sit at the top because attackers cannot easily alter how they operate. He presents MITRE ATT&CK as the encyclopedia of those behaviours, explains tactics versus techniques with defense-evasion examples such as base64 obfuscation and registry modification, and lists the benefits of mapping controls to the framework: coverage-gap assessment, a smaller analyst skills gap, a common language across tools and adversary emulation for purple teams. He then describes LogPoint's implementation, with more than 2,000 correlation rules tagged to ATT&CK, and its UEBA module, which baselines each user and entity with unsupervised machine learning, compares anomalies against peer groups to cut false positives, and feeds a per-entity risk score back into SIEM rules, for instance to alert only on file-sharing uploads by already suspicious users.

 Join LogPoint’s Jake McCabe and Christian Have as they discuss how thinking about security from the perspective of adversary behavior can help organizations better prepare for, detect, and respond to threats. 

  

Too often, security organizations focus on signatures and IOCs to alert them to threats in their environment, however this myopic focus can often leave them blind to the bigger picture-unable to ‘see the forest for the trees’.  By focusing instead on adversary behavior, security teams can make it more difficult for their adversaries to evade detection and they can even begin to predict where their adversaries might strike next. 

  

The MITRE ATT&CK framework is one tool organizations can use to help take a behavioral security posture.  The framework can help security teams assess risk, drive informed decisions, and help them to better understand how their adversaries typically behave.  

  

User and entity behavioral analytics (UEBA) provides another avenue by which security teams can take a behavioral approach to security.  UEBA complements and improves the fidelity of traditional signature-based detection methods to enable security teams to distinguish adversary behavior from normal behavior.  UEBA does so by looking for anomalies or changes in behavior and then analyzing sets of anomalies which together could be indicative of particular adversary techniques. 

  

Jake and Christian will discuss how these two approaches to behavioral security can be taken
together and how LogPoint can help organizations improve their security posture by helping them take a more behavioral-focused approach to security.  

Key takeaways

  • Rank your detections on the pyramid of pain: invest in TTP-level coverage, since hashes and IPs are the easiest indicators for attackers to swap.
  • Map existing alerts and controls to MITRE ATT&CK technique IDs to see where coverage is thin and to drive purchasing and engineering decisions.
  • Use the detection methods documented in ATT&CK (base64-encoding commands, registry edits) as ready-made hunting queries.
  • Baseline user and entity behaviour against peer groups, not just the individual, so first-time actions do not flood analysts with false positives.
  • Feed behavioural risk scores back into SIEM rules to raise the fidelity of grey-area alerts such as file-sharing site uploads.

Speakers

Jake McCabe
Jake McCabe
Presales Director · Logpoint Inc

Resources

Tags

More from GoSec 2020

Also from Jake McCabe

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.