{"id":3187,"date":"2024-04-19T12:28:56","date_gmt":"2024-04-19T17:28:56","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-analytics\/rethinking-how-you-work-with-detection-response-metrics"},"modified":"2024-04-19T12:28:56","modified_gmt":"2024-04-19T17:28:56","slug":"rethinking-how-you-work-with-detection-and-response-metrics","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/04\/19\/rethinking-how-you-work-with-detection-and-response-metrics\/","title":{"rendered":"Rethinking How You Work With Detection and Response Metrics"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltf28e35efb396525c\/6622a98c98cc9915e9b708f4\/Metrics_Dzmitry_Skazau_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/rethinking-how-you-work-with-detection-and-response-metrics.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/rethinking-how-you-work-with-detection-and-response-metrics.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">BLACK HAT ASIA \u2013 Singapore \u2013<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> Sorting the false positives from the true positives: Ask any security operations center (SOC) professional, and they&#8217;ll tell you it&#8217;s one of the most challenging aspects of developing a detection and response program.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As the volume of threats continues to rise, having an effective approach to measuring and analyzing this kind of performance data&nbsp;has become more critical to an organization&#8217;s detection and response program. On Friday at the&nbsp;Black Hat Asia&nbsp;conference in&nbsp;Singapore, Allyn Stott, senior staff engineer with Airbnb, encouraged security professional &nbsp;to&nbsp;reconsider how they use such metrics&nbsp;in their detection and response programs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Stott broached the topic at&nbsp;last year&#8217;s <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/detection-response-that-scales-a-4-pronged-approach\" rel=\"noopener\">Black Hat Europe<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, where&nbsp;he explained how to create a detection and response framework. &#8220;At the end of that talk, a lot of the feedback I received was, &#8216;This is great, but we really want to know how we can get better at metrics,'&#8221; Stott says. &#8220;That&#8217;s an area where I&#8217;ve seen a lot of struggles.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Importance of Metrics\">The Importance of Metrics<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Stott says that metrics are critical in assessing the effectiveness of a detection and response program because they drive improvement. Providing quality metrics is an essential step in the detection and response process, he adds, because it will reduce the impact of threats and validate investments in detection and response programs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Stott says metrics also enable security managers to demonstrate how detection and response lowers risk to the business. &#8220;Metrics help us communicate what we do and why people should care. That&#8217;s especially important in detection and&nbsp;response&nbsp;because it&#8217;s very difficult to understand from a business perspective.\u201d<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The most critical area for delivering effective metrics is alert volume. &#8220;Every security operations center I&#8217;ve ever worked in or ever walked foot in, it&#8217;s their primary metric,&#8221; Stott says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He emphasizes that knowing how many alerts are coming in is&nbsp;important, but that in itself is still not enough. \u201cThe question is always, &#8216;How many alerts are we seeing?'&#8221; Stott says. &#8220;And that doesn&#8217;t tell you anything. I mean, it tells you how many alerts the organization receives. But it doesn&#8217;t&nbsp;actually&nbsp;tell you if your detection and response program is catching more things.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He warns that effectively utilizing metrics can be complex and labor-intensive, adding to the challenge of effectively measuring threat data. Stott acknowledges he has made his share of mistakes when it comes to engineering metrics to assess the effectiveness of security operations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As an engineer, Stott routinely evaluates the effectiveness of the searches he conducts and the tools he uses, seeking to get an accurate true- and false-positive rates for detected threats. The challenge for him and most security professionals is connecting that information to the business.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Implementing Frameworks&nbsp;Properly&nbsp;Is Critical&nbsp;\">Implementing Frameworks&nbsp;Properly&nbsp;Is Critical&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One of his biggest mistakes was his approach to focusing too much on the&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/cisa-mitre-look-to-takeattack-framework-out-of-the-weeds\" rel=\"noopener\">MITRE ATT&amp;CK framework<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. While Stott believes it provides critical details on threat actors&#8217; different threat techniques and activities and says organizations should use it, that doesn&#8217;t mean they should apply it to everything.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Every technique can have 10, 15, 20, or 100 different variations,&#8221; he says. &#8220;And so&nbsp;having 100% coverage is kind of a crazy endeavor.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Besides using MITRE ATT&amp;CK, Stott recommends using the SANS Institute&#8217;s&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.sans.org\/tools\/hunting-maturity-model\/\" rel=\"noopener\">Hunting Maturity Model (HMM)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which helps describe an organization&#8217;s existing threat-hunting capability and a blueprint for improving it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It gives you the ability to, as a metric, say where you&#8217;re at as far as your maturity today and how the investments you&#8217;re planning to make or the projects you\u2019re planning to do will increase your maturity,&#8221; Stott says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He also recommends using the Security Institute&#8217;s&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/security-institute.org\/sabre-about\/\" rel=\"noopener\">SABRE framework<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which provides risk management and security performance metrics validated with third-party certification. &#8220;Rather than test across all of the MITRE ATT&amp;CK framework, you&#8217;re&nbsp;actually&nbsp;working on a prioritized list of techniques, which includes using MITRE ATT&amp;CK as a tool,&#8221; he says. &#8220;That way, you&#8217;re not just looking at your threat intel but also at security incidents and threats that would be critical risks for the organization.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Using these guidelines to provide useful metrics requires buy-in from CISOs, since it means gaining organizational adherence to these different maturity models. Nevertheless, it tends to be driven by a bottom-up approach, where threat intelligence engineers are the early drivers.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-analytics\/rethinking-how-you-work-with-detection-response-metrics\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>BLACK HAT ASIA \u2013 Singapore \u2013 Sorting the false positives<\/p>\n","protected":false},"author":12,"featured_media":3188,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3187","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/rethinking-how-you-work-with-detection-and-response-metrics.jpg?fit=1812%2C1063&ssl=1",1812,1063,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/rethinking-how-you-work-with-detection-and-response-metrics.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/rethinking-how-you-work-with-detection-and-response-metrics.jpg?fit=300%2C176&ssl=1",300,176,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/rethinking-how-you-work-with-detection-and-response-metrics.jpg?fit=640%2C376&ssl=1",640,376,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/rethinking-how-you-work-with-detection-and-response-metrics.jpg?fit=640%2C376&ssl=1",640,376,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/rethinking-how-you-work-with-detection-and-response-metrics.jpg?fit=1536%2C901&ssl=1",1536,901,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/rethinking-how-you-work-with-detection-and-response-metrics.jpg?fit=1812%2C1063&ssl=1",1812,1063,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/rethinking-how-you-work-with-detection-and-response-metrics.jpg?fit=1024%2C601&ssl=1",1024,601,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/rethinking-how-you-work-with-detection-and-response-metrics.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/rethinking-how-you-work-with-detection-and-response-metrics.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/rethinking-how-you-work-with-detection-and-response-metrics.jpg?fit=1812%2C1063&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3187","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3187"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3187\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3188"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3187"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3187"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3187"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}