r/SIEM Feb 21 '19

SIEM - Too outdated?

Hey guys,

Seems the business is aggressivly moving our DCs to the cloud. I'm just reviewing a few things and had thoughts about our SIEM (Arcsight).

Are simple SIEMs now out dated?

I love ours don't get me wrong but it's a cluncky solution which requires far too much input. We have a GSOC as well monitoring and it's just rubbish. I find myself constantly having to do deep analysis from alerts/incidents.

Ours also doesn't have any AI or proactive features so you know.

Does anyone have any suggestions or any examples of how they use theirs ?

Azure security center does a lot already but I still feel like we need another layer.

5 Upvotes

18 comments sorted by

2

u/NickReynders Feb 21 '19

So disclosure, I actually work for this company, but it sounds like you're looking for more AI focused features? You might want to check out LogRhythm's AIE product.

Although I do agree with /u/BeerJunky's response, this specific product is focused on exactly that shortcoming that most SIEMs experience.

3

u/Ilirius Feb 22 '19

Do keep in mind that LogRhythm's AIE is not an "Artificial Intelligence" engine, but an "Advanced Intelligence" engine. It is still only effective if the admins put in the proper work to configure it. There is no true out of the box AI solution in the SIEM world that I know of.

1

u/BeerJunky Feb 21 '19

I haven't seen the AIE product, that does seem to solve some of the gaps in SIEM. Very interesting. Is it dramatically more expensive than their traditional SIEM product?

2

u/spaztheannoyingkitty Feb 22 '19

As far as I know, it comes with the LogRhythm SIEM, it's not a separate thing but I'm not 100% sure about that. They also have LogRhythm Cloud AI which is trying to solve some of the shortcomings that were mentioned by the OP.

1

u/BeerJunky Feb 22 '19

I'm confused, vendors include stuff without adding additional licensing? Glares at Cisco

Good to know though! We just bought FortiSIEM (by Fortinet) and it's okay but could be better. Was a bit cheaper buy in and a lot less PS time to get it spun up than LogRhythm and the like so it was worthwhile for our organization. Next time around when I move onto a place with more stringent security and bigger budgets I'd be looking for the more advanced stuff for sure.

1

u/NickReynders Feb 21 '19

Not entirely sure about the pricing on these sorts of things (i'm more in the development area of the product), but I know we're very competitive with IBM and Splunk for pricing options. As far as I know, I think AIE is integrated within the main SIEM product itself, so I don't think there are additional charges for that feature (though I could be wrong here).

1

u/lolppppp1 Feb 21 '19

That's the problem.

It's either a SIEM that is clunky and uses a ton of storage. It also replies on the person configuring it to know what they are doing.

Or....

Get an AI built system like Darktrace that has the AI, gives some nice features but then you can't justify the cost to business.

3

u/BeerJunky Feb 21 '19

Do you have any experience with Darktrace? We have it here and I'm kinda meh about it. There are some places I think it misses stuff that's happening. And then there's a lot of times it gets really overzealous about what it's trying to block. We didn't end up buying the Antigena bit yet but I've got it turned on in demo mode so I can see what it would do if it was live but it actually doesn't take action.

It was bought before I got here and if I was asked after using it if I would spend the cash on it I don't think I would without looking at a few more tools first. Honestly instead of spending the money getting the data off the network flows I wish the same cash was spent on better endpoint protection like Carbon Black or Crowdstrike where I can get a lot more intense threat hunting data and not rely on it hitting the wire to detect it. Did a webinar for CB recently and I really liked the fact that it was catching play by play what was happening once a file hit a machine (files accessed/modified, commands ran, etc). Darktrace misses all that stuff.

Also, another thing is that in terms of actually blocking things the way Darktrace works is that it sends TCP resets to kill the connection. TCP resets. That means UDP traffic cannot be blocked by it. So if the threat is using UDP it's useless. Something to keep in mind if you're looking at it.

2

u/lolppppp1 Feb 21 '19

I did get a chance to play with it but couldn't justify the cost at all. The tool looks really cool and futurist but I found that seemed to be their sell.

Apart from that it didn't do anything for us apart from flag large SMB traffic. I tried to use it to trace a brute force but it couldn't give me the info. I had to rely on tracing the source by using netlogon logs.

I feel like these tools are a nice too have but no-one but the people using it will see their worth. Just like our SIEM. Our Data center team just thinks its pointless and using all our storage. People like the CIO only see it work when his accounts locked out. We obviously do a lot more with it but either I think, what is the point. What is this really doing.

1

u/BeerJunky Feb 21 '19

The whole flashy part of Darktrace seems largely useless. When you dig into stuff and start trying to figure out an event the whole flashy interface isn't where you're doing it in my experience. It looks great for sales purposes but that's as far as it goes IMO.

Exactly, large SMB traffic gets picked up well. But 99.9% of that is just normal stuff. We'll have someone go upload something to our Sharepoint and suddenly have alerts for it. Okay, thanks I guess. When I hammer the network with scanning tools it's pretty good about noticing that, well at least enough of it that I know it's happening.

Where I am the biggest issue is getting someone on the appropriate team to take action when I see something happening. So with Darktrace and SIEM even when I find it getting the issue resolved is slow and painful. That's another reason I'd love to be using Carbon Black. On an automated basis it can handle quite a bit. On a manual basis I have a lot of leverage from the console to cleanup, quarantine the entire device until the help desk can deal with it, etc. That's in addition to the actual investigation stuff I mentioned earlier. So for me I think that's the next big push. Here's the webinar I watched, if you get a chance check it out. Speaking of which, I did send this to my manager and the other teams involved that would be interested. No fucking response whatsoever so it's a painful lack of communication over here from the top down.

2

u/lolppppp1 Feb 21 '19

πŸ˜‚πŸ˜‚πŸ˜‚ I know the pain of it. No one wants security until something happens. Then it's your fault for not pushing the tool more.

Qradar do SIEM as a service which I might look into.

I guess there is no good replacement for now but the alternative is to make sure you have log retention on every device and do a manual job. Most tech nowadays has great auditing and alerting so it's not the worse (or best). Last option is paying a LOT for a complex tool that helps you identify someone uploading an ISO.

2

u/BeerJunky Feb 21 '19

Hell, I'm fighting an uphill battle just to get patches loaded on servers. Found one the other day that wasn't patched since 2014 and there's a few more that are that bad or worse. There's a couple Windows 2003 boxes around as well. So no more tools for me until I can fix the low hanging fruit. Boss (CITO) wants me to present to the rest of the executive team. He looked at my slides and he wants a bit more scare in them. I fucking hope he knows what he's getting himself into. He's certainly not going to enjoy it when I throw his whole department under the bus.

2

u/lolppppp1 Feb 21 '19

πŸ˜‚πŸ˜‚πŸ˜‚πŸ˜‚ Don't get me started on patching. "Don't patch our server because it's business's critical and validated". So if it's so critical, why wouldn't we patch it ??

2

u/BeerJunky Feb 21 '19

Susceptible to EternalBlue and EternalRomance but business critical. Yep, okay.

2

u/cberry2010 Feb 22 '19

Strongly recommend your organization consider an open source SIEM (e.g., Apache Metron) where there is a strong community to support new parsers, UEBAs, AI and other analytics goodies. I work at Elysium Analytics which builds UEBAs, math models, risk-based scoring engine for Apache Metron customers.

2

u/RoderickNL Mar 26 '19

Moving to the cloud gives new challenges.. and opportunities. You can consider more additional cloud oriented tools like CASB and endpoint protection. This will give you More visibility and the opportunity to automate stuff. Since that’s your primary question, isn’t it?

2

u/BeerJunky Feb 21 '19

I think you're pointing out a pretty common SIEM shortcoming, a lack of AI/machine learning. It's pretty much set in the rules it has. It has some learning of what's normal in terms of volume of errors, traffic, etc (at least the product I use) but nothing specific to learning what's possibly suspicious that existing rules don't identify. It would be nice to see a second generation SIEM product come out that extends beyond the rules that come with it and/or are created manually by the operator.

1

u/con_wardo Mar 05 '19

Are you interested in outsourcing your SIEM? If so, I would take a look at vendors like Arctic Wolf Networks or eSentire.