Dr Anton Chuvakin Blog (Original)

Security writing since the mid-2000s. New posts are mirrored from Anton on Security on Medium.

Do You Want “Security Analytics” Or Do You Just Hate Your SIEM?

Historical Archive Note: This post was originally published on the Gartner Blog Network on January 26, 2015 by Anton Chuvakin.
Original URL: https://blogs.gartner.com/anton-chuvakin/2015/01/26/do-you-want-security-analytics-or-do-you-just-hate-your-siem | Archive.org Snapshot

Now that I’ve taken a fair number of “security analytics” client inquiries (with wildly different meanings of the phase), I can share one emerging pattern: a lot of this newly-found “analytics love” is really old “SIEM hatred” in disguise.

A 101% fictional and slightly over-dramatized conversation goes like this:

  • Analyst: you said you wanted security analytics, what specifically do you want?
  • Enterprise: I want to collect logs and some other data, correlate, analyze, report.
  • Analyst: wait a second … that is called “SIEM”, SIEM does that!
  • Enterprise, passive-aggressively: Well, ours doesn’t!!!
  • Analyst: have you tried to .. you know… actually use it?
  • Enterprise: as a matter of fact, we did – for 5 years! Got anything else to ask?!

Upon some analysis, what emerges is a real problem that consists of the following:

  1. Lack of resources to write good correlation rules, tune them, refine them and adapt them to changing needs
  2. A degree of disappointment with out-of-the-box rules (whether traditional or baseline-based) and other SIEM content
  3. Lack of ability to integrate some of the more useful types of context data (such as IdM/IAM roles and user entitlements, as well as deeper asset data)
  4. Lack of trust that even well-written rules will let them detect attacker lateral moves, use of stolen/decrypted credentials, prep for data exfil, creating backdoors, etc
  5. Occasionally, a lack of desire to understand a multitude of their own monitoring use cases, but instead to buy a box for each problem.

So, a few years of such SIEM unhappiness have born a result … UBA. Some vendors’ UBAs are “SIEM add-ons” (since their rely on SIEM for collection, normalization and storage), others are more like a “narrower but smarter SIEM” (since their collect a subset of SIEM logs and maybe other data).

A few can work with DLP and not just a SIEM (as we all know, tuning DLP is often – imagine that! – a bigger pain than tuning a SIEM) in order to create additional insight from SIEM and DLP outputs. As I hypothesize, UBA is where a broader-scope security analytics tooling may eventually emerge.

Now, do you need/want analytics or do you just hate your SIEM?

Blog posts on the security analytics topic: