Thursday, December 26, 2019

Well, OK, but what I meant there is that you look thru ALL of the data when you hunt.


Well, OK, but what I meant there is that you look thru ALL of the data when you hunt. Search, pivot, search, pivot, etc. I frankly still don’t see what specifically do you mean by “prioritization” in TH context. I use the word a lot in relation to alerts, but I still don’t see what needs to be prioritized in TH as you don’t know what you ultimately look for.


Originally published at Medium.

Wednesday, December 25, 2019

Yes, in my analyst days. My polite was of describing what I saw is: ehhh…I was unimpressed :-)


Yes, in my analyst days. My polite was of describing what I saw is: ehhh…I was unimpressed :-)


Originally published at Medium.

Sunday, December 22, 2019

Dude, this is the same as IDS or SIEM rules, no? Why reinvent the very basic concept…?


Dude, this is the same as IDS or SIEM rules, no? Why reinvent the very basic concept…?


Originally published at Medium.

I don’t at all see why this is true.


I don’t at all see why this is true. TH and IR need all the data you can get, while detection perhaps needs to run on culled data. And, if you by chance equate hunting and detection, then you suck :-)


Originally published at Medium.

Thank you very much for this comment.


Thank you very much for this comment. Indeed security space have figured it out in this area, independently. However the only alternative available to us is actually raw data with no useful metadata and no categorization. In essence when taxonomy approach died, people went back to raw data and stayed there…


Originally published at Medium.

Friday, December 20, 2019

Well, we need such a standard but so far the attempts to make one all failed.


Well, we need such a standard but so far the attempts to make one all failed. Can we have it? Maybe.


Originally published at Medium.

Wednesday, December 04, 2019

Hiring: Come Join Chronicle/GCP as Security Data Scientist (!)

OK, I never imagined I’d be writing such a blog post seriously. But here it is. Chronicle (as a central part of Google Cloud security…


OK, I never imagined I’d be writing such a blog post seriously. But here it is. Chronicle (as a central part of Google Cloud security unit) is in need of … yes, you read it right … some Security Data Scientists.

While we are integrating our systems for hiring, I am going to just leave it here, with a hiring manager email below (yes, he agreed) — please don’t abuse it :-) Note that the text below is written by the hiring team and only slightly edited by me.

But before I go any further:

Location: Sunnyvale, CA [Sorry, we really do mean it. Yes, Sunnyvale only. You will have to show up in the office at least some of the time. Please don’t argue with me about it!]

Job: Security Data Scientist

Intro: Chronicle (Google Cloud Enterprise Security) is advancing cybersecurity for enterprises of all sizes. We work with the entire security industry to give good the advantage in the fight against cybercrime. Joining other experts in large-scale cloud computing, big data, machine learning, and cybersecurity, our goal is to build out the next generation of security analytics solutions.

Data science and Machine Learning are a critical part of Chronicle’s product offering. At Chronicle we analyze large amounts of data to derive valuable insights for our customers.

Job responsibilities

  • Cleanse, analyze, and derive insights from massive data sets
  • Research, design, and develop innovative algorithms to solve a variety of statistical data analysis problems
  • Build predictive models and apply machine-learning algorithms to solve critical customer issues
  • Collaborate with engineering and product development teams to understand the needs of Chronicle and devise possible solutions
  • Implement analytical models into production by collaborating with software and machine learning engineers
  • Keep-up with the latest technological advancements in the area of machine learning

As a data scientist, you will apply your experience in data analysis to understand the various data sets. You will work on defining and championing new data science related projects that will have a big impact on our customers. This will require you to collaborate with various internal Chronicle teams (product, engineering, and sales) for defining, scoping, and executing on the projects. You will use your machine learning skills to build new models, demonstrate the effectiveness of the models on the data sets, and the impact on the customers.

The ideal candidate is someone who is comfortable operating in an organization that moves fast and someone who loves variety in their work. You are a self-starter and bring innovative approaches to problem solving, to develop and propose new ideas, and actively participate in improving the quality of our processes and product.

Minimum qualifications [must have these to be hired]:

  • Master’s degree in a quantitative discipline (e.g., Statistics, Operations Research, Bioinformatics, Economics, Computational Biology, Computer Science, Mathematics, Physics, Electrical Engineering, Industrial Engineering) or equivalent practical experience.
  • 2 years of work experience in data analysis related field.
  • Experience with statistical software (e.g., R, Python, MATLAB, pandas) and database languages (e.g. SQL)

Preferred qualifications [having as many of these specific qualifications is a plus, but transferable skills/experiences may be equally valuable]:

  • PhD in Statistics, Physics, Biostatistics, Industrial Engineering, Operations Research or other related quantitative areas
  • Strong skills in Python and/or R.
  • SQL preferred in addition to Python or R.
  • Solid foundation in probability, statistics, and algebra
  • Strong research publication record in top conferences and journals
  • Excellent communication and presentation skills

Please contact Ram via email to apply (it will eventually be posted to Careers site, but use this for now)


Originally published at Medium.

Dr Anton Chuvakin