Showing posts with label philosophy. Show all posts
Showing posts with label philosophy. Show all posts

Tuesday, July 01, 2014

Anton Chuvakin

by Anton Chuvakin  |  July 30, 2014  |  4 Comments

SIEM technology has evolved to a point where conflicting requirements are starting to tear it apart – and I am not the only one to observe that. See here: Just as at its birth in the late 1990s, today’s SIEM must excel at real-time analysis using rule-based correlation and other methods and analyze thousands of […]

Category: analytics monitoring security SIEM     Tags:

by Anton Chuvakin  |  July 24, 2014  |  5 Comments

A long time ago, in a galaxy far far away … at the very dawn of my security career I attended a presentation by somebody who is now a notable incident response expert. Well … who am I kidding? He was a notable IR expert back in 2000, way…way before IR was cool and way […]

Category: analytics security SIEM     Tags:

by Anton Chuvakin  |  July 22, 2014  |  4 Comments

Another new document on SIEM that I wrote just published: Blueprint for Designing a SIEM Deployment. “Planning a distributed enterprise SIEM deployment is challenging for information security teams at many organizations. This Blueprint shows the architecture and timeline for an enterprise security information and event management deployment and highlights key tasks for each stage. “ […]

Category: announcement security SIEM     Tags:

by Anton Chuvakin  |  July 17, 2014  |  3 Comments

“Hello, I am your anti-virus program. Which specific viruses would you like me to kill today? Enter names here: [……..]” While I don’t recall the exact state of the art of anti-virus back in the late 1980s, I do not remember any anti-virus program ever asking such a question. The technology originated in response to […]

Category: philosophy security SIEM     Tags:

by Anton Chuvakin  |  July 14, 2014  |  11 Comments

During my original SIEM architecture and operational practices research (see the paper here and a presentation here), I looked at the topic of SIEM operation maturity. Organizations that purchase and deploy SIEM technologies are at different stages of their IT and information security maturity (such as when measured by Gartner ITScore for Security). Certain security […]

Category: monitoring security SIEM     Tags:

by Anton Chuvakin  |  July 8, 2014  |  15 Comments

So, occasionally I get this call from somebody (vendor, end-user, investor, etc) inquiring about “the size of the security analytics market.” They are usually shocked at our answer: since there is no such market, there is no size to report. If you recall, we [as well as myself] don’t really believe there is such a […]

Category: analytics philosophy security     Tags:

by Anton Chuvakin  |  July 2, 2014  |  4 Comments

It is with tremendous excitement that I am announcing the publication of my “Evaluation Criteria for Security Information and Event Management” document and SIEM selection tool (download link inside the document). Love the “Magic Quadrant for Security Information and Event Management” and “Critical Capabilities for Security Information and Event Management” but want more details? [and […]

Category: announcement security SIEM     Tags:

by Anton Chuvakin  |  July 1, 2014  |  1 Comment

Most popular blog posts from my Gartner blog during the past month were: SIEM Magic Quadrant 2014 Is Out! (announcements) SIEM Analytics Histories and Lessons (SIEM research) On SIEM Tool and Operation Metrics (SIEM research) Detailed SIEM Use Case Example (SIEM research) Popular SIEM Starter Use Cases (SIEM research) Security Essentials? Basics? Fundamentals? Bare Minimum? […]

Discover what 12,000
CIOs
and Senior IT leaders
already know.

Comments or opinions expressed on this blog are those of the individual contributors only, and do not necessarily represent the views of Gartner, Inc. or its management. Readers may copy and redistribute blog postings on other blogs, or otherwise for private, non-commercial or journalistic purposes, with attribution to Gartner. This content may not be used for any other purposes in any other formats or media. The content on this blog is provided on an "as-is" basis. Gartner shall not be liable for any damages whatsoever arising out of the content or use of this blog.

© 2015 Gartner, Inc and/or its affiliates. All rights reserved.

Anton Chuvakin

by Anton Chuvakin  |  July 30, 2014  |  4 Comments

SIEM technology has evolved to a point where conflicting requirements are starting to tear it apart – and I am not the only one to observe that. See here: Just as at its birth in the late 1990s, today’s SIEM must excel at real-time analysis using rule-based correlation and other methods and analyze thousands of […]

Category: analytics monitoring security SIEM     Tags:

by Anton Chuvakin  |  July 24, 2014  |  5 Comments

A long time ago, in a galaxy far far away … at the very dawn of my security career I attended a presentation by somebody who is now a notable incident response expert. Well … who am I kidding? He was a notable IR expert back in 2000, way…way before IR was cool and way […]

Category: analytics security SIEM     Tags:

by Anton Chuvakin  |  July 22, 2014  |  4 Comments

Another new document on SIEM that I wrote just published: Blueprint for Designing a SIEM Deployment. “Planning a distributed enterprise SIEM deployment is challenging for information security teams at many organizations. This Blueprint shows the architecture and timeline for an enterprise security information and event management deployment and highlights key tasks for each stage. “ […]

Category: announcement security SIEM     Tags:

by Anton Chuvakin  |  July 17, 2014  |  3 Comments

“Hello, I am your anti-virus program. Which specific viruses would you like me to kill today? Enter names here: [……..]” While I don’t recall the exact state of the art of anti-virus back in the late 1980s, I do not remember any anti-virus program ever asking such a question. The technology originated in response to […]

Category: philosophy security SIEM     Tags:

by Anton Chuvakin  |  July 14, 2014  |  11 Comments

During my original SIEM architecture and operational practices research (see the paper here and a presentation here), I looked at the topic of SIEM operation maturity. Organizations that purchase and deploy SIEM technologies are at different stages of their IT and information security maturity (such as when measured by Gartner ITScore for Security). Certain security […]

Category: monitoring security SIEM     Tags:

by Anton Chuvakin  |  July 8, 2014  |  15 Comments

So, occasionally I get this call from somebody (vendor, end-user, investor, etc) inquiring about “the size of the security analytics market.” They are usually shocked at our answer: since there is no such market, there is no size to report. If you recall, we [as well as myself] don’t really believe there is such a […]

Category: analytics philosophy security     Tags:

by Anton Chuvakin  |  July 2, 2014  |  4 Comments

It is with tremendous excitement that I am announcing the publication of my “Evaluation Criteria for Security Information and Event Management” document and SIEM selection tool (download link inside the document). Love the “Magic Quadrant for Security Information and Event Management” and “Critical Capabilities for Security Information and Event Management” but want more details? [and […]

Category: announcement security SIEM     Tags:

by Anton Chuvakin  |  July 1, 2014  |  1 Comment

Most popular blog posts from my Gartner blog during the past month were: SIEM Magic Quadrant 2014 Is Out! (announcements) SIEM Analytics Histories and Lessons (SIEM research) On SIEM Tool and Operation Metrics (SIEM research) Detailed SIEM Use Case Example (SIEM research) Popular SIEM Starter Use Cases (SIEM research) Security Essentials? Basics? Fundamentals? Bare Minimum? […]

Discover what 12,000
CIOs
and Senior IT leaders
already know.

Comments or opinions expressed on this blog are those of the individual contributors only, and do not necessarily represent the views of Gartner, Inc. or its management. Readers may copy and redistribute blog postings on other blogs, or otherwise for private, non-commercial or journalistic purposes, with attribution to Gartner. This content may not be used for any other purposes in any other formats or media. The content on this blog is provided on an "as-is" basis. Gartner shall not be liable for any damages whatsoever arising out of the content or use of this blog.

© 2015 Gartner, Inc and/or its affiliates. All rights reserved.

Friday, April 12, 2013

Gartner Blog Network


Bye-bye, Compliance Thinking. Welcome, Military Thinking!

by Anton Chuvakin  |  April 12, 2013  |  1 Comment

While listening to the keynote by Vice Admiral Gerald Beaman at a recent SINET ITSEF event, the following occurred to me: now in 2013, all the “hottest” security thinking has military roots … again.  Kill chain, defense, intelligence, adversary, TTPs, campaigns, engaging [the adversary], even the whole cyber thing all have roots in either DoD, DIB or surrounding area.

Here are a few more examples observed recently:

  • Incident response practices are moving away from automatic “find badness – flatten the box” and (in some cases!) started to include deception (such as honeypot redirection, much discussed for a decade, but done VERY rarely – until now) and attacker observation in live production environments [please recover from your shock quickly Smile] To fight the adversary, you need to know what they are likely to do next, and not just “make them go away” for now. Winning the battle [at this one PC] is not winning the war.
  • Goals of some security programs have shifted to mission resilience/survivability as opposed to control compliance and pondering “are we secure?” [I totally get that this is old news for The Enlightened Few aka “security-haves” – the point is not that there is this dude who can now say “I told ya so”, but that is actually happening!] This change has obvious military roots, IMHO, as few wars were won because all tanks had proper maintenance done …
  • Focus on the threats, long predicted by some people and dismissed by the majority, is slowly replacing the view that “we can do nothing about the threats, lets focus on vulnerabilities.” If threats are assumed to be persistent, doing something about them becomes an unavoidable priority since one can not fix all the vulnerabilities, all the time. Obviously, there was no age in history when the military ONLY perfected armor and ignored the gun (spear, bow, missile, laser, malware, whatever)

In the same speech, it was also quite interesting to observe the admiral take a very long-term view of information security and put some of its current security challenges in the context of a technological gap ( = US has less people to field a military than some other countries, thus it must maintain a technology advantage). Quite a few of other organizations can benefit from the same focus on the mission [=business] and its survival.  BTW, here is a fun fact: this excellent paper [PDF] treats “a zero-day wielding professional attacker” as … threat Tier 3 of 6. Who is Tier 6? Well, read the paper Smile

On top of this, I recently noticed the following a phenomenon, a few times already: Google for “site:new_security_vendor.com compliance” and see NO RESULTS. Despite that, “compliance is not dead” and a long list of security basics needs to be executed first – and executed well! However, the cutting edge is most definitely no longer anywhere near compliance …

P.S. Yes, this post is a bit of a rant or an incomplete thought. Well, that is why it is tagged philosophy

Additional Resources

Category: philosophy  security  

Tags: security  

Anton Chuvakin
Research VP and Distinguished Analyst
8 years with Gartner
19 years IT industry

Anton Chuvakin is a Research VP and Distinguished Analyst at Gartner's GTP Security and Risk Management group. Before Mr. Chuvakin joined Gartner, his job responsibilities included security product management, evangelist… Read Full Bio


Comments or opinions expressed on this blog are those of the individual contributors only, and do not necessarily represent the views of Gartner, Inc. or its management. Readers may copy and redistribute blog postings on other blogs, or otherwise for private, non-commercial or journalistic purposes, with attribution to Gartner. This content may not be used for any other purposes in any other formats or media. The content on this blog is provided on an "as-is" basis. Gartner shall not be liable for any damages whatsoever arising out of the content or use of this blog.

Gartner Blog Network


Bye-bye, Compliance Thinking. Welcome, Military Thinking!

by Anton Chuvakin  |  April 12, 2013  |  1 Comment

While listening to the keynote by Vice Admiral Gerald Beaman at a recent SINET ITSEF event, the following occurred to me: now in 2013, all the “hottest” security thinking has military roots … again.  Kill chain, defense, intelligence, adversary, TTPs, campaigns, engaging [the adversary], even the whole cyber thing all have roots in either DoD, DIB or surrounding area.

Here are a few more examples observed recently:

  • Incident response practices are moving away from automatic “find badness – flatten the box” and (in some cases!) started to include deception (such as honeypot redirection, much discussed for a decade, but done VERY rarely – until now) and attacker observation in live production environments [please recover from your shock quickly Smile] To fight the adversary, you need to know what they are likely to do next, and not just “make them go away” for now. Winning the battle [at this one PC] is not winning the war.
  • Goals of some security programs have shifted to mission resilience/survivability as opposed to control compliance and pondering “are we secure?” [I totally get that this is old news for The Enlightened Few aka “security-haves” – the point is not that there is this dude who can now say “I told ya so”, but that is actually happening!] This change has obvious military roots, IMHO, as few wars were won because all tanks had proper maintenance done …
  • Focus on the threats, long predicted by some people and dismissed by the majority, is slowly replacing the view that “we can do nothing about the threats, lets focus on vulnerabilities.” If threats are assumed to be persistent, doing something about them becomes an unavoidable priority since one can not fix all the vulnerabilities, all the time. Obviously, there was no age in history when the military ONLY perfected armor and ignored the gun (spear, bow, missile, laser, malware, whatever)

In the same speech, it was also quite interesting to observe the admiral take a very long-term view of information security and put some of its current security challenges in the context of a technological gap ( = US has less people to field a military than some other countries, thus it must maintain a technology advantage). Quite a few of other organizations can benefit from the same focus on the mission [=business] and its survival.  BTW, here is a fun fact: this excellent paper [PDF] treats “a zero-day wielding professional attacker” as … threat Tier 3 of 6. Who is Tier 6? Well, read the paper Smile

On top of this, I recently noticed the following a phenomenon, a few times already: Google for “site:new_security_vendor.com compliance” and see NO RESULTS. Despite that, “compliance is not dead” and a long list of security basics needs to be executed first – and executed well! However, the cutting edge is most definitely no longer anywhere near compliance …

P.S. Yes, this post is a bit of a rant or an incomplete thought. Well, that is why it is tagged philosophy

Additional Resources

Category: philosophy  security  

Tags: security  

Anton Chuvakin
Research VP and Distinguished Analyst
8 years with Gartner
19 years IT industry

Anton Chuvakin is a Research VP and Distinguished Analyst at Gartner's GTP Security and Risk Management group. Before Mr. Chuvakin joined Gartner, his job responsibilities included security product management, evangelist… Read Full Bio


Comments or opinions expressed on this blog are those of the individual contributors only, and do not necessarily represent the views of Gartner, Inc. or its management. Readers may copy and redistribute blog postings on other blogs, or otherwise for private, non-commercial or journalistic purposes, with attribution to Gartner. This content may not be used for any other purposes in any other formats or media. The content on this blog is provided on an "as-is" basis. Gartner shall not be liable for any damages whatsoever arising out of the content or use of this blog.

Gartner Blog Network


Bye-bye, Compliance Thinking. Welcome, Military Thinking!

by Anton Chuvakin  |  April 12, 2013  |  1 Comment

While listening to the keynote by Vice Admiral Gerald Beaman at a recent SINET ITSEF event, the following occurred to me: now in 2013, all the “hottest” security thinking has military roots … again.  Kill chain, defense, intelligence, adversary, TTPs, campaigns, engaging [the adversary], even the whole cyber thing all have roots in either DoD, DIB or surrounding area.

Here are a few more examples observed recently:

  • Incident response practices are moving away from automatic “find badness – flatten the box” and (in some cases!) started to include deception (such as honeypot redirection, much discussed for a decade, but done VERY rarely – until now) and attacker observation in live production environments [please recover from your shock quickly Smile] To fight the adversary, you need to know what they are likely to do next, and not just “make them go away” for now. Winning the battle [at this one PC] is not winning the war.
  • Goals of some security programs have shifted to mission resilience/survivability as opposed to control compliance and pondering “are we secure?” [I totally get that this is old news for The Enlightened Few aka “security-haves” – the point is not that there is this dude who can now say “I told ya so”, but that is actually happening!] This change has obvious military roots, IMHO, as few wars were won because all tanks had proper maintenance done …
  • Focus on the threats, long predicted by some people and dismissed by the majority, is slowly replacing the view that “we can do nothing about the threats, lets focus on vulnerabilities.” If threats are assumed to be persistent, doing something about them becomes an unavoidable priority since one can not fix all the vulnerabilities, all the time. Obviously, there was no age in history when the military ONLY perfected armor and ignored the gun (spear, bow, missile, laser, malware, whatever)

In the same speech, it was also quite interesting to observe the admiral take a very long-term view of information security and put some of its current security challenges in the context of a technological gap ( = US has less people to field a military than some other countries, thus it must maintain a technology advantage). Quite a few of other organizations can benefit from the same focus on the mission [=business] and its survival.  BTW, here is a fun fact: this excellent paper [PDF] treats “a zero-day wielding professional attacker” as … threat Tier 3 of 6. Who is Tier 6? Well, read the paper Smile

On top of this, I recently noticed the following a phenomenon, a few times already: Google for “site:new_security_vendor.com compliance” and see NO RESULTS. Despite that, “compliance is not dead” and a long list of security basics needs to be executed first – and executed well! However, the cutting edge is most definitely no longer anywhere near compliance …

P.S. Yes, this post is a bit of a rant or an incomplete thought. Well, that is why it is tagged philosophy

Additional Resources

Category: philosophy  security  

Tags: security  

Anton Chuvakin
Research VP and Distinguished Analyst
8 years with Gartner
19 years IT industry

Anton Chuvakin is a Research VP and Distinguished Analyst at Gartner's GTP Security and Risk Management group. Before Mr. Chuvakin joined Gartner, his job responsibilities included security product management, evangelist… Read Full Bio


Comments or opinions expressed on this blog are those of the individual contributors only, and do not necessarily represent the views of Gartner, Inc. or its management. Readers may copy and redistribute blog postings on other blogs, or otherwise for private, non-commercial or journalistic purposes, with attribution to Gartner. This content may not be used for any other purposes in any other formats or media. The content on this blog is provided on an "as-is" basis. Gartner shall not be liable for any damages whatsoever arising out of the content or use of this blog.

Dr Anton Chuvakin