Building a Security Operations Centre (SOC)
Pages
Page 10 of 14
Detection approaches
Having looked at the rationale behind choosing an approach, it is important to understand in more detail what each approach involves.
Commercial tool detection
The tools you can use to analyse logging data and identify potential security issues can be traditional detection technologies such as anti-malware tools and network intrusion detection systems. These could also be more advanced technologies, such as behavioural analytical tools utilising machine learning. Whatever their nature, these tools will typically generate alerts in response to detected security events, for human analysts to investigate.
These tools will have rulesets provided by the vendor and should be updated regularly. Some will be configurable, so they can ingest new rules or threat intelligence (TI) feeds. This is explored further on the Threat Intelligence page.
Custom detection use-cases
This refers to your SOC developing and maintaining a set of alert logic or alert rules that trigger, based on a detection use-case.
For example, you might want to know if there are files being emailed out of the business outside of working hours, or large sets of data being sent out of the company via SSH. These are the types of things that a typical monitoring platform will be able to detect, providing you configure the alert rules to do so.
The use-cases are there to detect behavioural indicators of potentially malicious events.
These are typically implemented in SIEM tools, automatically searching for matching logical patterns within your log sources. These alerts will be generated in near real time as the log information is collected and analysed (depending on technology used).
Staff are needed to build and maintain these alerts and their logic. Therefore this requires greater investment in people and their expertise than relying on commercial tools only. This shifts the focus of staff more towards building capability as opposed to simply maintaining the tools.
Data mining (or log analysis)
Data mining allows the use of more complex alert logic than developed alerts. This can be advantageous if you have larger amounts of data.
Data mining can be useful in a number of scenarios. For example, if an organisation did not have an alert or detection implemented for a specific type of attack, there is a risk that an attacker could have evaded detection and may be present on the IT estate.
By developing logic that detects abnormalities across a large data set - such as unauthorised outbound connections, high traffic volume, or random file transfers - you may find evidence of an otherwise undetected compromise.
Data mining, and the advanced logic it uses, are key in detecting systemic risks. An attack is rarely successful based on a single exploit or action. Instead, attackers often a combination of techniques. If you understand how attacks are successful, and the lifecycle of their implementation, you can develop complex logic to detect them.
The sequence of events an attack typically follows is often referred to as the kill chain. MITRE ATT&CK codified this sequence as 14 distinct tactics and Lockheed Martin created the Cyber Kill Chain ®, with 7 stages.
Threat hunting
Threat hunting is the proactive, iterative and human-centric identification of cyber threats that have evaded existing security controls. Simply put, threat hunting involves skilled analysts that have knowledge of attack techniques, hunting through data, in order to find evidence of a security breach.
The main benefit of threat hunting is that it can help discover “unknown attacks”. Because they are unknown, the SOC wouldn’t be able to develop a use-case, and from that, detect the activity.
As threat hunting is a human centric activity, it requires the highest investment in skilled staff.
The Home Office has produced a useful guide on threat hunting, the content of which is applicable to most organisations considering a threat hunting capability.


