cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40%...

38
Powering Prevention Lessons Learned from Building a Global Security Response Team Christopher Clark – Director, GSRT

Transcript of cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40%...

Page 1: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Powering  PreventionLessons  Learned  from  Building  a  Global  Security  Response  Team

Christopher  Clark – Director,  GSRT

Page 2: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Many  Brilliant  People,  Many  Small  SilosRapid  organic  growth  in  products  and  customers

Effort  duplication,  inconsistencies,  and  internal  focus

Page 3: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Connect  the  dots  and  deliver  holistic  preventionProactively  detect  and  respond  to  threat  evolutions

Develop  countermeasures,  reporting,  and  technical  solutions  

Page 4: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Faster,  Better,  and  Globally  ImpactfulDefine  Mission,  Build  Processes,  Hire  Team  and  Internalize  Response  in  <12  months

250m+   Attacks,  31k+  Customers,  10k+  Engagements,  600+  Threats  Identified

Page 5: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

AgendaBuilding  a  Global  Security  Response  Team

Stakeholder  Empowerment

Strategic  Hiring

Mission  over  Metrics

Communication  &  Collaboration

Page 6: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Research  &  Response

Automation,  Automation,  Automation!

Questions?

FINISH

Page 7: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Stakeholder  Empowerment

Page 8: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Proactively  Engage  Everyone

Seek  out,  Sit  down  (in  person),  and  LISTEN

Understand  the  current  reality  and  pain  points

Access  stakeholder  resources  and  capabilities

Plan  for  unknown  unknowns  (then  double  it!)

Page 9: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Education  is  the  MOST  important  jobSkip  the  details,  tell  the  story

Be  a  trusted  resource  and  teach  up,  down,  left  and  right

Page 10: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Know  the  “NO”  MonsterLeverage  expertise  to  prioritize  security  resource  expenditure  

Identify  fires  before  they  start  and  protect  the  team

Page 11: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Strategic  Hiring

Page 12: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Strategic  Talent  CaptureStart  at  the  core  and  identify  key  functional  areas

Acquire  and  empower  proven  leaders

Page 13: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Functional  Teams  with  Matrixed Deliverables

88

Vulnerability  and  Exploit  UnitProvide  Actionable  Vulnerability  and  Exploit  Intelligence.  Coverage  for  delivery  Methods  and  Hack  /  Post  Exploitation  tools.  

Tools  and  TechnologyDevelop  and  Enhance  Collection,  Analysis,  and  Detection  Capabilities,  as  well  as  DevOpssupport   for  existing  tools.  

Threat  Analysis  UnitFirst  line  of  triage,  Conducting  

Analysis  of  Adversaries,  Campaigns,   and  TTPs  

Malware   and  Countermeasures  UnitProvide  Actionable  Malcode  

Analysis  and  Deployable  Countermeasures

!"

#$

Page 14: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Security  Operations

Malware  Analysis

Scripting  and  Development

Penetration  Testing

Identify  and  Ensure  Critical  Skillsets  Improved  communication  and  operational  efficacy

Eliminate  single  points  of  failureCareer  progression  and  cross  training

Page 15: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Team  Member  Critical Skillset  Continuum

Threat  Researcher

Security  Operations80%

Malware  Analysis50%

Scripting  &  Development40%

Malware  Researcher Vulnerability  and  Exploit  Researcher

Automation  Engineer

Penetration  Testing40%

Security  Operations40%

Malware  Analysis80%

Scripting  &  Development40%

Penetration  Testing20%

Security  Operations50%

Malware  Analysis40%

Scripting  &  Development40%

Penetration  Testing80%

Security  Operations30%

Malware  Analysis30%

Scripting  &  Development90%

Penetration  Testing30%

Page 16: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Regional  Threat  ExpertiseCultural  and  Linguistic  Knowledge

Improved  Response  Speed  and  Quality

Page 17: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Mission  over  Metrics

Page 18: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Metrics  are  an  indicator,  not  the  goal  Progress  is  achieved  through  failure

Culture  is  the  key

Page 19: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

PASSION:  believe  in  the  mission  and  what  you  can  do

Page 20: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

CAPACITY:  learn.  share.  ask  for  help

Page 21: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

INNOVATION:  rules  are  a  finite  construct

Page 22: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

AGILITY:  change  is  constant,  be  multi-­‐disciplinary

Page 23: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

HUMILITY:  ego-­‐less  execution

-­‐ Bryson  Bort,  CEO

Page 24: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Communication  & Collaboration

Page 25: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Great  Communication  is  required  for  Great  Security  “Remote  by  default”  ensures  expansion,  flexibility,   and  data  retention

Trust  is  formed  in  person  and  grows  through  transparency

Page 26: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Remove  (or  Connect)  Data  and  Operational  SilosNormalize  processes  and  remove  effort  duplicationTransparent  and  accessible  data  and  deliverables

Page 27: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Vertical  and  Horizontal  Status  Reports  Deliver  regular  status  reports  on  both  research  and  response  goals

Ensure  broad  delivery  to  all  team  members  and  stakeholders

Page 28: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Research  &  Response

Page 29: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Encourage  Research  and  Response  from  All  Diversity  of  experience  drives  new  approaches

Innovation  is  born  from  operations

Page 30: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Research  and  Response  Mix

80%

20%

Response Research

60%

40%

Response Research

40%

60%

Response Research

20%

80%

Response Research

Junior  Researcher Researcher Senior  Researcher Principal  Researcher

Page 31: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Response  must  be  efficient,  Research  must  be  impactfulPublications  (Reports  or  Code),  Presentations,  or  Products

Page 32: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Security  Innovation  is Distilled  Threat  IntelligencePrevention  is  driven  by  heuristics  refined  through  researchTargeted  research  is  made  possible  by  intelligent  response

Page 33: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Automation,  Automation,  Automation!

Page 34: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Automation  is  critical  to  efficacy  and  scalePOC  by  researchers,  maturation  and  upkeep  by  automation  engineers

“Do  it  three  times?  Automate  it!”  

Page 35: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Enable  and  Liberate  ResearchersCentralize  response  tool  stack  and  maximize  data  density

Ensure  complete  auditable  transparency  

Page 36: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Develop  Integrations  and  Orchestration

!

Connecting  existing  detection,  analysis,  workflow  and  collaboration  platforms  

Page 37: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

Powering  Prevention  -­‐ ReviewBuilding  a  Global  Security  Response  Team

Stakeholder  EnablementActively  engage   with  all  stakeholders,   understand   their  needs.   Educate  non-­‐security  teams,  and  protect  your  resources.  

Strategic  HiringIdentify   required   talent  and  proactively  recruit  it.  Ensure  all  team  members  possess   key  skills.  

Mission  Over  MetricsCulture   is   the  most  important  part  of  the  team,  never  compromise  on  fit  and  ensure  Metrics  are  a  guide  not  a  target.

Communication  &  CollaborationLeverage   technology  to  expand  coverage,  improve  efficacy,  and  reduce  effort  duplication.

Research  &  ResponseEnsure  staff  is   focused  on  short  and   long  term  research  projects  

as  well  as  operational  triage.

Automation!Dedicate   resources   to  automating  processes   and   tools  once  they  have  been  proven.  

Page 38: cclark first keynote · Automation, Engineer Penetration)Testing 40% Security)Operations 40% Malware)Analysis 80% Scripting)&)Development 40% Penetration)Testing 20% Security)Operations

[email protected]

https://www.linkedin.com/in/cybersec