Posted in

What Is Security Operations Center and How Can It Help Protect Your Business?

The business landscape is changing with the development of technologies such as mobile and cloud solutions, big data, and the Internet of Things. Cyber threats evolve along with new technologies. Attackers are using new methods to violate the confidentiality, integrity, and availability of information while avoiding detection, improving their tools, looking for ways to reduce costs and quickly monetize their efforts. The new paradigm stimulates digital transformation with its potential components – artificial intelligence, automation and others. This opens up new opportunities for business growth but also increases the number of vectors for various cyber attacks.

As per VPNBrains, all these factors require organizations to improve cyber resilience. One of its important elements is SecOps and Security Operations Center (SOC) as its component. SOC is a functional structure created to meet the needs of customers, both internal and external, by providing the necessary services, as well as information for analysis and making informed decisions about information security and risk management processes. We can say that SOC is the nervous system of the entire Information Security organism. It also turns out to be a link between Cyber Security and CyberResilience, becoming the center of information risks.

SOC weaknesses and ways to overcome them

A traditional SOC has certain systemic weaknesses, which can only be avoided by changing the structure and components of the incident management process. Here are the main weaknesses:

  • Proportionally growing noise in events (Alert Noise.)
  • The distributed landscape and the resulting poor transparency of hybrid networks.
  • A low level of automation leading to a potential shortage of personnel.

Other issues include increasing demand for SOC capacity, constant need to improve the quality of analytics, constant need to increase investments.

As the SOC matures and if there are relevant requests from the business, it can absorb the following functions:

  1. First of all, the use of automated solutions capable of analyzing large datasets and effectively identifying threats and attacks using new technologies. In this way, analysts can pay more attention to the human aspect of attacks and search for threats. The most sophisticated threats come from targeted attacks launched by APT groups that are technologically and process-ready to carry them out consistently without time or budget limits, in strict accordance with thoroughly developed methods.
  2. Developing new threat analysis processes to maintain situational awareness. Vulnerability scanning and patch management can be integrated and ready to make timely adjustments to the current risk landscape.
  3. Continuously updated information on cyber threats (CyberThreat Intelligence), obtained from external resources and containing data on current threat trends and indicators of compromise (IoC). Analyze data collected from CTI by automated tools before sending it to systems for further use. Next-generation SOCs have the potential to rely on artificial intelligence (AI) and machine learning (ML) to uncover actionable and relevant information.
  4. Automation of information security incident response processes and execution of scenarios for organizing the collection of evidence from various sources to increase productivity (compared to the time spent by analysts on manually resolving the same incidents).
  5. Leverage machine learning-based security tools to detect behavioral anomalies in networks and applications and identification of potential malicious activities, including data breaches (exfiltration) and malicious insiders.

Let’s now highlight the main steps towards SOC maturity that need to be performed and implemented across the entire SecOps area.

Step 1. Analyze network and infrastructure visibility

When constructing and further assessing the quality of the SOC, it is important to determine the appropriate visibility of the network and infrastructure. The effectiveness of threat detection by SOC units directly depends on the visibility of the network. If the detection logic and associated tools are not appropriately adapted to the network size and structure, it can lead to depletion of performance capabilities. The number of monitored infrastructure objects plays an important role in expanding the visibility of activities on the network. In addition to information about the number of events, the SOC gains access to network topology maps, which describe how various devices are connected, and to the asset map in general.

Step 2. Asset and vulnerability management

To be proactive, the SOC must be aware of the organization’s assets, including their importance. This assessment can be based on financial and operational risks. It is important to note here that without a regular assessment and analysis of risks in one form or another, with one or another degree of detail and effectiveness, it is impossible to obtain and update knowledge about the controlled infrastructure, current threats, and possible costs of applied countermeasures.

An important part of information security is vulnerability management. Given that the process of eliminating them and updating the software is quite laborious in terms of resources and time, it is advisable to adjust these priorities based on the criticality of the vulnerabilities found.

Step 3. Enrichment

There are a lot of directions for increasing the depth of event visibility of the SOC now. These include enriching events with XDR and other advanced practices and increasing network transparency by means of monitoring network anomalies (Network Behavior Anomaly Detection). To enrich information about incidents, various feeds are used provided by CyberThreat Intelligence platforms.

Step 4. Analysis and visualization

The growing amount of data is forcing SOC units to use automated tools. User and Entity Behavior Analytics solutions (UEBA) use machine learning algorithms and statistical analysis to look for biases in human actions. UEBA systems can detect internal threats and user accounts controlled by intruders. In addition, combining SIEM and UEBA can be beneficial as it allows a centralized decision point to be created.

Step 5. Processes and automation

SOC processes must be flexible and constantly evolve in response to new threats. They should be regularly optimized so that the SOC can handle incidents in a short time frame with increasing quality. To truly test the capabilities of the SOC unit, you might consider hiring a Red Team. Its function is to simulate a full-fledged cyberattack. The Red Team test is similar to a penetration test but is more extensive and covers all attack vectors. Rigorous testing helps to form a SOC unit and improve the quality of playbooks – incident response instructions describing the correct course of action for SOC analysts from the very beginning of incident detection.

Step 6. Analysts and team

While many tools help SOC units respond faster and provide better visibility, people are still the most important part of the SOC. Automating repetitive tasks does not diminish the value of analysts. At the same time, it is not always easy to motivate SOC employees. The work tasks of lower-level professionals are routine, which can lead to high turnover if there are no career prospects. A qualified SOC analyst should have extensive theoretical and practical knowledge of the overall IT infrastructure, including network devices, security devices, protocols, servers, operating systems, etc. In addition, analysts need to know the mechanics of control systems, event processing, as well as tactics, techniques, and procedures of adversaries (TTP). These skills can be obtained through penetration testing and red teaming.

Conclusion

As threats become more sophisticated and can escalate into large-scale incidents in a short time, the cyber defense must be introduced at all stages of the workflow and be built on a multi-layered principle. This obliges SOC units to become more agile and proactive. At the same time, they struggle with massive amounts of data and unmanaged workloads. Moving to better security requires maturing of SOC technologies and processes.

When creating a SOC, the organization must already have a solid security policy that it follows. The SOC can only complement the security program, not replace it. SOC units depend on existing security technologies to block common threats and collect data for further analysis. To improve the efficiency of their work, SOC employees must use new technologies, primarily with the aim of minimizing the number of recurring events that need to be analyzed manually, increasing the quality of event analysis and the speed of responding to incidents.

Alex Vakulov is a cybersecurity researcher with over 20 years of experience in malware analysis. Alex has strong malware removal skills. He is writing for numerous tech-related publications sharing his security experience.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.