{"id":56612,"date":"2023-01-17T11:00:32","date_gmt":"2023-01-17T09:00:32","guid":{"rendered":"https:\/\/www.cocus.com\/?p=56612"},"modified":"2024-06-04T16:59:29","modified_gmt":"2024-06-04T14:59:29","slug":"threat-detection-enterprise-security-siem","status":"publish","type":"post","link":"https:\/\/www.cocus.com\/en\/threat-detection-enterprise-security-siem\/","title":{"rendered":"Threat Detection 101: Corporate Security with Detection and Security Information &amp; Event Management (SIEM)"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"56612\" class=\"elementor elementor-56612 elementor-56394\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-64f56580 elementor-section-full_width elementor-section-height-default elementor-section-height-default lottie-bg-no\" data-id=\"64f56580\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;enable_lottie_background&quot;:&quot;no&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2226542f lottie-bg-no\" data-id=\"2226542f\" data-element_type=\"column\" data-e-type=\"column\" data-settings=\"{&quot;enable_lottie_background&quot;:&quot;no&quot;}\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-26c26fe elementor-widget elementor-widget-text-editor\" data-id=\"26c26fe\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\tThreat detection? What is it, who needs it and how do you implement it? \n<br><br>\nAttack detection is currently coming to the fore, especially for companies that are operators of critical infrastructures (KRITIS). With its amendment to the <a href=\"https:\/\/www.bsi.bund.de\/DE\/Themen\/KRITIS-und-regulierte-Unternehmen\/Kritische-Infrastrukturen\/Allgemeine-Infos-zu-KRITIS\/Rechtsgrundlagen\/rechtsgrundlagen_node.html\" target=\"_blank\" rel=\"noopener\">BSI Act<\/a> (BSIG) in December 2021, the German Federal Office for Information Security (BSI) obligated all companies with KRITIS to operate their own attack detection systems from May 1, 2023 at the latest. \n<br><br>\nBut attack detection is also becoming increasingly important for organizations without critical infrastructure. Malicious and targeted attacks are now both more advanced in execution (<a href=\"https:\/\/www.cocus.com\/en\/lockbit-apt-siem-protection-advanced-attacks\/\">example Lockbit &#8211; a recurring successful attacker<\/a>) and more severe in their mission-critical consequences.  Detection and Security Information &amp; Event Management (SIEM) are thus becoming important components of enterprise security, for any company regardless of size and type of infrastructure.\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1d8961b elementor-section-full_width elementor-section-height-default elementor-section-height-default lottie-bg-no\" data-id=\"1d8961b\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;enable_lottie_background&quot;:&quot;no&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c89cfa8 lottie-bg-no\" data-id=\"c89cfa8\" data-element_type=\"column\" data-e-type=\"column\" data-settings=\"{&quot;enable_lottie_background&quot;:&quot;no&quot;}\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2df6438 elementor-widget elementor-widget-heading\" data-id=\"2df6438\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Why preventive measures are no longer enough <\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-07b2930 elementor-widget elementor-widget-text-editor\" data-id=\"07b2930\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\tNowadays, topics such as cyber security, data protection and information security are indispensable in the corporate world. Precautions through security-by-design, various security tools such as anti-malware, firewalls or vulnerability scanners, as well as the establishment and operation of an information security management system remain necessary to avoid continuous damage from opportunistic hacker attacks. \n<br><br>\nHowever, the systems described are no longer sufficient on their own to guarantee corporate security. The reason for this is often a few individual gaps in the system that are exploited by hackers for <a href=\"https:\/\/www.cocus.com\/en\/cyberattacks-are-becoming-more-complex-the-attack-surface-larger\/\">initial access to the corporate network.<\/a>  The greatest weak point for an attack is the human being.\n<br><br>\nIf one imagines the security architecture of a company as a castle that has fully implemented all technical protection measures (for example, drawbridge, steel gates and a moat), one danger still remains: the population. Since each inhabitant of the castle has a password for access, there is a risk that the password may be inadvertently or even intentionally transmitted to attackers, or that the inhabitant himself may become the attacker. Once the castle has been penetrated, even the sturdiest drawbridge and the deepest moat no longer serve as protection.  \t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fd6753f elementor-widget elementor-widget-heading\" data-id=\"fd6753f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">The consequence for companies and the security industry<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2edf344 elementor-widget elementor-widget-text-editor\" data-id=\"2edf344\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\tApplied to the corporate world of today, this means that social engineering and phishing are a daily problem for all companies. In addition, the issue of insider attackers is also part of everyday life in German companies, i.e., employees who intentionally or unintentionally endanger information security. Many successful attacks are actually carried out with regular accounts, sometimes even with admin accounts.  \n<br><br>\nFrom here, attackers move around the network like a seemingly legitimate user, identifying and exploiting further vulnerabilities until they finally execute the actual malicious action. The goals of the attack can vary from encrypting important data, exfiltrating sensitive information, to sabotaging systems. \n<br><br>\nToday&#8217;s world is characterized by a constant arms race to see who can find and close the next security gap first, or exploit it. The term &#8220;arms race&#8221; also refers to the ongoing battle to see who can execute the next malware undetected or prevent it. Hundreds of thousands of malware variants are sighted every day, and yet there is still the risk of infection by malware that is not yet detected by endpoint protection.  \t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fc5032e elementor-widget elementor-widget-heading\" data-id=\"fc5032e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">BSIG: This will change for companies as of May 2023 <\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4eb1d62 elementor-widget elementor-widget-text-editor\" data-id=\"4eb1d62\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\tThe amendments to \u00a78a of the BSIG stipulate that operators of critical infrastructures regulated by the BSIG must implement attack detection systems by May 1, 2023. This implementation must in turn be externally validated and proven to the BSI no later than two years later. \n<br><br>\nThe BSIG only roughly specifies what this means in concrete terms: <em>&#8220;The systems used for attack detection must continuously and automatically record and evaluate suitable parameters and characteristics from ongoing operations. They should be able to continuously identify and prevent threats and provide appropriate remediation measures for incidents that have occurred.&#8221;<\/em>\n<br><br>\nFunctionally, such an attack detection system must essentially provide logging, log analysis and detection as well as an appropriate response. In essence, then, we are talking about SIEM systems. \t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e19e4a4 elementor-widget elementor-widget-heading\" data-id=\"e19e4a4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">How detection and SIEM systems contribute to attack detection <\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-32f259d elementor-widget elementor-widget-text-editor\" data-id=\"32f259d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The basic principle of attack detection is to identify anomalies or traces of attacks. Typically, modern SIEM systems are used for this purpose. A SIEM system aggregates, normalizes and analyzes data against known attack patterns and provides the results to Security Operations Center (SOC) analysts. The SOC analysts can trigger appropriate response processes based on the results. In some cases, these tasks can also be automated so that responses are faster and more efficient. Additionally, a SIEM system informs the relevant people about the current security status of the company. Some simple examples of such events are:      <\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-13e3dd3 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"13e3dd3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Unusual use of user accounts, e.g. in parallel from different computers or several locations or at unusual times of day <\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Detection of brute force attempts, where software is used to try to crack passwords in rapid succession of different character strings. <\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Detection of unusual network traffic, e.g. very many DNS requests or those with unusual payloads <\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">High number of firewall denies or drops due to internal hosts<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d756996 elementor-widget elementor-widget-text-editor\" data-id=\"d756996\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\tThese examples are simple and their monitoring should be part of the basic building block of an attack detection system. An effective SIEM also implements the detection of atomic indicators down to the process or packet level, using both proven frameworks such as Mitre Att@ck or the Cyber Kill Chain as well as current detection patterns from threat intelligence sources. \n<br><br>\nSuch detections do not necessarily have to represent an attack, but can result from errors or simply legitimate yet unusual usage scenarios. Therefore, these cases must be examined in detail. Modern SIEM systems provide important support for this: they correlate data from other log sources to such events or offer functions to obtain further information on such events. This enables the security analyst to decide more quickly and reliably whether an actual attack has occurred.   \t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-852899f elementor-widget elementor-widget-heading\" data-id=\"852899f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">We support you<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-17473fe elementor-widget elementor-widget-text-editor\" data-id=\"17473fe\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>By implementing a SIEM system, every company ensures that potential and also advanced attacks can be detected as quickly as possible. For KRITIS companies, these systems are the recommended option to comply with the legal regulation that will apply from 01.05.2023. COCUS AG supports companies in the introduction of SIEM systems, but also in the optimization of existing implementations or the migration and replacement of old SIEM systems with more modern ones.  <\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-18d69e0 elementor-section-boxed elementor-section-height-default elementor-section-height-default lottie-bg-no\" data-id=\"18d69e0\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;gradient&quot;,&quot;enable_lottie_background&quot;:&quot;no&quot;}\">\n\t\t\t\t\t\t\t<div class=\"elementor-background-overlay\"><\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-946d016 lottie-bg-no\" data-id=\"946d016\" data-element_type=\"column\" data-e-type=\"column\" data-settings=\"{&quot;enable_lottie_background&quot;:&quot;no&quot;}\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5ab595a elementor-widget elementor-widget-heading\" data-id=\"5ab595a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">We offer you full protection when it comes to the security of your business.<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8910068 elementor-align-center elementor-widget elementor-widget-button\" data-id=\"8910068\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.cocus.com\/en\/about-us\/contact\/\" element=\"blog-contact\" type=\"services\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Contact us<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Threat detection? What is it, who needs it and how do you implement it? Attack detection is currently coming to the fore, especially for companies that are operators of critical infrastructures (KRITIS). With its amendment to the BSI Act (BSIG) in December 2021, the German Federal Office for Information Security (BSI) obligated all companies with [&hellip;]<\/p>\n","protected":false},"author":24,"featured_media":56518,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[424,570],"tags":[586,426,518],"class_list":["post-56612","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-en","category-news-en","tag-automation-en","tag-cybersecurity-en","tag-siem-en"],"_links":{"self":[{"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/posts\/56612","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/users\/24"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/comments?post=56612"}],"version-history":[{"count":0,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/posts\/56612\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/media\/56518"}],"wp:attachment":[{"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/media?parent=56612"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/categories?post=56612"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/tags?post=56612"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}