Security Analytics and Zero Trust - How Do We Tackle That?

Presented at DeepSec 2019 „Internet of Facts and Fears“, Unknown date/time (Unknown duration)

With the current trends towards zero trust networks, deployment of billions of IoT devices, interconnection of critical infrastructure to the cloud, well-organised threat agents, and the rise of fully autonomous systems, both the control of our environments and the security of our networks/systems are hard to achieve. As a matter of fact, it will not be manageable with traditional security safeguards and practices.

In our 1 ½ years of research we had the target to build not just another SIEM and so we have identified, modified and combined the best available technologies and practices, providing an alternative capability to master the current and future security challenges, all without any log, IDS/IPS, AV or EP data feeds. We've focused on network-related information analytics, combining technologies such as deep packet inspection, big data search, graph databases and machine learning to identify technologies and malicious intent.

We have analysed more than 20 billion flows in all kind of networks and would like to share our results and findings, how to apply such approaches to a security analytics system, a hunting platform or a security safeguard, identifying analyze attacks and compromises not detected by other state of the art safeguards. Furthermore we want to speak about the often propagated "end of DPI" as a result of encrypted traffic. We think our work might change the view on such predictions.


Presenters:

  • Holger Arends - Telstra
    Being a lifelong enthusiast for computer security and emerging technologies, Holger started his IT Security career in the German army in 1997. Since then, Holger has continued to strengthen his professional skill set by being involved in many security projects around the globe. While working with industry leaders such as Microsoft, he's had several years of experience running his own IT Security business. Holger has always been passionate about innovating and developing new security solutions, and this has led him to Telstra where he is the Principal Security Domain Cyber Security expert at the Centre of Excellence, Technology & Innovation. His current role focuses on futuristic and real-world security analytics solutions in the fields of IoT and Cyber Security.

Links:

Similar Presentations: