Detection at Scale

Google Cloud’s Anton Chuvakin on Decoupled SIEMs and the Future of Data Platforms and Security


Listen Later

On this week's episode of the Detection at Scale podcast, Jack talks with Dr. Anton Chuvakin, Senior Security Staff at the Office of the CISO at Google Cloud. They dig deeper into the conversation taking place online around decoupled SIEMs, which both Jack and Anton wrote about. They discuss what a decoupled SIEM is, the evolution of data platforms and security capabilities, if decoupled SIEMs will work broadly with current customer demands, and if having backend data lakes is the best solution for fast, real-time querying.

Topics discussed:

  • What is a decoupled SIEM, and why the broader discussion around whether security data lakes will replace SIEMs prompted Anton's Medium post.
  • How this conversation is being driven by the fact that we’re coming to the "end of the runway" on previous storage choices.
  • The arguments around why decoupling may not work broadly, simply because customers want integrated SIEMs.
  • The evolution of data storage platforms and how successful past attempts at integrating security capabilities were.
  • Why there's not a straightforward solution to storage — and why it's a challenge that's taking years to solve.
  • Why having a data lake on the backend is the best solution to fast querying and real-time detection.
  • A discussion around OCSF and the benefits of log normalization. 
  • Resources Mention: 

    • Decoupled SIEM: Brilliant or Stupid?” by Anton Chuvakin
  • The Transition from Monolithic SIEMs to Data Lakes for Security Monitoring” by Jack Naglieri
  • ...more
    View all episodesView all episodes
    Download on the App Store

    Detection at ScaleBy Panther Labs

    • 5
    • 5
    • 5
    • 5
    • 5

    5

    11 ratings


    More shows like Detection at Scale

    View all
    Security Now (Audio) by TWiT

    Security Now (Audio)

    1,966 Listeners

    Risky Business by Patrick Gray

    Risky Business

    360 Listeners

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    628 Listeners

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

    367 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,014 Listeners

    Smashing Security by Graham Cluley & Carole Theriault

    Smashing Security

    314 Listeners

    Click Here by Recorded Future News

    Click Here

    392 Listeners

    Hacking Humans by N2K Networks

    Hacking Humans

    313 Listeners

    Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

    Defense in Depth

    78 Listeners

    Dwarkesh Podcast by Dwarkesh Patel

    Dwarkesh Podcast

    352 Listeners

    Cyber Security Headlines by CISO Series

    Cyber Security Headlines

    118 Listeners

    The Ezra Klein Show by New York Times Opinion

    The Ezra Klein Show

    15,037 Listeners

    Cloud Security Podcast by Google by Anton Chuvakin

    Cloud Security Podcast by Google

    40 Listeners

    Risky Bulletin by risky.biz

    Risky Bulletin

    33 Listeners

    No Priors: Artificial Intelligence | Technology | Startups by Conviction

    No Priors: Artificial Intelligence | Technology | Startups

    129 Listeners