Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

By SplunkTechnology
Download on the App Store

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides episodes

  • Is it Normal or Suspicious? Detecting Anomalies via Market Basket Analysis [Splunk User Behavior Analytics]
    Detecting abnormal behavior is an important objective in security monitoring, but is extremely challenging as we mostly are expected to detect "unknown unknowns." We can, however, use an entity's past behavior to measure how much of what we observe today deviates from normal behavior. In this way we can detect unknown, hidden and insider threats early on to stay ahead of advanced threats. This talk presents a unified, scalable framework for anomaly detection that is built on the frequent itemset mining technique. The premise is that if we can align an event with more frequent patterns observed in history, then the event is unlikely to be an anomaly. By mining through an extensive set of features and feature co-occurrences, the model can accurately capture the normal behaviors. Any new behaviors can then be scored. At which point, any new rare co-occurrences of events can be detected and sent to analysts and SOC teams for rapid investigation.

    Speaker(s)
    Nancy Jin, Data Scientist, Splunk
    Ping Jiang, Sr. Software Engineer in Test, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1230.pdf?podcast=1577146215

    Product: Splunk User Behavior Analytics

    Track: Security, Compliance and Fraud

    Level: Intermediate

    0 min
  • Klapp-Back at Attackers: Capturing Data in the Wild to Build Tailored Defenses with Splunk Security Analytics [Splunk Enterprise, Splunk Enterprise Security, Phantom]
    Splunk's Security Research Team collects attack data in the wild from across the globe and analyzes new and unusual techniques, tactics, and procedures employed by threat actors. We use this data to help customers build tailored defenses—defenses that automatically detect, investigate, and respond to suspicious activities in real time. In this session we will discuss how Splunk security researchers created our own honeypot and data collection framework in response to research demonstrating that honeypots were twice as effective as open-source intelligence feeds at detecting new threats (http://tinyurl.com/y335po8d). We will provide an introduction to honeypots and explain how we architected and built KLAPP-Back, a high-interaction SSH honeypot. We will also discuss how KLAPP-Back helped us build better detection analytics and seed Splunk Enterprise Security, Splunk Phantom, and Splunk User Behavior Analytics use cases with attacker data.

    Speaker(s)
    Bhavin Patel, Security Software Engineer, Splunk
    Jose Hernandez, Security Researcher, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1357.pdf?podcast=1577146215

    Product: Splunk Enterprise, Splunk Enterprise Security, Phantom

    Track: Security, Compliance and Fraud

    Level: Intermediate

    0 min
  • Large Scale Threat Hunting in Splunk [Splunk Enterprise, Splunk Enterprise Security, Splunk Machine Learning Toolkit]
    Threat hunting is hard, and threat hunting in an enterprise network with thousands of endpoints is even harder. We will demonstrate how we leveraged Splunk Enterprise to build an Advanced Threat Hunting platform designed for large scale threat hunting of 100,000 or more endpoints. Using Splunk Enterprise allows us to combine analytics, data enrichment, and custom workflows to display in one platform the most important data to analysts. Our threat hunting platform addresses the challenges of data retention and collection, high false positive rates, and analyst fatigue, all while lowering the time to detection of malicious incidents and improving the efficiency of enterprise SOC operations.

    Speaker(s)
    Dan Rossell, Analyst, Booz Allen Hamilton
    Ashleigh Moriarty, Lead Technologist, Booz Allen Hamilton

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1071.pdf?podcast=1577146215

    Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Machine Learning Toolkit

    Track: Security, Compliance and Fraud

    Level: Intermediate

    0 min
  • Lessons Learned From Building a Threat Detection Program [Splunk Enterprise, Splunk Enterprise Security, AI/ML]
    We will share experiences and best practices for implementing notable events, the various Splunk Enterprise Security frameworks, and adaptive response actions, and we'll share our approach for building a program to consistently develop, measure, and iterate on correlation searches. We will discuss how to integrate lessons learned from incidents, red team engagements, threat intelligence, threat hunting, and requirements from business units into the program. Example tactics we'll cover include leveraging low-fidelity detections to develop higher-fidelity and higher-value ones, managing detection content simply and easily through macros, and building a formula to assess the efficacy of your detection content.

    Speaker(s)
    Chris Ogden, Principal Threat Detection Engineer, Sony Corporation of America
    Drew Guarino, Senior Threat Detection Engineer, Sony Corporation of America

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1674.pdf?podcast=1577146215

    Product: Splunk Enterprise, Splunk Enterprise Security, AI/ML

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Lessons Learned from Deploying Splunk UBA [Splunk User Behavior Analytics, AI/ML]
    Splunk User Behavioral Analytics (UBA) is a machine learning driven solution that helps organizations find hidden threats and anomalous behavior across users, devices, and applications. In this session we'll answer questions that came up during our large-scale deployment such as, once you've got UBA installed, how do you know if it is working well in your environment? And how long after installation does it take for the system to be operational and produce results? We'll also share best practices for validating outputs and tuning the system. This session will help you jumpstart your understanding of UBA and help you get your UBA deployment into production and detecting threats faster.

    Speaker(s)
    Teresa Chila, Data Scientist, Chevron
    Maria Sanchez, Technical Support Engineer, User Behavioral Analytics (UBA), Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1490.pdf?podcast=1577146215

    Product: Splunk User Behavior Analytics, AI/ML

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Make Compliance a Breeze with Splunk Enterprise Security [Splunk Enterprise Security]
    This session will give you the tools to tackle compliance with Splunk Enterprise Security. The session will showcase why you might want to grant different compliance views to your teams based on the compliance standard they are responsible for adhering to, and how to do so. We'll also cover how to present the compliance standards that a notable event relates to and how to grant your compliance officers visibility into only the notable events that are relevant to them.

    Speaker(s)
    Jason Timlin, Professional Services, Splunk
    Darren Dance, Staff PS Consultant, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1852.pdf?podcast=1577146215

    Product: Splunk Enterprise Security

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Make Your Security Tools Work Better Together Using Splunk's Adaptive Operations Framework [Splunk Enterprise, Splunk Enterprise Security, Phantom]
    Security architectures typically involve many layers of tools and products that are not designed to work together, leaving gaps in how security teams bridge multiple domains to coordinate defense. The Splunk Adaptive Operations Framework (AOF) addresses these gaps by connecting security products and technologies from our partners with Splunk security solutions including Splunk Enterprise Security (ES) and Splunk Phantom. Join this session to learn how the Splunk AOF benefits both users and security technology providers by enabling rich context for all security decisions, collaborative decision-making, and orchestrated actions across diverse security technologies.

    Speaker(s)
    Alexa Araneta, Product Marketing Manager, Splunk
    John Dominguez, Product Marketing Director, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC2372.pdf?podcast=1577146215

    Product: Splunk Enterprise, Splunk Enterprise Security, Phantom

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Measure What Matters to Streamline Security Operations with Splunk [Splunk Cloud, Splunk Machine Learning Toolkit]
    To tame an event queue that's ballooning out of control, you need to know first which rules and data sources are generating a disproportionate number of alerts, and second the security value you're getting from those rules and data sources. Any changes made to rules or telemetry analyzed without that knowledge risk making your organization more vulnerable. In this session we'll discuss how Splunk empowers us to perform advanced analytics on everything from alert conversion rates to human time expenditure on alerts so that we can optimize all processes related to alerting. As long as we know what to measure and where to look, Splunk can help us tune our security operations centers to reduce monotony and false positives without diminishing our ability to detect actual threats.

    Speaker(s)
    Keshia LeVan, Detection Engineer, Red Canary

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC2105.pdf?podcast=1577146215

    Product: Splunk Cloud, Splunk Machine Learning Toolkit

    Track: Security, Compliance and Fraud

    Level: Advanced

    0 min
  • Advanced Threat Hunting and Anomaly Detection with Splunk UBA [Splunk Enterprise, Splunk Enterprise Security, Splunk User Behavior Analytics, AI/ML]
    Splunk User Behavior Analytics (UBA) contains the largest library of unsupervised machine learning in the market. In this session we'll show how to analyze data from both cloud and on-premises data sources in both types of deployment (cloud/on-premises) to convey the unique benefits of Splunk UBA. We'll discuss real world examples that showcase the importance of using UBA and all other tools at your disposal for day-to-day threat hunting. Specifically, we'll show how to use Splunk Enterprise, Splunk Enterprise Security, and Splunk UBA together to hunt and detect anomalies that can reveal significant threats. We'll wrap up with best and worst practices from deployments seen throughout the world.

    Speaker(s)
    Tom Smit, Staff Sales Engineer, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1248.pdf?podcast=1577146214

    Product: Splunk Enterprise, Splunk Enterprise Security, Splunk User Behavior Analytics, AI/ML

    Track: Security, Compliance and Fraud

    Level: Intermediate

    0 min
  • Anatomy of an Attack []
    This session covers how an actual phishing attack from APT29 came together. We will discuss how incident responders can learn more about the attack and build out a timeline of key events. We will also explain how DNS based security plays an important role in proactively blocking threats and how integrations with Splunk can help you with effective threat hunting.

    Speaker(s)
    Mark Stanford, Cisco Systems

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC3014.pdf?podcast=1577146214

    Product:

    Track: Security, Compliance and Fraud

    Level:

    0 min

About Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

From the publisher's feed

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides