SECURITY AND SIE TOOLS(Task 6.1)

Hlo guys,

I am back with an some other intersting topic.........

****************************SIEM TOOLS****************************

Now,let me tell .....

1).What is SIEM  means..??

At a basic level, a security information and event management (SIEM) solution is designed to ingest all data from across your enterprise, normalize the data to make it searchable, analyze that data for anomalies, and then investigate events and remediate incidents to kick out attackers.

2).What challenges we have in SIEM tools..??

-->Complex Architectures Increase the Ways Attackers Can Gain Access

Organizations are using a more distributed architecture than ever before. The more complex an architecture, the more cracks a sophisticated attacker can utilize. This increases the company’s risk of a cybersecurity incident.

-->Enterprises Generate More Data Than a Human Can Review in Time To Stop an Attack

When monitoring for suspicious activity, there is more data to process than any number of analysts could ever review without help. Analysts need technology to help them find and flag the most important events to investigate, or a policy violation that needs to be mended.

    Now i wanna relate this SIEM to  DATA SCIENCE.....

Disorganized Data Labeling Hamstringing Your SIEM?


Detecting threats accurately is crucial. One of the biggest challenges a security teams faces is differentiating anomalies from true malicious behavior. Is this a real threat or a false-positive? Modern SIEM is helping to answer this question but data inconsistencies at ingestion may drive false positives and false negatives. Data (log) complexity shouldn’t complicate a security analyst’s job further. That’s why you invested in security solutions.

Securonix Next-Gen SIEM solves this data inconsistency challenge by simplifying the way analysts search and label data in a feature known as Data Dictionary. Data Dictionary simplifies ingestion, analytics, and hunting processes by providing consistent and easy to understand labels for data ingested from various data sources. This helps to eliminate false positives and negatives and reduce the time analysts would take trying to find the information/context that was incorrectly categorized.

Benefits of Data Dictionary

Data Dictionary gives you a more consistent search experience. Customers with the latest release will be able to:

  • Simplify and streamline inconsistent data formats from various data sources.
  • Help security analysts to get valuable context and be able quickly differentiate false positives.
  • Reduce the time and effort a content developer spends creating policies for different data sources.

Improve Search

Data Dictionary streamlines the mapping of data attributes with consistent labeling to simplify and improve searchability. It provides uniform labelling of security data from various sources which otherwise would be inconsistent, labeling groups under a name or label that makes sense for your organization. 

The Data Dictionary feature was introduced recently with the Jupiter launch.

WHAT IS CONFUSION MATRIX?

A confusion matrix is a summarized table of the number of correct and incorrect predictions (or actual and predicted values) yielded by a classifier (or classification model) for binary classification tasks. 

 

In simple words, “ A confusion matrix is a performance measurement for machine learning algorithm.


The confusion matrix is in the form of a square matrix where the column represents the actual values and the row depicts the predicted value of the model and vice versa. Specifically;

 

  1. A confusion matrix presents the ways in which a classification model becomes confused while making predictions.”

  2. A good matrix (model) will have large values across the diagonal and small values off the diagonal.

  3. Measuring a confusion matrix provides better insight in particulars of is our classification model is getting correct and what types of errors it is creating.

 



Comments

Popular posts from this blog

WHAT IS TECHNOLOGY AND WHY TECHNOLOGY,HOW IT'S EVOLVING in NOW-A-DAYS.

SELF RELIANCE DIGITAL INDIA

LINUX ESPEAK COMMANDS