Security Automation
Security Automation
Security Automation
I am your CIO presenting to the board via a kiosk and you just
locked me out !!!
Threat
Intelligence
Webhooks
Push notifications
SOC AUTOMATION
Detect
Assess SMS
Respond
Response
Log
Action
Close
SOC AUTOMATION
16
SOC AUTOMATION
• The alert is sent from
Sumo Logic into
LogicHub.
• Sumo Logic ,
CrowdStrike,
LogicHub,
• Twilio
• This flow captures the
work that would be
done manually if we
had the resources
17
SOC AUTOMATION
SOC AUTOMATION
• LogicHub created an action
that opens a case in
ServiceNow for purposes of
the POC.
• In the test case, Lucky User
had responded “yes” to the
text which is automatically
documented in the case
that LogicHub automatically
opened
• This action could be easily
modified to our Case
Management System via API
access
SOC AUTOMATION
• Lucky User - The Information Security Office has
received notification of suspicious activity from your
account. IP: 72.216.244.24 Login Time: 2018-06-
12T14:17:30.000Z Please reply with “Y” or “YES” if this
WAS you. Please reply with a “N” or “NO” if this WAS
NOT you. Maricopa Community Colleges will never ask
you for your password, and you may contact the
Information Security Office to verify the validity of this
message at 480-7xx-xxxx
or informationsecurity@mysite.edu.
SOC AUTOMATION
• Because the user has not entered a mobile phone
number, we are resetting their password.
Time: 2018-06-12T21:33:18.000Z UTC
Name: Lucky User
Title: Music Instruction Hrly
Suspicious login from: , United States
Login IP: 2600:8800:2c00:e430:4577:2b1d:f130:5a3f
• Because the user did not respond, we reset their
password
Time: 2018-06-12T16:21:22.000Z UTC
Name: Ima Teepot
Title: Tech Support Specialist
Suspicious login from: Ashburn, United States
Login IP: 54.208.84.215
SOC AUTOMATION
Best Practices
Fail Fast
SOC AUTOMATION
Lessons Learned
•Founded in 2015
•Headquarters: Mountain View, CA
Traditional SOA Vendors
THOUSANDS
HUNDREDS
TENS
Eliminate
Detection
False Incidents
Rules Alerts Positives
( Security Events )
Ignored
Notifications
Security Automation Platform:
Alerts SIEMs
Automation
Integration Framework
Framework
Ingestion Framework
Deep
Threat Intelligence Ranking Case Management
freegeoip
Messaging
ICANN WHOIS SIEMs
Endpoint
dig
ET Intelligence
LogicHub Sample Use Cases
Thank You!
Tammy Sexton
VP Sales
612-961-6672
tammy@logichub.com
Q&A