2020年12月4日 星期五

資安 | What is CASB? 十分鐘初探 CASB (Cloud Access Security Brokers)

 

source: https://www.everypixel.com/search?q=&authorname=geralt



What is CASB(Cloud Access Security Brokers) ? Why need CASB?


" CASB is a solution to provide cloud access controls and visibility, acts as a gatekeeper. " 


因今年發生covid-19,work form home(or everywhere)  越來越普遍,各種 NB, Phone, iPad 等managed 或un-managed Devices 現在就更容易就接上公司網路。

另外,近幾年各式各樣的Cloud App ( ex. zoom, salesforce, dropbox, Box....) 和 Cloud platform storage ( ex. AWS S3) 也廣泛地被使用,資料也都座落在這些Cloud storage上(雖然這些資料還是屬於自己的)。

因為這幾個趨勢,造成組織內部security 管理上複雜維度與風險的急遽升高,對於sensitive data 的控制越來越困難,也因此CASB 的重要性隨之升高。

CASB 非取代 SWG, FWaaS 等技術,而是一種補充與加強。

以組織管理的角度來看,Cloud App的部分可區分為Sanctioned app 與 un-sanctioned app兩類。



CASB的市場價值預估

Gartner 預估2018~2023年,將會有 41% 成長率。

Market is forecast to reach 870 million U.S. dollars in size worldwide in 2019 and 3800 million U.S. dollars in 2023. ( refer to Statista )





/

CASB 簡史

其在2014 年就出現於 Gartner top security projects 中,2015年曾掉出榜外,2016 年又上榜至今。雖然中間略有起伏,不過根據最新趨勢看起來是成長的。

CASB最初發源是為了協助發現 Shadow IT,演進到現在支援越來越多的Use cases.



CASB 4 Pillars

Gartner認為CASB應提供四個維度的功能:發現、資料保護、威脅檢測、合規性,亦即 4 pillarsVisibility, Data Security , Threat Protection, Compliance 

  • Visibility – discover shadow IT cloud services and gain visibility into user activity within sanctioned apps
  • Data security – enforce data-centric security such as encryption, tokenization, and information rights management
  • Threat protection – detect and respond to insider threats, privileged user threats, compromised accounts
  • Compliance – identify sensitive data in the cloud and enforce DLP policies to meet data residency and compliance requirements. Provide visibility for various compliance, for example,  PII, HIPAA, PCI, PHI.



CASB Benefits ( Use cases )

  • Gives companies real-time security control enforcement or enough flexibility to "start out in an API mode or a monitoring mode of operation."
  • help security teams understand a cloud security event before blocking is initiated.
  • To simplify cloud access, companies need compliance reporting and usage monitoring.
  • Protect your sensitive information and prevent data leak. ex. Prevent sensitive folders ( in OneDrive, dropbox, box, S3.... ) which are accessible by others who should not access it. 
  • Protect against insider threats and anomalous behaviors : some vendors also have UEBA capabilities.
  • Get real-time controls for user access and sessions from managed and un-managed devices. ex. limit app access, block downloads,  restrict copy/paste in SaaS apps
  • Threat protection: some vendors also provide cloud sandbox capability
  • Some vendors provide CSPM(Cloud Security PostureManagement) function: to evaluate and reduce laaS, PaaS and SaaS config risk 
  • Some vendors provide data protection functions. ex. data encryption.



TOP CASB vendors

參考 Gartner 2020 and 2019 Magic Quadrant for CASB.

最明顯的兩個變化...
一為 McAfee 在 2020 年的評比中從一群Magic Quadrant Vendors 中脫穎而出,衝到最右上角。
另一而是 Symentec 由2019年的leader 退居 Challenger....





/

Ref:


https://www.ciodive.com/news/gartner-security-risk-covid-strategy/585218/

https://www.mdeditor.tw/pl/2snx/zh-tw

https://www.statista.com/statistics/1067748/worldwide-cloud-access-security-broker-market-value/

https://www.appsruntheworld.com/top-10-cloud-access-security-broker-casb-software-vendors-and-market-forecast-2018-2023/

https://techcommunity.microsoft.com/t5/microsoft-security-and/securing-all-your-cloud-apps-with-microsoft/ba-p/1072310

https://cloudsecurityalliance.org/blog/2015/12/07/gartners-latest-casb-report-how-to-evaluate-vendors/



歡迎轉貼分享,轉貼時禁止修改內容及標題且保持所有連結。禁止商業使用,請註明原文標題、連結以及作者。

2020年12月2日 星期三

資安 | What is UEBA? 十分鐘初探 UEBA (User and Entity Behavior Analytics)

 

近期接觸到幾個蠻有意思的領域,其中一個是UEBA。就順手把手邊資料稍微整理一下,也提供給有興趣的朋友參考。



What is UEBA? 

User and Entity Behavior Analytics( UEBA, 使用者與實體行為分析) 使用行為分析來監測user activities 和 infrastructural entities(ex. routers, servers , enterprise applications, IoT devices and so on.) 。

偵測方式通常是建立一個行為的baseline,接著對異常行為(anomaly behavior)發出Alerts,後續由 InfoSec等會接手進行Investigate。

提到user behavior,就需要知道相關的 assets有哪些。




UEBA 的歷史

曾在Gartner 2016 TOP 10 security projects 中獨立存在,2017年消失後, 在2018年再度入榜。這時是與 EPP+EDR,Deception(欺騙) 和 MDR service這幾個一起包進 Detection and Response Project. 

在 Gartner 2020-2021 TOP 10 security projects 沒有特地再提UEBA, UEBA 也常已被包含在NextGen SIEM 裡面。

如 2020 SIEM Gartner Magic Quadrant 廠商 LogRhythm, Securonix , Exabeam等,也特意提到他們有包含UEBA。

最常見的 use case 是偵測惡意的insider與滲透進組織的外部 attackers.

UEBA Benefits ( Use cases )

  • The ability to accurately detect compromised user accounts and malicious insider by identifying abnormal behavior.
  • Useful as part of a software toolkit for preventing data loss.
  • The prevention of misuse of privileged account access by ensuring the appropriate use of access rights.
  • Improved information security efficiency through automation.
  • Reduced attack surface using advanced behavioral analytics to frequently update IT security staff about potential weak points in the network.
  • Incident Prioritization: to prevent alert fatigues 
  • When and how frequently a user is active, how much information they access and what sensitive information they attempt to download by identifying logs, network packets and endpoint logs. 

/

和SIEM的主要差異

SIEM: focus on log and event information related to suspicious network behavior.
UEBA: emphasizes user and entity behavior.
UEBA is an extension of SIEM applied to a different aspect of information security.


/

TOP UEBA Vendor

因為UEBA 也通常已被包含在NextGen SIEM 裡面,先來參考一下 Gartner 2020 TOP 的 SIEM 有哪些。





以下為 TOP 20 的 UEBA solutions. 粗體的vendor 也出現在Gartner 2020 Magic Quadrant for SIEM. 

  • Aruba
  • Dtex
  • Exabeam
  • Forcepoint
  • Fortinet
  • Fortscale
  • Gurucul
  • Haystax Technology
  • Interset
  • LogRhythm
  • Microsoft
  • One Identity
  • Palo Alto
  • Preempt
  • RSA
  • Securonix
  • Splunk
  • Varonis
  • Veriato
  • VMware


/

Ref:
https://gurucul.com/news/20-top-ueba-vendors ( include UEBA product feature comparison) 




若有您轉貼需求,請來信討論。 轉貼時禁止修改內容及標題且保持所有連結。禁止商業使用,請註明原文標題、連結以及作者。

2020年11月27日 星期五

資安 | Gartner top 10 security projects for 2020-2021 簡筆與摘要

 
Gartner Top 10 Security Projects @2020-2021



"If you can only do one project, focusing on securing your remote workforce and going back and looking at some of those changes we might have made earlier in the year would be a really good use of time" 
                                    — Brian Reed, senior director analyst at Gartner 

預估市場成長

Gartner expects investments in cloud access security broker (CASB) will see a 41% compound annual growth rate, followed by encryption software (24%), and threat intelligence (20%), between 2018 and 2023.


The top 10 security projects

(以下專案為獨立的,並非按照重要性排列

No. 1: Securing your remote workforce

Security teams need to know if they opened too much access for employees. 

No. 2: Risk-based vulnerability management

It's the security team's job to recommend how to prioritize patches, IT team is to apply them. 

No. 3: Extended detection and response (XDR)

XDR is a unified security and incident response platform that collects and correlates data from multiple proprietary components. It is not just SIEM and SOAR.

The platform-level integration occurs at the point of deployment rather than being added in later.

This consolidates multiple security products into one and may help provide better overall security outcomes, simplify and streamline security.

Centralization of normalized data and a centralized incident response capability.

The capabilities have to be able to "change the state of individual security products as part of the remediation process." 


No. 4: Cloud security posture management


To deliver "risk identification and alerting capabilities by reviewing different cloud audit and cloud operational events.
A CSPM platform...

No. 5: Simplify cloud access controls

CASB give companies real-time security control enforcement or enough flexibility to "start out in an API mode or a monitoring mode of operation."

No. 6: DMARC

"We use email far too often as the single or sole source of trust and verification. And it's incredibly easy to spoof," 
DMARC falls short of protecting other areas, such as "lookalike domains," but it's a "quick win,"  
Advises companies to begin in "monitor mode" and graduate to "reject" emails. 

No. 7: Passwordless authentication

Multi-factor authentication, zero factor authentication


No. 8: Data classification and protection 


Not all users and data have the same value, that' why we need it project.
Start with policies and definitions and really get the process right before we start layering in the technology.

No. 9: Workforce competencies assessment

Install the right people with the right skills in the right roles. 


No. 10: Automating security risk assessments 

Automate workflows extracting data from data sources "critical to risk assessment.

/

最近不經間看到一篇2018 年 Gartner top security projects 的分析。
基於好奇心,順手查了一下最新年度變得如何。

不意外地,看到CASB 和  threat intelligence 的預期成長都超過20%。
其中 CASB 在2014 年就出現了,雖然中間起起伏伏,不過最新趨勢看起來是成長的。


順便帶一下 2019 的 Top security projects, 長得和2020-2021 差了不少。
2020-2021 Top security projects 還存在一樣/相似概念的有 CASB和Cloud security posture management。

另外相近的還有vulnerability management、Detection and response (變成XDR)等。

Email threat 相關的,則由2019 的 BEC 變成了DMARC。老實說,DMARC 的出現還真的讓我有點驚訝,畢竟不算是新技術。

  • Privileged access management
  • CARTA-inspired vulnerability management
  • Detection and response
  • Cloud security posture management (CSPM)
  • CASB
  • Business email compromise 
  • Dark data discovery
  • Security incident response
  • Container security
  • Security ratings services



若有您轉貼需求,請來信討論。 轉貼時禁止修改內容及標題且保持所有連結。禁止商業使用,請註明原文標題、連結以及作者。

2020年11月16日 星期一

讀書筆記 | 大人的閱讀方法—極簡閱讀





"閱讀本身也不能創造價值,理解和記憶知識都不能創造價值,改變行為才有可能創造價值。"



為什麼推薦這本書

現在職場工作者的學習方式和以往學生時代有著本質上的不同,現在更聚焦在是否能解決實際問題。
學習的動力,也不再是學校老師的規定和規劃,而是當我們覺得需要以及想要時。
對於實用類書籍,既然花了珍貴的時間閱讀,放棄從事其他休閒活動的時間,總是期待可以收集到想收集的技能點數,或是可以解某部分的惑。
此書亦屬於此類工匠書,作用在提高閱讀的效用,轉換閱讀中得到的知識,進而創造價值。



誰適合讀這本書

買很多書,但都沒看完而覺得內疚者
想學習大人的閱讀方法,提升閱讀成效者
唸了一堆書,但感覺吸收效率不夠好的朋友
閱讀完許多書,但仔細想想卻好像得到「知識消化不良症」,好像沒有得到什麼?


本書如何幫助讀者提高閱讀的效用,學習大人的閱讀方法?

透過其特有的拆書法 —「便利貼學習法」+「RIA現場學習」協助讀者
1. 拆解書中知識,轉化為自己的能力
2. 協助構建個人知識體系,往成為專家邁進
3. 幫助讀者透過閱讀,快速提升所需的職場競爭力。


那具體的做法是什麼?

拆書法主要有兩種實踐形式:一為供組織學習(由拆書家帶領)的「RIA現場學習」,另一個是供個人學習的「便利貼學習法」。
在本書中,前一個方法比較偏向給講師與引導者參考,而後者 —「便利貼學習法」更適用於個人。透過學習此方法,對於從書中拆出對自己有幫助的那部分知識會更有效率。故Peggy以下的書摘著重在此部分。



首先來看看有效的成人學習五大定理 ,拆書法就是建立在這基礎上。

1. 自我導向
2. 連結經驗
3. 強調實踐
4. 聚焦於解決實際問題
5. 内在驅動


「便利貼學習法」

準備工具:

  • 三個不同顏色的便利貼:分別給 I 、 A1 、A2 三種筆記類型用
  • 標籤


 




「拆書」七部曲: 


 1. 拆書法的適用範圍 —「實用類的書籍」。目的是為提升特定能力,解決具體問題,應用在實際工作和生活中。

2. 先要求自己快速閱讀,卡住時問自己:「這對我有多重要?」 若對現在的我並不重要,那就先不理會。


3. 在「I便利貼」上用自己的語言簡要重新描述相關資訊,或總結自己得到的提醒,最好貼在相應的頁面。

4. 針對書中的某資訊,把自己相關經歷寫在「A1 便利貼」上並貼上在「I便利貼」旁

5. 思考今後如何應用:先考慮目標,再把 action item 寫在「A2 便利貼」,也貼在書頁上。

6. 在貼了便利貼的那頁,也貼上一張標籤,以提醒自己這一頁有學習資料

7. 看完一本書後,把所有的便利貼貼在顯而易見的地方,提醒自己要採取行動




/

「便利貼法的社群軟體訓練法」


因為很多初學者回饋,雖然「便利貼法」易理解,但要真正運用到位並不容易
一個較簡單且有趣的「便利貼法的社群軟體訓練法」因應而生。

1. 一個月内,嚴格要求自己不能在臉書或Line「直接分享」任何內容。

2. 當想分享文章時,先停下來問自己以下幾個問題:能加上自己的重述嗎? 能呈現前因後果或適用範圍嗎?能加上自己的相關經驗嗎? 可以有任何應用或行動嗎?

3. 重點在於透過這個加上自己的思維的練習過程來鍛鍊腦袋。如果想五分鐘還是想不到呢? 就放棄分享吧,看起來這篇文章和你沒什麼相關呢,另外這五分鐘內,腦袋還是有訓練到,這樣就達到目的了。




/

一書一行動:從接下來的一個月,可以先用便利貼法的社群軟體訓練法」來鍛鍊腦袋,把需要的知識萃取出來。


/

書中除了本書摘沒有包含的「RIA現場學習」之外,也有不少篇幅討論學習的謬誤、常見的疑惑、怎麼更有效率的建構自己的知識體系等,也蠻值得翻閱的。





若有您轉貼需求,請來信討論。 轉貼時禁止修改內容及標題且保持所有連結。禁止商業使用,請註明原文標題、連結以及作者。


Peggy的實驗空間| 小書庫 Index card ( 讀書筆記總目錄/書單 )

  一直很喜歡閱讀,也常從閱讀好書中與讀書會得到許多的力量與啟發,不管是在人生的低潮抑或是順遂的時候。在閱讀之路上,這幾年也保持一個習慣。當閱讀到喜歡的書籍,且那陣子時間允許,就會提醒自己閱讀完後整理出心得筆記。一方面藉機鍛鍊寫作肌肉與思路,方便之後的複習和查閱。另一方面,也可以...