Cyberstudy
PDF p.315 In progress

Data Sources, Dashboards, and Reports

Open PDF at p.315 19 flashcards

Summary

PDF p.315

In incident response and digital forensics, data sources are analyzed to discover indicators. SIEM tools aggregate and correlate these diverse data sources, providing dashboards and automated reports to support incident management.

In plain words

Supplementary — not from your PDF

Investigations draw on many data sources: memory and file system data, network appliance logs, traffic captures, vulnerability scan logs, OS and application logs, and endpoint security logs. The challenge is the 'Vs': volume, velocity, variety, veracity and value. A SIEM brings them together, with dashboards for daily monitoring (different ones for analysts and managers) and automated reports (alerts that open cases, and status reports).

Detailed explanation

PDF p.315

Data Sources

  • System Memory and Media Device Data: Includes file system data and metadata.
  • Network Appliance Logs: Generated by switches, routers, and firewalls/UTMs.
  • Network Traffic: Captured by sensors and intrusion detection systems.
  • Vulnerability Scanner Logs: Generated by network-based scanners.
  • OS Component Logs: From client and server host computers.
  • Application and Service Logs: From hosts.
  • Endpoint Security Logs: Includes host-based intrusion detection, vulnerability scanning, antivirus, and firewall security software.

Challenges

  • Diversity and Size: Managing large and varied data sources.
  • "Vs" of Data: Volume, velocity, variety, veracity, and value.

Dashboards

  • Purpose: Provide a console for day-to-day incident response.
  • Customization: Separate dashboards for different purposes (e.g., incident handler vs. manager).
  • Content: Visualizations (graphs, tables) showing key status metrics.

Automated Reports

  • Types
    • Alerts and Alarms: Detect threat indicators and start incident cases.
    • Status Reports: Communicate threat levels, incident numbers, and effectiveness of controls.
  • Customization: Preconfigured and custom reports tailored to audience needs.

Important terms

taken from the text above
System Memory and Media Device Data
Includes file system data and metadata.
Network Appliance Logs
Generated by switches, routers, and firewalls/UTMs.
Network Traffic
Captured by sensors and intrusion detection systems.
Vulnerability Scanner Logs
Generated by network-based scanners.
OS Component Logs
From client and server host computers.
Application and Service Logs
From hosts.
Endpoint Security Logs
Includes host-based intrusion detection, vulnerability scanning, antivirus, and firewall security software.
Diversity and Size
Managing large and varied data sources.
"Vs" of Data
Volume, velocity, variety, veracity, and value.
Customization
Separate dashboards for different purposes (e.g., incident handler vs. manager).
Alerts and Alarms
Detect threat indicators and start incident cases.
Status Reports
Communicate threat levels, incident numbers, and effectiveness of controls.

Examples & real-world scenarios

Supplementary — not from your PDF
  • An analyst dashboard showing open alerts.
  • A manager dashboard showing incident trends.
  • A weekly automated status report.

Scenario

A manager wants a monthly view of incident counts and control effectiveness without digging into raw logs. An automated status report from the SIEM provides it.

Common mistakes

Supplementary — not from your PDF
  • Giving everyone the same dashboard regardless of role.
  • Collecting everything without thinking about value.

Practical skills

Supplementary — not from your PDF
  • Design dashboards for an analyst and a manager.

What I should remember

Key Points PDF p.315
  • Data Sources
    • System Memory and Media Data: File system data and metadata.
    • Network Appliance Logs: Switches, routers, firewalls.
    • Network Traffic: Sensors and IDS.
    • Vulnerability Scanner Logs: Network-based scanners.
    • OS Component Logs: Client and server hosts.
    • Application and Service Logs: Hosts.
    • Endpoint Security Logs: Intrusion detection, antivirus, firewall.
  • Challenges
    • Diversity and Size: Managing large data sources.
    • "Vs" of Data: Volume, velocity, variety, veracity, value.
  • Dashboards
    • Purpose: Incident response console.
    • Customization: Different dashboards for different roles.
    • Content: Key status metrics.
  • Automated Reports
    • Types: Alerts/alarms and status reports.
    • Customization: Preconfigured and custom reports.