Artwork

Kandungan disediakan oleh Podcast Archives - Dale Peterson: ICS Security Catalyst. Semua kandungan podcast termasuk episod, grafik dan perihalan podcast dimuat naik dan disediakan terus oleh Podcast Archives - Dale Peterson: ICS Security Catalyst atau rakan kongsi platform podcast mereka. Jika anda percaya seseorang menggunakan karya berhak cipta anda tanpa kebenaran anda, anda boleh mengikuti proses yang digariskan di sini https://ms.player.fm/legal.
Player FM - Aplikasi Podcast
Pergi ke luar talian dengan aplikasi Player FM !

Podcast: Is The Normalized, Taxonomized Approach In A SIEM Doomed To Fail?

 
Kongsi
 

Manage episode 390042503 series 3538694
Kandungan disediakan oleh Podcast Archives - Dale Peterson: ICS Security Catalyst. Semua kandungan podcast termasuk episod, grafik dan perihalan podcast dimuat naik dan disediakan terus oleh Podcast Archives - Dale Peterson: ICS Security Catalyst atau rakan kongsi platform podcast mereka. Jika anda percaya seseorang menggunakan karya berhak cipta anda tanpa kebenaran anda, anda boleh mengikuti proses yang digariskan di sini https://ms.player.fm/legal.

An Interview with Corey Thuen of Gravwell.

Dale and Corey discuss the value of a normalized, taxonomized approach to SIEM, which Dr. Anton Chuvakin has famously claimed is doom to fail. Corey is sympathetic to this view and tries to explain it to Dale.

The alternative is gathering and creating a data lake with more log data and pcaps that can be used by threat hunters and customized rules.

The conversation continues with what types of integration would be helpful between the OT detection products and whatever is used for organization wide detection and response, the packet encryption challenge, and the preference to just buy a product.

You can submit your audio question on this episode or other OT and ICS Security topics to the show by going to dale-peterson.com and clicking on “Record Your Question”.

The post Podcast: Is The Normalized, Taxonomized Approach In A SIEM Doomed To Fail? appeared first on Dale Peterson: ICS Security Catalyst.

  continue reading

7 episod

Artwork
iconKongsi
 
Manage episode 390042503 series 3538694
Kandungan disediakan oleh Podcast Archives - Dale Peterson: ICS Security Catalyst. Semua kandungan podcast termasuk episod, grafik dan perihalan podcast dimuat naik dan disediakan terus oleh Podcast Archives - Dale Peterson: ICS Security Catalyst atau rakan kongsi platform podcast mereka. Jika anda percaya seseorang menggunakan karya berhak cipta anda tanpa kebenaran anda, anda boleh mengikuti proses yang digariskan di sini https://ms.player.fm/legal.

An Interview with Corey Thuen of Gravwell.

Dale and Corey discuss the value of a normalized, taxonomized approach to SIEM, which Dr. Anton Chuvakin has famously claimed is doom to fail. Corey is sympathetic to this view and tries to explain it to Dale.

The alternative is gathering and creating a data lake with more log data and pcaps that can be used by threat hunters and customized rules.

The conversation continues with what types of integration would be helpful between the OT detection products and whatever is used for organization wide detection and response, the packet encryption challenge, and the preference to just buy a product.

You can submit your audio question on this episode or other OT and ICS Security topics to the show by going to dale-peterson.com and clicking on “Record Your Question”.

The post Podcast: Is The Normalized, Taxonomized Approach In A SIEM Doomed To Fail? appeared first on Dale Peterson: ICS Security Catalyst.

  continue reading

7 episod

Semua episod

×
 
Loading …

Selamat datang ke Player FM

Player FM mengimbas laman-laman web bagi podcast berkualiti tinggi untuk anda nikmati sekarang. Ia merupakan aplikasi podcast terbaik dan berfungsi untuk Android, iPhone, dan web. Daftar untuk melaraskan langganan merentasi peranti.

 

Panduan Rujukan Pantas

Podcast Teratas