Главная
Study mode:
on
1
Cloud SIEM: What happened and what's next? Gunter Ollmann
2
A 20 Year Journey
3
Cloud Native SIEM
4
Overwhelmed with Data
5
Cutting-edge Today
6
Raw Events to High Fidelity Incidents
7
Changes in Hunter Thinking
8
Reactive Investigation vs Preemptive Hunting
9
Prioritizing Haystacks
10
Cloud-native Threat Hunting
11
Attack Timelines
12
User & Event Behavioral Analytics (UEBA)
13
Al-powered Threat Intelligence
14
(Auto) Threat Hunting
15
(Auto) Mitigation
16
Cloud Effects on Hunting
17
Cloud Effects on Response
18
Ditching Human Constraints
19
The Threat Hunter Role
20
Technology Constraints
21
Constraining Al in Security
22
Replicate the Human Expert?
23
Change the medium...
24
Evolving Machine Intelligence
25
Conclusion
26
Belgian Style Hacking
Description:
Explore the evolution and future of Cloud SIEM in this 56-minute conference talk from BruCON 0x0B. Delve into the successful fusion of cloud-native SIEM and AI, examining its impact on cybersecurity operations and risk management. Learn how this technology enables real-time threat discovery and mitigation at a compelling cost for both CFOs and CISOs. Discover the potential for preemptively identifying and neutralizing attacks before they escalate into viable threats. Investigate the changing roles of "Threat Hunters" and security analysts as incident identification and response become API-driven. Examine how SecDevOps will embrace cloud SIEM and lead threat response efforts. Explore the balance between AI capabilities and in-house expertise, and understand the newfound ROI for enterprise security. Gain insights into cloud-native threat hunting, attack timelines, User & Event Behavioral Analytics (UEBA), and AI-powered threat intelligence. Consider the evolving landscape of machine intelligence in security and its implications for the future of cybersecurity operations. Read more

Cloud SIEM - What Happened and What's Next?

BruCON Security Conference
Add to list
0:00 / 0:00