How can I measure my organizations Automation Capabilities?
5
What can Automations look like, and where do we start?
6
Component One: Alert Ingestion
7
Component Two: Data Collection
8
Component Four: Alert Remediation
9
Component Five: Reporting
10
The Missing Component: Automated Alert Analysis (Component Three)
11
Reviewing the Manual Analysis Process for Indicator Scoring
12
Simple Scoring Use Case: Virustotal File/URL Reputation
13
Simple Scoring Summary
14
Implementing Heuristic Analysis
15
Detailed Scoring Use Case: VirusTotal Domain Reputation
16
Heuristic Scoring Summary
17
Uplifting from Heuristic Analysis to Machine Learning Models
18
Training the Machine Learning
19
Tuning the Automations
20
How to Calculate ROI
21
Real-World Automation Return on Investment
22
How do I implement this in my environment?
Description:
Explore advanced security automation strategies in this 28-minute RSA Conference talk by Tomasz Bania, Cyber Defense Manager at Dolby. Learn how to transition from basic automation to implementing comprehensive end-to-end security solutions. Discover real-world insights on scaling defenses to address the increasing workload of security teams without additional resources. Gain knowledge on measuring automation capabilities, implementing key components such as alert ingestion, data collection, and remediation, and leveraging automated alert analysis. Understand the process of implementing heuristic analysis and machine learning models for more sophisticated threat detection. Explore practical use cases, including VirusTotal file, URL, and domain reputation scoring. Learn how to calculate ROI for automation initiatives and get guidance on implementing these strategies in your own environment.
Scaling Your Defenses - Next Level Security Automation for Enterprise