Unified Detection The traditional way of operationalizing security content is forward-looking ,
by disseminating the content to the detection edge where they can act, e.g.,
network sensors or endpoint agents. If the roll-out relies on periodic pulling,
then there's an inherent minimum delay from the time a detection was available
to the time when it can act. In addition, if there is no historical telemetry at
the edge, the detection must also be applied to the SIEM out-of-band. The
diagram below illustrates this:
eyJ2ZXJzaW9uIjoiMSIsImVuY29kaW5nIjoiYnN0cmluZyIsImNvbXByZXNzZWQiOnRydWUsImVuY29kZWQiOiJ4nO2bWXeiylx1MDAxNsff+1O4vK+tp+bhvCVmTsxkJ7Fzz1lZXGKoKIJccmiivfq738IkglxiTp3YpPv6kGhcclBU/X+1d+0qvn8qXHUwMDE0isGob1x1MDAxNv8uXHUwMDE0zSddsy3D01x1MDAxZYufw/Sh6fmW66gsNPntu1x1MDAwM0+flGxcdTAwMDdB3//7r7+0fr9cdTAwMWPVKutu77mmaZs901x0fFX2v+p3ofB98jd2L83z3OfbTJKjW0mYTDx3ncldOZRcdTAwMTJjSKf5lr+nblx1MDAxNJiGymxqtm9GOWFScVi1O+xi/9t9/f7s0LpcdTAwMTmeuvfIie7ZtGy7XHUwMDE2jOxJe3xXPUOU51x1MDAwN57bNe8sI2irXFyYSM+q5bmDVtsxfX+mjtvXdCtcdTAwMTiFaVx1MDAwMExTNac1uUaU8qR+UVx1MDAwNMqCYcBcdTAwMDRCXGIzjKe5k/qyjFxiYVx1MDAxOGIosICC0ETDKq7temHD/kMkXHUwMDA1lEdNa2h6t6Xa51x1MDAxOFGZhqE3jUZU5vHlcTGKXHUwMDFh1TatVjuYaadvTnpcdTAwMWNcdTAwMDFGXGLkXCI2YOFccvrHxmTY/433imO89IozsO2oTWHGfkwqUZ1B39CeXHUwMDA3XHUwMDE2MkqoIFx1MDAxOGNcdTAwMTJ7XFzbcrrJy9mu3k3Rglx1MDAxZmhesGs5huW0klVMx8jIsTU/qLi9nlx1MDAxNahmXFy6llx1MDAxMyRLTK67XHUwMDEzyrhtakbKleN5xcCznkd8WqJcdTAwMWZeNFwiJPxE31xuUX9Pfky///s5tXRsyFx1MDAxMuU/xf//+LwmjVxmJ1x1MDAxM19ppFxmcEYliEZ/XHUwMDE5jn6nbvaaujFqNndcdTAwMGa+XFztP9ieYedcdTAwMWJHyECZMkjV1IMo4Fx1MDAxMEdcblx1MDAxY01cdTAwMTAoXHUwMDEziFx1MDAxOMJcdTAwMTJIgFx1MDAxNZG/XHUwMDEwRzUjICRcdTAwMDWG/P84ZiGXgHKm/ofAXHUwMDExXHUwMDEymcWjslx1MDAwNkxcdTAwMDLOeVRiXHUwMDE5kDVI7k6a5+Lh4bpcbnT0JThyetomQJLt2cdYibBGKV4lXHRcdTAwMWSYfDaDLlx1MDAwNTk1XHUwMDE5JKFjXHUwMDEwUIVCrM8/XHUwMDAyc9+ncnx11I4neng6f3o433+oNoBePbW8LqJWq1qMhFxcbLr6wI93TvjAWj9s4kvCj19gWlxyN3gnqzpTWlxy/5pcdTAwMThcdTAwMDfmU5BGMaLJxCnEhEiEOcDRJL5cZmLzW/8rsq6NW37hXHUwMDEwt1apX1+cPubbqopcdTAwMDTE5H1cdTAwMTCmke8yZVx1MDAxOM0hTCDkjDBcdTAwMTJcdTAwMTVejnBcZqCXsUZz+t9cdTAwMGXZTddcdGrWeKJcdTAwMWQ2k3qg9Sx7NDNGXHUwMDEzPapcdTAwMWU7XHUwMDE4XHUwMDA0XHUwMDAzz4x3qm+qez5cdTAwMGJwpvSObbVCxVx1MDAxNnX1XHUwMDE0pjcj5sBS675pgcDtR7m6ur+mLuhcdTAwMWTPwet6VstyNPvLbFs24ojyTI5EOKySoNU5XHUwMDFhaE93pV7bXHUwMDFi12utq/pcdOje6WedfHNcdTAwMDTJVjhcIim2cJ4jiJGUXGJcdTAwMDD4XHUwMDA3gXSpLFk+MJq0ZCFEpm1bfd9M44iQTI4kg5hcYrSGPepcdTAwMWXWjdLl1+pdXHUwMDFkXHUwMDFl4/6g0aldeE/55oiyWY5+XHUwMDBlo6bWXHUwMDAwgK6GXHUwMDExSVnGXHUwMDExgChcdTAwMTd0XHUwMDFkl/KXY7Sp8ijIVFx1MDAxZZKQXG5BV1x1MDAwZi9cZmpXlUq90aagTbWbb8f3dLx/nW/hMZRcdTAwMWbhXHUwMDExxFx1MDAwMESI/Vx1MDAxMbojmZ5cdTAwMDNcdTAwMTdcdTAwMTBDuc4q+mY8pFx1MDAwZk51YJRo21x1MDAxNKdWx211c1x1MDAxZdbCbzzhUUTRprpcdTAwMTNcYlx1MDAxMYHjgY3fWHfZXHUwMDFlq+RcdTAwMTIhKmNcdTAwMDH/ZbrTpVx1MDAwN49cdTAwMGUuzK6oMHvc3ztcdTAwMGa07lW+dYfeeL77XHUwMDE53UFKsVx1MDAxMESAXHUwMDBm5a8uXHUwMDE0XnbYUGbqXHUwMDBlXHUwMDAxKSWUmK0uPK45xztcdTAwMDdEent1NMJfx8dcdTAwMTZcdTAwMWO6+Vx1MDAwZVx1MDAxYlwiXHUwMDAyylSNtSBcdTAwMDQwXHUwMDAwXHUwMDA0YDM6ZLBMOaGKQcxcdTAwMDWLx1x1MDAwMt5yXHUwMDFkpfAuXHUwMDEzXG6VX6M4XHUwMDBmO53M6zTRXHUwMDEwJERSt4hcdTAwMTHCxHp2+teHXHUwMDFjf88wf/aIhp/S/GBGXHUwMDE3/Fx1MDAxNP+/NtCIZDvOyphKgCBafZ98fNpcdTAwMDN7jWvQrzTpbq9m1LWzg9t8XHUwMDAzzVx1MDAxNdCMXHUwMDAzXHUwMDBlJIecsdhcdTAwMWX0XHUwMDBiz1xmc06EQFx1MDAwMiNcdTAwMTGb/d6U5zRDk2JnXHUwMDAwXHUwMDA1QELxsfblsvZcYm7vb1x1MDAxYqf1Tlx1MDAwNVxyd8fHvKZ5e8K+TNsjQGXEhFx1MDAxNOrRMcc4nLFihV42XHJoWTDl9UDIIeNcdTAwMTBgPGdMf5upolx1MDAxNFNLosJKU0FWXGZUZm7Qq4VcZlbzwDr7gWZv5I+AuX9Sb1x1MDAxYbuHotPZOVx1MDAxOOXcoySzO/Kcl7PPxPxcZuyQonnYY3PsK+2AXHUwMDEziNXMXHUwMDEz5XxcdTAwMDCvMlx1MDAxYeIoXG5cdTAwMWFz1ZdEQT1T9XPBUMLSg1CUsf6NXHUwMDAyomKm2vtcdTAwMDdEk43a0M7yzP12LsJcdTAwMDVb/ETIUr/Z7NyMXHUwMDA3e3cleVr3/dtcdTAwMTNQNcn5m+JluOFk+KZ2XHUwMDE2KFNcbsOTL1xmSEJjq/TRrEbe8sBL2t47hGVMsDJcdTAwMTFcZjAoWCwu+Fx1MDAxYb9cdTAwMTKUXHUwMDExXG624Vx1MDAxN0skMVx1MDAxNIJtQtj2/OKZbfGt2bmZ0qX5YXsjs1x1MDAwNyN3Yn7PXHUwMDAyYcXmXHUwMDFhkePFPk0u7Z7qzvK2LFx1MDAxZk7bR5+zfFxicMxcdTAwMTBF8N1cdTAwMDN50zrfY1JbaSkzI63nSX+a8+NVj7mxq7Y1NPNmVlx1MDAxM21ayO6COCjP9FohXHUwMDA0XGJcdTAwMTFcdTAwMTifx5fhW+ndnV2VxpeHO65nu7vX+k6J53zHkZO3XGaEXG6kS2jOk7tiIFx1MDAxNFx1MDAxMyhcYsFynVx1MDAwNeovd1k3slx1MDAxYVwi8+BcdTAwMTVCmPO1tlx1MDAxYv3dI99EbbPd24Gda0j4XHUwMDAzaG50eHKLiyWMZlRXYtm60yXSkLahxeApkc1cdTAwMTThMclcdTAwMDSCSH6oXGJ82py++omRnuX7plHQ1PQ5VMP2j1x1MDAxM7iFhllohi0uXGYtrVA73q+mTvV420dKVmvqZt6bXFxwjJmFsSCxOog355dcdTAwMDKjq1x1MDAxYepUmqhXcztHt48w3yDSxD7YXCJcdTAwMTBNxvnGrlx1MDAxYoOrgIjU0lx1MDAwZUP2R52BnFO3MTBcdTAwMGJK4Z5r2+4gUD6OrY1yXG5ialM3XHUwMDAyXHUwMDExkWxHjFx1MDAwMKL8MFx1MDAwMddwxHx47MpRPziqNvb4mXfYXHUwMDFhn8l8k8hjr8ssI5Hqklx1MDAwMGNTXHUwMDEy+SokMk5cdTAwMDXjXHUwMDFmy1x1MDAxM/s5XHUwMDBlX1Vd0F0lQNP4x3m0gnbBN/WB95ysqHLST1luncRVXHUwMDFiuyGL2W++XG5cdTAwMDJcdTAwMDBmZHVcdTAwMTSrN/7jcO/uqTnsdvmdfXR/XHUwMDBlQT3fKLJEKL9cdTAwMDTf6TwzhCmh/HlcdTAwMTYlXHUwMDA1jChcdTAwMWHTI/lcdTAwMTF1fu3pxL/9cvl13Lv29cYxXHUwMDFjjmvwNa6wXHJmJZKIXHS2PWYrzzIveKZmKHPUdL0lYYqtg7qwhVx1MDAwYun0VKHEXHUwMDFlYYRobP00TyjCdJ33XHJcdTAwMTa/bJVLQsncy3dcdTAwMGKs5UonuGBcdTAwMTM1U05wIZBcdTAwMTK5mH/7XHUwMDBlXHUwMDAy5aNcYlx1MDAxZd9cZtjEXs6/u7ZiyDF1Ro9ccvHt4dnh6PKOn1xcXHUwMDFmNs97g8f7XHUwMDA27uuxiOPn9Muu8nLmzP3Xj2RcdTAwMTIsXHUwMDAwilxcv3dcbrfgTOdcdTAwMTIxXG5cdTAwMDQlcI1cdTAwMTh9al/mXHUwMDFjlzmDXHUwMDA2fy5GXHUwMDFmeJrj9zVvxiGamjWZ9p5cdTAwMGVOQoOAkJAzjj/Ugds0g7V6JL326qBVXHUwMDE2eJOxlcB6RqpnXHUwMDE5RtxezNqpZVx1MDAxM33SdM219Vx1MDAxOb1PLzxcdTAwMTe1fr9cdTAwMTao3pyOSnFomY+7abPr5Fx1MDAxM9afXGZSyIg5XHUwMDE5zFx1MDAxZp9+/Fx1MDAwZkXHXUIifQ==Future Past retro detection live detection missed activity to be found via SIEM missed activity due to rollout delay activity covered with security content Content ready for detection Security Content
What we really want is a unified approach for operationalizing security
content: automated push-based dissemination with a negligible propagation delay
and installation at the detection edge, so the that future telemetry streams
through the engine. When keeping telemetry at the edge, the new detection should
also immediately trigger a retro scan:
eyJ2ZXJzaW9uIjoiMSIsImVuY29kaW5nIjoiYnN0cmluZyIsImNvbXByZXNzZWQiOnRydWUsImVuY29kZWQiOiJ4nOVbWVPqSFx1MDAxYr73V1B8t1x1MDAwN6b3Ze7c91x1MDAxZMflm6lTMVx0XHUwMDEwXHJJTFx1MDAwMlwip/zv04lKXHUwMDE2XHUwMDAyXHUwMDAyXHUwMDAyZmagVOj1TffzvFu3v9YqlWr44pnV3ytVs69rtmX42nP1R1TeM/3Aclx1MDAxZFWF4u+B2/X1uGU7XGa94PffftM8r570qutu562naZtcdTAwMWTTXHRcdTAwMDPV9v/qe6XyK/6dmkvzffdtmrg4mUrSfOGJ68SzSoowh5QmXHKsYEvNXHUwMDE0moaqbWp2YCY1UVF117w4QM9cdTAwMWKH61dXT1pg967N1qGeTNq0bPsyfLFjgVx1MDAwMlc9RFJcdTAwMTeEvvtoXltG2Fa1MFc+rpfvdlttx1xmgkxcdTAwMWbX03QrfInKXHUwMDAwXHUwMDE4lmpOK1x1MDAxZSMp6atvXHUwMDE0gbpgXHUwMDE4MIFcdTAwMTDCXGbjYW3UXHUwMDFmU1lHhDBcZjFcdTAwMTRYqJ+cYJuu7fqRYP8jklx1MDAwMspcdTAwMTPR7jX9saXkc4ykzb2hN437pM3z++NilFxi1TatVjvMyFx1MDAxOZjxiktcZlx1MDAwMSSCJVx1MDAwZlx1MDAxYY3v7Vx1MDAxYvG2/5VeXHUwMDE0x3hfXHUwMDE0p2vbiUhRxXZcbipJn65naG/7XG5cdTAwMTklVFx1MDAxMMw4XHUwMDAyZFhvW85jfjjb1Vx1MDAxZlx1MDAwYqBcdTAwMTCEmlx1MDAxZm5YjmE5rXxcdTAwMTfTMcbU2FpcdTAwMTBuup2OXHUwMDE1KjHOXFzLXHTzLeJx1yNcdTAwMTi3Tc0oXHUwMDE4OV1XXHJ9623Dhy28aNCEIdEr+VRJljv+Mvz814/C1qlcdTAwMWTLtV9L/339MSNcdTAwMWJcdTAwMTlcdTAwMWbHRk6I4IIxOTVcdTAwMWKPXHUwMDA3tatgXHUwMDFknHTWLUd/OsJG/+jhvNxshFxm1CmDlEOJKOBcdTAwMTAnuiemo6omXHUwMDEwMYQlkFx1MDAwMGPxjWxkSFx1MDAwMKpcdTAwMTRGXCLhf5uNXHUwMDA1jMtxMtP/XHUwMDFmwUaUXHUwMDAybI6OkGG1MYjiXHUwMDA06J/xcdC62tszjszWTeP8XGKcSlx1MDAwN5CwN1x1MDAwZlx1MDAxZkmufInWMdVcIuqBXGLIzZ3QXHTEr/koV0A4pVxu8pTjXHUwMDE0YMpQSlx1MDAwNS6Xckwm5n5+yv1cdTAwMWGi8cNN24/hcFx1MDAwYtldZ1x1MDAxMEh969glW89cdTAwMTfNM/WuJjiuNl29XHUwMDFipFx1MDAxNyd6YM2LRHwveP1cdTAwMDbDarjhkmxqprXa/lx1MDAxOVlcdTAwMWOa/bCQxDJf+MFhTJVDJaGYnsLa/fp2KDY02Dk1+/3T2/274NQtt0lcdTAwMTU5XG5jsVx1MDAxY1xu04QrQ1x1MDAwZaNRXHUwMDFmVkQ6k+NZfNhcdTAwMTSB3vdcdTAwMWGN4H81xrTpOuGlNXjT/5nSXHUwMDFkrWPZL5lNivGoVmynXHUwMDFidn0zvaiBqeaMXHUwMDA3IZnW67bVilx1MDAxMFvV1VOYflx1MDAwNsyhpaK+YYPQ9ZJaXc2vqVx1MDAwMf39XHUwMDEx8rq+1bJcdTAwMWPNbmRlmYtHqbgjxyNcdTAwMDJib2xcdTAwMDZTiMCe+/hwZ3W9XHUwMDBi9Piw+3TQ0k5KziNIVsMjUmBcdTAwMGJHeVx1MDAwNCVRXjJcdTAwMDOc/3eIdKYsWTloXHUwMDE0SzKRRKZtW15gXHUwMDE28YiMt0dcdTAwMDCroFx1MDAwNaW8js94dMnc28b99fnz8+b9wcNcdTAwMDBsXHUwMDFmXz93ys0jynI8+qJLKZAuoTlcdTAwMWSPyCiPMFaBNVx1MDAxM/RbXHJcdTAwMTKnMiXa5zyaXHUwMDE3enRsrlx1MDAwZkEpXHUwMDA1QIhPXHI9r3Z9tb573ni4or2zXHUwMDE2pDJAwVO5ocdQmaAnXHUwMDE5wITLb1XgK1x1MDAwM1x1MDAxZVx1MDAxYVx1MDAwNzxIXHUwMDAxi1x1MDAxMqtg+izz4I+7M++FXFxetK+P+lx1MDAxN5hfmEe7d+VGXHUwMDFlLpfSI4hKrmTC3409uFx1MDAwMuyxsdhTXHUwMDEycKHe00PP6Z/Dm51d1NR73cub56t2d9BA5YZcdTAwMWUqldJDQEFcdTAwMGZcdTAwMTBcdTAwMGW/Xe0tXGZ6XHUwMDEzsodjkSekMphATFx1MDAwZrzLLdrqoVrtqbF3c8g3sNszN/g8wFtd7lx1MDAxMFx1MDAxMVCnRFx1MDAwMEFcYmBcdTAwMDBcYsAyOCRcdTAwMDDWKSeKglx1MDAxMkfnXHUwMDFhZPzR2lfCKVx1MDAwNbc6oVCtN5VYSlx1MDAxNTeNwjQnXGJcdTAwMTJcIlx1MDAwZluMXHUwMDE5wpCJWVx1MDAxNGZ5M4/Cfry8aVx1MDAxZYPnP/rk8FRcdTAwMGJEw6SFmcdcdTAwMWGqI6xiTKGWXHUwMDBl0fTRY2WYiqT1qFxuIMCQcqYpX3Ju8juPXHUwMDE5xmMpetVGYZRcZriW/ju7JpFjcy+MXHUwMDBizDmZQZWcuLe1n487XHUwMDBmbmOwsX990XVcdTAwMDdcdTAwMDLulluVcKVKXHUwMDE4XHUwMDA3XHUwMDFjSGU4XHUwMDE4S63GhyZh8VwiXGIkcCrdu1A9UmTfRj0rXHUwMDBlqNp5SGcxb+VVXHUwMDE06GC/tnHzpFx1MDAwM/chXHUwMDE0Pafv3dauvVwiRaH0XHUwMDA0XHUwMDEzKoBcdTAwMDRcbvtKV1xukGJGoihcdTAwMDRDiELIIeNqz+m/V1HUUmjJdZhKXHUwMDExjEvBSpEvXHUwMDFjxu9cdTAwMDRIXHUwMDA2XHSZPnU02VxilNOVJdnrXHUwMDAwXHUwMDA08jrNzb5cdTAwMTi2w1TAmmRhU3O931x1MDAwMVD84zJcdTAwMWRALMmZXHUwMDFk9vmVQtVUrmFcdTAwMDZXb1x1MDAwNmZY8/pcdTAwMDHGZaiYVIo3XHUwMDE1gXyS4vVNtYlcdTAwMTVDwVZcdTAwMGYjyKc2L8n2iky35Wd780LNZ8OV9zSWvFx1MDAxMKuVplx1MDAwME3P3v7dUyBOwV7jtr/Z2N37ea3vm85C2Wu4ka5d5mWCdFJkkfd3XHUwMDEwKzDVafE+YlFlqJTDXHUwMDA2ZrlOsNhQVCrHTiivclx1MDAwMSZ8iVx1MDAxN3syJ/4rs6FcItO8xj73zkG2h/i8XHUwMDA3y/ZQXHUwMDE4WZChhnisw66iXHUwMDA25Vx1MDAwNnFBpyf7ZDeslKaaXHUwMDAxVl+ZscZFV1x1MDAwZkaMtVQxmYDKWn+nsZ5cdTAwMWN8ZbA1l7H++nns9Mbatnpm2Wx1TqaJ5J2QM+Zjr+FcIoCZRFx1MDAxOMLpT8rOW3dcdTAwMDav3a3TXHUwMDEz0NZcdTAwMGX1l6NWy2Dlpi/PX3b43vNcbrXaKnLEaOl+9lwiyTWX4UBy/I1TICBiXHUwMDEwyOmv2ZBB293dxzW4KTY3+vfe+T5cdTAwMWOsl1x1MDAxYnkkd1xcQSYgj+qSXHUwMDAwY06jkTpcdTAwMGKfdM9cdTAwMDZRKCSB5DvPK6hcbuy/XHUwMDFjhE1/z0az7Yqm9GdP7VlFV+Gkb1x1MDAxYcXafdX3blxuJZuLZ+k7/iMn0lx1MDAxOFx1MDAwMElnuFx1MDAxNeqTzs+dLXpcdTAwMGaOLi5+ulx1MDAwN/624I2y+2c5XHUwMDA1XHUwMDBml3SbXHIhNkqz0ZvdKlx1MDAwMpZSuWasWMMnfHo5vL53sWj0xGbn+Fx1MDAwNKFds3fW+XCSVsRGRUbOVsbGTVWtpKpYnY5pWEpcdTAwMTT75U/HV9HXS6Xp+omv86ejOUYlVIxpmb6K/CpvaYuOXHUwMDE26m0zKOQvXTV/XHUwMDE39CxcdTAwMTNcdTAwMTnvqyFyed9cdTAwMTTtx16Aglx1MDAwNEOGuZjhXHUwMDA21ORcdTAwMGL8paQ9XHUwMDAxi6V9XHUwMDEzNlFcdTAwMTNcdTAwMTXQXHUwMDFlXHUwMDE0OHajtIdcZqlwWKpfX7Kuo0eOM8Vkj6y9t3HTdfX2Mdz1SHP7qbFfK47JYlJcdTAwMGUrXn9MXHUwMDFhdvK/+2SGnT3UU25cdTAwMTFMZcOX5I3isedcclx1MDAxMEBcdTAwMDR45Fx1MDAxNk9Nl8nLXFxSumRzXHUwMDE4UIqv5TBCX3NcdTAwMDJP81x1MDAxNSxcdTAwMGJcXFJZQJpUTviDNNFcdDSkY0xlSYOhXCJcdTAwMWI4fabh0tS7fuTzvVx1MDAxYpBib5Rn+k1vzTqWYaTNRdagfabm8zZuRNY35q2907mqed5lqFZzuCvVnmU+b1x1MDAxNCnX+Fx1MDAxNfWPNyliiFx1MDAxOW/m69rr31xm7NFgIn0=Future Past retro detection live detection all activity covered Content immediately ready for detection and triggering retro matches Security Content
This architecture decouples the arrival of new security content from the
execution of the detection. VAST runs in production with this use case for
detections in the form of tactical indicators. We are in the process of
extending this mechanism to more advanced stateful detections, e.g., Sigma
correlations or machine-learning models.
Check out our talk with DCSO at Suricon
2021 on how VAST supports this
architecture with Suricata telemetry and security content in the form of STIX
indicators.