[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: Re: [cti-cybox] Network Connection Object TCP Extension
Just as a point of fact (understanding full well that many of our use cases are not typical): We captured, processed, and stored 2-4 TerraBytes of External Ingress/Egress Raw Packet Data every day. As anyone who has dealt directly with entrenched Determined
Adversaries can tell you, investigations, forensics collection/analysis, reporting, etc. for a given event can extend from months to years. This is a massive amount of data that requires a lot of analysis to narrow it to manageable levels. A single 1 TB
LT-05 tape of raw packet data took 4 hours just to initially re-process (locally with high speed DAS/NAS storage).
Metadata drives effective analysis. Sharing of same drives effective community analysis. Along with the practical/physical limits of sharing raw packet data once you get to Enterprise scale, there are a number of Employee/Customer Privacy, IP Protection,
and Confidentiality considerations when sharing raw packet data. Where we do share this data once vetted (which can take quite a bit of time) the metadata helps us isolate which packets are relevant.
Again, understand this represents only a small overall portion of the community. However, 10GBs to 40Gbs pipes in our network cores and cloud infrastructures are increasingly the norm for many larger organizations.
Patrick Maroney
President Integrated Networking Technologies, Inc. Desk: (856)983-0001 Cell: (609)841-5104 Email: pmaroney@specere.org Yes, my Ultimate Data Exfiltration Toolkit mutilates headers from layer2 to layer7, but I see most of this information being captured in STIX with a pointer to a CybOX object that contains an artifact of a libpcap or libpcap-ng data blob.
Thanks,
Bret
Bret Jordan CISSP
Director of Security Architecture and Standards | Office of the CTO
Blue Coat Systems
PGP Fingerprint: 63B4 FC53 680A 6B7D 1447 F2C0 74F8 ACAE 7415 0050
"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."
|
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]