SIEM Consulting for a Cloud Security-as-a-Service Provider
Summary
A US-based provider of a cloud-based, multi-tenant security-as-a-service (SECaaS) solution decided to develop its own proprietary SIEM tool but found it challenging to build the logic and correlation rules needed for the system to function properly. INNERLUXES's SIEM cloud-security consultants elaborated the logic from the ground up, developing 120+ correlation rules in two months that met 18 of 20 CIS Critical Security Controls — enabling a successful launch of the solution.
About the Customer
The Customer is a US-based provider of a cloud-based, multi-tenant security-as-a-service solution. The company monitors, analyzes, and protects enterprises of all sizes — ensuring intrusion detection, vulnerability assessment, web application protection, log management, and threat research along with advanced analytics.
The Challenge
The Customer decided to develop a proprietary SIEM tool that would allow end clients to detect threats, manage vulnerabilities, ensure web security, and more. Having a precise vision of the future solution, the Customer nonetheless found it highly challenging to build up the logic and create correlation rules that could ensure the proper functioning of the system. For this, the Customer was looking for SIEM cloud-security consultants who could help elaborate the logic from the ground up to be applied to the solution.
The Solution
Among multiple SIEM cloud-security consulting companies, the Customer chose INNERLUXES for its information-security expertise.
To solve the task, INNERLUXES's team followed best practices and recommendations in SIEM cloud security introduced by the information-security experts of the SANS Institute — namely the CIS Critical Security Controls, a recommended set of actions for cyber defense that provide specific, actionable ways to detect the most pervasive and dangerous attacks.
Sticking to the Customer's requirements, in just two months INNERLUXES developed more than 120 correlation rules that met 18 of 20 possible CIS Critical Security Controls. The rules were designed for platforms such as Cisco ASA, NetScreen, FireEye, Oracle, and IronPort, among others, to ensure the extensive functionality of the solution in the works.
The Results
- Applying the logic developed by INNERLUXES's cloud-security consulting team, the Customer successfully launched its proprietary SIEM solution.
- The solution went on to be used by a large global client base.
Technologies and Tools
SIEM, CIS Critical Security Controls, correlation rules; supported platforms including Cisco ASA, NetScreen, FireEye, Oracle, and IronPort.