NIST CSF · Domain 3
Detect
About 20% of the exam
Detect categories in 2.0
- DE.CM
- continuous monitoring
- DE.AE
- adverse event analysis
- Retired
- detection processes folded into these
- DE.CM covers
- networks, people, services, hardware, software
- DE.AE covers
- correlation, impact, escalation, declaration
- Outcome
- find the event and understand it
- Boundary
- declaring an incident starts Respond
Detect ends the moment an incident is declared; everything that happens after that belongs to Respond
Event versus incident
- Observable event
- Alert raised
- Triage
- Correlation
- Impact estimated
- Threshold met
- Incident declared
- Event
- any observable occurrence
- Adverse event
- an event with negative consequence
- Alert
- a notification worth looking at
- Incident
- adverse event needing a response
- Threshold
- the criteria for escalating
- False positive
- an alert with no real cause
Building a baseline
- Learn normal traffic and behavior
- Baseline before anomaly detection works
- Include the expected data flows
- Refresh after significant change
- Seasonality distorts a short baseline
- Unbaselined environments generate noise
What to monitor
- Wired, wireless, remote and cloud networks
- Endpoint and server activity
- Privileged account use above all
- External service provider activity
- Physical access to facilities
- Unauthorized personnel, devices and software
Detection sources
- SIEM
- correlates events across many sources
- EDR
- endpoint behavior and process activity
- IDS
- detects and alerts only
- IPS
- detects and can block
- Flow data
- traffic patterns without payload
- DNS logs
- beaconing and exfiltration signals
- Threat intelligence
- known indicators to match against
Alert fatigue
- Tune rules to the environment
- Suppress known benign patterns
- Prioritize by asset and impact
- Automate triage of repeat alerts
- Measure the false positive rate
- Volume without triage hides real attacks
Analysis techniques
- Correlate across time and source
- Compare against the known baseline
- Pivot from indicator to related activity
- Fingerprint encrypted sessions where possible
- Watch volume anomalies for exfiltration
Log retention
- Retention must exceed likely dwell time
- Short retention hides long intrusions
- Central collection resists tampering
- Clocks synchronized across all sources
- Integrity protection on stored logs
Coverage gaps
- Cloud control plane left unmonitored
- Service accounts excluded from rules
- Built in system tools ignored
- Third party access outside visibility
- Physical events never correlated digitally
Measuring detection
- Time to detect
- how long attackers stay unseen
- Coverage
- share of tactics with detections
- Alert precision
- true positives over all alerts
- Escalation time
- alert to triage elapsed time
- Dwell time
- intrusion start to discovery
- Test method
- purple team and detection engineering
A rising time to detect is a trend to investigate, not a number to explain away in the monthly report
Where the 1.1 detect categories went
- DE.AE
- still adverse event analysis
- DE.CM
- still continuous monitoring
- DE.DP
- absorbed into the other two
- Baselines
- now inside adverse event analysis
- Thresholds
- still an explicit outcome
Rapid recall: detect terms
- Event
- something observable happened
- Adverse event
- an event with harm potential
- Incident
- declared, so response begins
- Indicator
- artifact suggesting a compromise
- Baseline
- the expected normal pattern
- Threshold
- the agreed escalation trigger
Reference strip: monitor, baseline, analyze, escalate, measure
Monitor
- Networks, endpoints, cloud, people
- Privileged accounts always included
- Physical and provider activity too
Baseline
- Normal traffic and behavior learned
- Refreshed after significant change
- Anomalies mean nothing without it
Analyze
- Correlate across sources
- Estimate scope and impact
- Pivot on indicators
Escalate
- Thresholds defined in advance
- Triage before declaration
- Declaration hands over to Respond
Measure
- Time to detect and dwell time
- Coverage across attacker tactics
- False positive rate tracked
Quick exam traps
- Trap: An intrusion prevention system only alerts and never blocks
- Trap: Any security event is by definition an incident
- Trap: Anomaly detection works without an established baseline
- Trap: More alerts means better detection coverage
- Trap: Ninety days of logs is always enough for an investigation
- Trap: Detect includes containing the attacker once found
cybercertprep.com · original revision sheet written from the public body of knowledge