- Level: APP-ING3
- Semester: S10
- Duration: 15h
- Language: Fr
- Teacher: Pierre Parrend
Summary
Security alert handling is performed by Security Operating Centers, or SOCs. A SOC operates technical alert-raising systems (IDS, SIEM) to analyze alerts, react to attacks, and prevent their recurrence. SOCs are associated with 3 levels of intervention: 1) handling of routine alerts; 2) alert analysis; 3) in-depth analysis and risk and threat management.
Objectives
After completing this module, students will be able to:
- Deploy, configure, and set up SOC technical tools
- Define and carry out level 1 operations
- Design and plan level 2 and level 3 operations
- Conduct a case study from the first symptoms to the implementation of long-term countermeasures, covering analysis and incident response
Lecture outline
- SOC architecture
- SOC tools
- IDS
- SIEM
- Level 1 operations — operator: raising alerts, performing an initial diagnosis
- Level 2 operations — security analyst: performs detailed alert analysis, communicates with relevant teams, supports incident handling, implements simple remediations
- Level 3 operations — security experts: perform in-depth analysis; create and maintain the risk analysis framework; create and maintain a threat case catalogue
References
- Blue Team Field Manual (BTFM), Alan J White, Ben Clark
- Blue Team Handbook: SOC, SIEM, and Threat Hunting (V1.02): A Condensed Guide for the Security Operations Team and Threat Hunter, Don Murdoch
- The Modern Security Operations Center, Joseph Muniz
- Aligning Security Operations with the MITRE ATT&CK Framework: Level up your security operations center for better security, Rebecca Blair
