• Level: APP-ING3
  • Semester: S10
  • Duration: 15h
  • Language: Fr
  • Teacher: Pierre Parrend

Summary

Security alert handling is performed by Security Operating Centers, or SOCs. A SOC operates technical alert-raising systems (IDS, SIEM) to analyze alerts, react to attacks, and prevent their recurrence. SOCs are associated with 3 levels of intervention: 1) handling of routine alerts; 2) alert analysis; 3) in-depth analysis and risk and threat management.

Objectives

After completing this module, students will be able to:

  • Deploy, configure, and set up SOC technical tools
  • Define and carry out level 1 operations
  • Design and plan level 2 and level 3 operations
  • Conduct a case study from the first symptoms to the implementation of long-term countermeasures, covering analysis and incident response

Lecture outline

  • SOC architecture
  • SOC tools
    • IDS
    • SIEM
  • Level 1 operations — operator: raising alerts, performing an initial diagnosis
  • Level 2 operations — security analyst: performs detailed alert analysis, communicates with relevant teams, supports incident handling, implements simple remediations
  • Level 3 operations — security experts: perform in-depth analysis; create and maintain the risk analysis framework; create and maintain a threat case catalogue

References

  • Blue Team Field Manual (BTFM), Alan J White, Ben Clark
  • Blue Team Handbook: SOC, SIEM, and Threat Hunting (V1.02): A Condensed Guide for the Security Operations Team and Threat Hunter, Don Murdoch
  • The Modern Security Operations Center, Joseph Muniz
  • Aligning Security Operations with the MITRE ATT&CK Framework: Level up your security operations center for better security, Rebecca Blair