flâneur

How Google Security Operations enriches event and entity data | Google Cloud

cloud.google.com · 1,794 words · saved by 1 readers

This document describes how Google Security Operations enriches data and the Unified Data Model (UDM) fields where data is stored. To enable a security investigation, Google Security Operations ingests contextual data from different sources, performs analysis on the data, and provides additional context about artifacts in a customer environment. Analysts can use contextually enriched data in Detection Engine rules, investigative searches, or reports. Google Security Operations performs the following types of enrichment: Enriched data from WHOIS, Safe Browsing, GCTI Threat Intelligence, VirusTotal metadata, and VirusTotal relationship are identified by event_type, product_name, and vendor_name. When creating a rule that uses this enriched data, we recommend that you include a filter in the rule that identifies the specific enrichment type to include. This filter helps improve performance of the rule. For example, include the following filter fields in the events section of the rule that

강화 구성 다음에서 지원: 강화는 다음 방법을 사용하여 통합 데이터 모델 (UDM) 표시기 또는 이벤트에 컨텍스트를 추가합니다. 일반적으로 UDM 필드인 지표를 설명하는 별칭 항목을 식별합니다. 식별된 별칭 또는 항목의 추가 세부정보로 UDM 메시지를 채웁니다. UDM 이벤트에 GeoIP, VirusTotal과 같은 전역 보강 데이터를 추가합니다. 이벤트 보기 이벤트 뷰어의 이벤트 필드 탭에서 이벤트를 확인합니다. 이 탭에는 선택됨이라는 라벨이 지정된 계층적 트리 구조로 UDM 이벤트 필드가 표시됩니다. 각 UDM 필드에는 필드에 보강 데이터나 보강되지 않은 데이터가 포함되어 있는지 여부를 나타내는 아이콘으로 라벨이 지정됩니다. 아이콘 라벨은 다음과 같습니다. U: 보강되지 않은 필드는 정규화 프로세스 중에 원본 원시 로그에서 값을 직접 가져옵니다. E: 보강된 필드에는 Google SecOps에서 환경의 아티팩트에 대한 추가 컨텍스트를 제공하기 위해 생성한 값이 포함됩니다. 강화된 필드에는 검증, 문제 해결, 감사, 규정 준수에 도움이 되도록 연결된 모든 소스가 표시됩니다. 또한 보강 소스별로 필터를 적용하여 보기를 세부적으로 조정할…

related reading