Talk With an Expert

The Conductor Role in Security Automation and Orchestration

The Conductor Role in Security Automation and Orchestration (PDF, 3.55MB)Published: 22 Aug, 2017
Created by
Murat Cakir

Security Operations Centers (SOCs) are trying to handle hundreds of thousands of events per day and automating any part of their daily routines is considered helpful. Ultimately fast creation of malware variants produces different Indicators of Compromise (IOCs) and automated tasks should adapt themselves accordingly. This paper describes the possible use of automation at Threat Hunting, Identification, Triage, Containment, Eradication and Recovery tasks and phases of Incident Handling along with practical examples. Also describes how they can fail or can be systematically forced to fail when orchestration is missing. Orchestration should not only cover dynamic selection of proper paths for handling of specific tasks, but should also provide circumstantial evidence while doing that. Finally, there should be a Conductor who should know when and how to use the baton to accept, modify or reject any part of the automated flow.