How to Secure Big Data Across Large Environments

536 views
•
April 8, 2014
by
RSAC Cybersecurity
YouTube video player
How to Secure Big Data Across Large Environments

TL;DR

Secure large data environments by monitoring behavior across the whole system, identifying anomalies early, keeping adequate records, evaluating changes daily, and adapting treatment. Big data improves security analysis through faster processing, centralized data lakes, and broader source access, but the collected data must itself be protected because it supports security judgments and may be exposed to leaks or loss.

Transcript

Thank you. Thank you. So today's presentation is called Securing the Big Data Ecosystem, and it really comes from two places. One, what is really different about big data? I get asked this all the time. Is it something new and distinct? Can we use the same old tools we used before? And then based on that answer, the second part is really, what are ... Read More

Key Insights

  • Big data is different from traditional data environments because automated processes create faster ingestion, larger accumulations, centralized data lakes, and broader access to information sources. Existing security knowledge remains useful, but it must be applied through controls designed for this changed scale and structure.
  • The cattle analogy treats servers as valuable assets that require systematic care. Organizations managing tens of thousands of servers cannot provide individualized attention to each machine, yet simply destroying every unhealthy server makes little sense when structured detection, quarantine, treatment, and recovery are possible.
  • The ERM model emphasizes actions that are easy, routine, and require minimal judgment. Such controls can be applied consistently by people who may not understand every technical detail, making them suitable for treating recurring problems across a very large and heterogeneous computing environment.
  • The IKEA model consists of identifying unhealthy servers as early as possible, keeping adequate records, evaluating their condition daily, and adapting the response. Logging provides a trail of activity, while repeated evaluation reveals changes that inform efforts to return systems to a healthy state.
  • System-wide behavioral monitoring can identify compromised systems without requiring each endpoint to recognize and report its own illness. Analysts observe activity across the environment, detect changes in one system, trace possible spread to others, and decide which machines require quarantine and closer examination.
  • John Snow's cholera investigation demonstrates that mapping movement, outcomes, and exceptions can reveal a hidden source of harm. The absence of deaths among people using a different water source was informative, showing that security analysis should consider missing events as well as observed incidents.
  • A data lake can support breach investigation by combining information from across an environment. Analysts can examine the total collection, locate the apparent source of an infection, observe the data points through which it spreads, and construct a map of the compromise.
  • The data used for security judgments must itself be protected. Faster ingestion, centralized analysis, and trusted access to information from many sources increase analytical capability, but saving more information also raises concerns about leaks, loss, access protection, and compliance requirements.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should organizations secure a large big data environment?

Organizations should use systematic controls that work across the entire environment. The proposed process is to identify unhealthy servers early, keep adequate records of their activity, evaluate their condition daily, and adapt the response. Broad behavioral monitoring and centralized analysis can reveal sources and patterns of spread, while the underlying data must also receive protection against leaks, loss, and inappropriate access.

Q: Why is big data security different from traditional security?

Big data environments ingest and process information faster, collect much larger quantities, and place information from many sources into large repositories or data lakes. Traditional environments relied more heavily on slower processes and isolated analysis. Although established security knowledge still applies, controls must accommodate the increased scale, centralized analysis, heterogeneous distribution, multiple users and purposes, and the need to protect the collected data itself.

Q: What does the cattle analogy mean for server security?

The analogy means that servers in a large environment should be managed as valuable assets through systematic care. Treating every server like an individually named pet does not scale to tens of thousands of machines. However, immediately destroying every unhealthy server is also inappropriate. A better approach uses routine treatment, behavioral observation, quarantine when necessary, adequate records, and adaptable measures intended to restore systems to health.

Q: What is the IKEA model for securing servers?

The proposed IKEA model means identifying sick servers as soon as possible, keeping adequate records, evaluating them daily, and adapting the response. Identification finds systems that appear unhealthy, recordkeeping preserves a log of their behavior, daily evaluation detects change, and adaptation adjusts treatment. Together, these steps create a repeatable process for handling problems across an environment containing many servers.

Q: How can a data lake help investigate a security breach?

A data lake brings information from across an environment into one place for analysis. By examining the total collection, investigators can look for the source of an infection, observe the data points through which it appears to spread, and build a map of the incident. This broader view differs from relying on each endpoint to recognize its own compromise and request assistance.

Q: Why is John Snow's cholera investigation relevant to cybersecurity?

John Snow investigated cholera by mapping deaths, examining how people moved toward water pumps, and comparing affected groups with exceptions. The absence of deaths among people using another source helped distinguish the suspected cause. Applied to cybersecurity, this method suggests analyzing system-wide activity, tracing the path of compromise, identifying its source, and treating missing events or unaffected groups as meaningful evidence.

Q: Why is endpoint monitoring alone insufficient for big data security?

Endpoint monitoring depends on each individual machine recognizing that it is unhealthy and reporting the problem. In a large environment, broader observation can instead detect behavioral changes across many systems, identify one machine that may be affecting others, and support quarantine and investigation. This system-wide perspective helps analysts trace relationships and patterns that an isolated endpoint may not recognize on its own.

Q: What risks arise when organizations save and centralize more data?

Saving and centralizing more information creates stronger analytical capability because organizations can process data faster, combine sources, and examine a wider environment. It also increases the consequences of leaks or loss and creates requirements for multi-user, multi-purpose access protection and compliance management. Because security decisions depend on this information, organizations must protect the data used to produce those judgments.

Summary & Key Takeaways

  • Big data differs from older environments because automated processes ingest information faster, gather much larger volumes, and consolidate it in data lakes. Security practices must therefore shift away from individually tending every server and toward systematic controls that can operate across tens of thousands of servers with minimal routine judgment.

  • The proposed IKEA model calls for identifying sick servers quickly, keeping adequate records of their activity, evaluating them daily, and adapting the response. Combined with easy, routine controls requiring minimal judgment, this approach lets large organizations detect behavioral changes, understand causes, apply treatments consistently, and restore systems to health.

  • John Snow's cholera investigation illustrates how broad data analysis can reveal an infection source and its path of spread. Security teams can similarly examine data across an environment, notice both suspicious events and meaningful absences, locate the source of compromise, quarantine affected systems, and avoid depending solely on endpoint self-reporting.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚