IT2 мин. чтения

Surviving the Age of Myths: Richard Bejtlich on Network Threat Analysis

Richard Bejtlich redefines network threat analysis by emphasizing full attack chain reconstruction and eliminating blind spots in NDR systems.

Modern Network Detection and Response (NDR) systems face an effectiveness crisis. Despite abundant telemetry, SOC teams often struggle to answer basic incident investigation questions. Cybersecurity expert Richard Bejtlich proposes a methodology to overcome these limitations.

The Data Analysis Crisis in Cybersecurity

SOC teams process thousands of alerts daily, yet many go unaddressed. The issue isn't data scarcity but fragmentation. Traditional alerts lack sufficient attack context.

  • Abundant telemetry doesn't guarantee threat visibility
  • Unprioritized alerts create processing bottlenecks
  • Missing cross-correlation leads to fragmented threat perception

The Blind Spot Problem in NDR

Modern NDR systems generate numerous alerts, but many are false positives. Real attacks blend into legitimate activity noise, complicating detection.

  • Blind spots emerge from poor data source integration
  • APT attacks often go unnoticed without context
  • Manual alert triage causes response delays

Bejtlich's Methodology

Richard Bejtlich advocates reconstructing complete attack kill chains instead of isolated alert analysis. His approach involves:

  1. Using timestamps to assemble attack sequences
  2. Verifying evidence through multiple data sources
  3. Integrating NDR, EDR and SIEM system data

Investigation Failure Case Studies

Failed investigations reveal common SOC team mistakes, including APT false negatives and recurring incidents from unaddressed IoCs.

ProblemImpactSolution
False negativesUndetected attacksUEBA implementation
Manual triageResponse delaysSOAR automation
Unidentified IoCsRepeat incidentsNDR-SIEM integration

Technological Solutions

To eliminate NDR blind spots, Bejtlich recommends UEBA platforms for behavioral analysis, SOAR for evidence automation, and graph databases for relationship mapping.

Actionable Recommendations

Key threat analysis improvements include creating raw network log repositories, conducting attack reconstruction drills, and integrating NDR with EDR/SIEM systems.

Questions & Answers

Why do traditional SIEMs fail against modern threats?

Legacy SIEMs focus on alerts rather than attack context, limiting effectiveness against sophisticated threats.

How to distinguish real attacks from NDR false positives?

Analyze multiple data sources while correlating event timestamps.

Which organizations face greatest threat analysis gaps?

Highly digitized companies with substantial network traffic face maximum risk.

How long does complex attack reconstruction take?

Depending on attack scale and data availability, this may require hours to days.

What skills do analysts need for advanced NDR platforms?

Analysts require big data expertise, network protocol knowledge, and incident investigation experience.