SIEM Consulting for an Oil Company

SIEM Consulting for an Oil Company

Industry
Oil & Gas

Summary

After a malicious virus spread across its network and infected many workstations, a global petroleum and chemicals enterprise set out to understand what went wrong and harden its defenses. Over a 9-month project, INNERLUXES enhanced the company's Juniper STRM SIEM — fixing architecture and correlation-rule issues, connecting all log sources (including unsupported ones), and building new threat cases and automation tools to detect and respond to malicious activity across its vast enterprise network.

About the Client

The Client is a global petroleum and chemicals enterprise with operations across the world, involved in exploration, production, refining, distribution, shipping, and marketing.

The Challenge

A malicious virus from external sources spread throughout the company's network and infected many workstations. After recovering from the incident, the Client decided to define what had gone wrong and what changes would help avoid massive damage from future attacks. The Client chose Juniper STRM as its SIEM solution to collect, log, correlate, and analyze security events across its vast enterprise networks, and its information security experts turned to INNERLUXES for SIEM consulting and custom SIEM architecture enhancement.

The Solution

After a thorough analysis, INNERLUXES identified a number of vulnerabilities in the system's architecture. The initial deployment had produced many invalid and useless correlation rules and damaged the correlation rules editor, so the SIEM product needed adjusting and new correlation rules capable of detecting threats in the network infrastructure's behavior. All log sources — including unsupported ones — also needed connecting to realize the SIEM solution's full potential.

For SIEM architecture enhancement, INNERLUXES recommended extending the security policy for better coverage of the company's infrastructure, assessed the incident management process, analyzed the correlation rules, and provided recommendations for SIEM customization, which were presented for the Client's approval.

In the second phase, INNERLUXES designed advanced threat cases for the Unix and Linux platforms, including an audit baseline for each platform, and developed a tool for importing and exporting the asset database to allow easy mass updates of the assets identified in the network infrastructure.

The extended enterprise-wide security policy was converted into a set of correlation rules and successfully implemented. For better response to malicious activities, INNERLUXES developed and connected new log sources, with security events parsed, normalized, and mapped. A dedicated framework was also created for integration with vulnerability scanners not supported out of the box, and the SIEM solution was customized with a number of scripts and tools. Finally, INNERLUXES provided recommendations for audit configuration as part of the information transfer.

The Results

  • The Client received a set of detailed reports covering its infrastructure, business processes, and dependencies, along with recommendations for SIEM architecture enhancement.
  • INNERLUXES carried out the SIEM product customization, delivering a set of connected log sources (including previously unsupported ones) and new, implemented correlation rules.
  • The consultants made valuable recommendations on audit and operating-system configuration. The project lasted 9 months and was mostly performed on the Client's side.

Sizing

  • Average events per second volume: 11,000.
  • Total number of log sources: 1,200.
  • Log sources developed: 25.
  • Threat cases created: 250.

Technologies and Tools

RegExp, Python, Perl, SQL, Shell, Batch.