Palo Alto Networks’ internal security operations center (SOC) ingests more than 36 billion events and 75 terabytes of data per day, yet it’s run by only 10 analysts. The company’s SOC Operations Specialist Devin Johnstone explained their '30/30/30” working model and how they leverage new artificial intelligence (AI)-powered cybersecurity technologies to handle the workloads of about 16 analysts for them.
Created around 2017, Palo Alto Networks’ internal SOC comprises 22 full-time employees, including those 10 analysts responsible for security alerts, incident response and threat hunting. The rest of the team is on the engineering side who configure and maintain cybersecurity tools that enable those analysts. The team is responsible for protecting the security giant’s own infrastructure and employees, Johnstone told SDxCentral.
He added these SOC analysts follow what Palo Alto Networks calls the 30/30/30 model:
- Up to 30% of their day is spent reactively responding to alerts.
- Another 30% is dedicated to proactive threat hunting based on threat intelligence.
- The remaining time is used to create new detection and automation use cases, suggest tuning for existing use cases, and provide product feedback and professional development like optional training.
“The SOC analysts are split between two locations: six in the U.S. and four in Tel Aviv,” Johnstone noted, adding they work a normal eight-hour business day, so between the two teams there are 16 hours of human coverage per day across six days per week (The weekend in Tel Aviv is Friday and Saturday).
Palo Alto Networks SOC taps the power of automationWhat about the remaining eight hours in the day and the Saturdays? The gap is bridged by Cortex XSOAR — Palo Alto Networks’ own security orchestration automation and response (SOAR) platform, according to Johnstone.
“All 10 SOC analysts do the same kind of work. We haven't separated them into ‘tiers’ or ‘levels’ like some organizations because most of the ‘tier 1’ work is given to Cortex XSOAR, which performs automatically,” he noted. “100% of alerts have some kind of automation: 15% are fully automated end-to-end and the remaining 85% have partial automation to help them along with input from analysts.”
Currently, Palo Alto Networks SOC receives about 36 billion events per day, which is “36 times the volume of data that we need to analyze just since the year 2020,” Johnstone said. The tools, such as XSOAR and automation capabilities from Cortex XSIAM, help bring that number down to an average of 133 events.
“For 10 analysts that 130 is very manageable,” he added. “XSOAR automation is doing about 16 analysts worth of work for us. So we've got a team of 10 analysts who are essentially supported by this other SOC of 16 which is the tool."
“Our major goal today is looking at all of the activities we do every single day and figuring out what's the next thing we can automate, that's repetitive and doesn't require human input to free up the SOC analysts’ time,” Johnstone said.
Consolidating SOAR and SIEMThe two major tools that Palo Alto Networks SOC analysts are using are Cortex XSIAM and XSOAR. The team has replaced its traditional security information and event management (SIEM) tool with the XSIAM platform, which stands for extended security intelligence and automation management.
“The advantage is now we're getting a lot more in-depth data on the detection side before it even gets into XSOAR in the SOC,” Johnstone said. “XSIAM is gathering data from all our log sources, network endpoint, and cloud whether they're from Palo Alto Networks’ own platform or third parties. It captures everything, applies machine learning, and then builds what we call a complete attack story from beginning to end.”
The team currently spends about 80% of their time in XSOAR and sometimes goes over to XSIAM to do threat hunting and configure detections.
To consolidate and simplify security operations, the SOC team is actively moving automation from XSOAR into XSIAM, so they have one less tool to maintain. And the XSIAM product team also aims to build a “one-stop shop” for all the SOC teams, according to Johnstone.
“XSIAM also includes the ability to do a lot of that automation itself, so we're undergoing our own transformation to see which automation playbooks we can take out of XSOAR and put them into XSIAM. And maybe one day when we retire XSOAR we have just one tool that does everything,” he said.
Additionally, “XSIAM is also able to start recommending automation. This is my new favorite term — automating the automation — coming up with response automation based on what the analysts are doing and then suggesting to them,” Johnstone added.
Photo: Screenshot of Palo Alto Networks SOC 3D scan. Source: Palo Alto Networks
Comments