The Defense Information Systems Agency has revealed that it is developing unique cyber analytics to reinforce the protection of over 2.4 million users of the Defense Information Systems Network and around 600 cybersecurity service provider—a.k.a. CSSP—mission partners.
The agency said Wednesday CSSP Defensive Cyberspace Operations analysts are building customized tools or analytics to monitor data from network traffic, system logs and intelligence sources. These frequently updated analytics, when deployed to Security Information and Event Management systems, create alerts pinpointing potential cyberthreats or system vulnerabilities.
Table of Contents
Enhancing Cyber Defense Through Tagging & Collaboration
A key component of the DISA CSSP analytics is the disciplined use of metadata tagging, which allows analysts to monitor for advanced threat indicators. With the addition of detailed information to each analytic, analysts can deploy the right tools to combat large datasets and different formats.
DISA’s Cyber Analytics Users’ Group
The Cyber Analytics Users’ Group fosters collaboration by enabling cybersecurity teams to explain new detection analytics, share concepts, troubleshoot problems and avoid duplicate work. The CAUG uses a disciplined tagging approach to continue creating baseline analytics for specific missions. This bolsters the cyber defense of the DISN and its mission partners.