BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Connecting the Dots: Mastering Alert Correlation for
  Proactive\n   Defense in the Cloud\n   When: Saturday\, Aug 10\, 13:50 - 
 15:50 PDT\n   Where: LVCC West/Floor 1/Hall 2/HW2-09-01 - [1]Map\n\n   Des
 cription:\n\n   Interpret the vast amount of alerts (from different source
 s) received\n   with a comprehensive\, hands-on autonomous attack correlat
 ion & false\n   positive detection workshop designed to enhance your proac
 tive defense\n   in the cloud. The workshop aims to demystify the process 
 of\n   identifying coordinated attacks amidst this noise\, empowering\n   
 attendees to improve their efficacy & utilize the cloud\n   cost-effective
 ness.\n\n   No data science expertise is required. Little cloud & secops e
 xpertise\n   is required.\n\n   Intro: - The session begins with a foundat
 ional overview of event\n   analysis challenges and state of the art. - Pa
 rticipants will learn\n   about the ATT&CK framework\, focusing on its Flo
 ws\, Tactics\, &\n   Techniques to standardize threat detection.\n\n   AI 
 & Data: - A deep dive into accessible open-source AI tools will\n   follow
 \, featuring clustering algorithms\, natural language processing\,\n   & M
 arkov chains. - Guidance on importing\, cleaning\, & normalizing data\n   
 will ensure accuracy in subsequent analyses. - Participants will have\n   
 access to a demo environment to apply these tools interactively.\n\n   Map
 ping Alerts: - Techniques for automated mapping of alerts to ATT&CK\n   wi
 ll be demonstrated. - Attendees will engage in mapping exercises\n   using
  AI.\n\n   Clustering Alerts: - The workshop will cover clustering methods
  based\n   on temporal\, spatial\, & technical attributes. - Participants 
 will\n   engage in clustering sample alerts to form contextualized attack\
 n   steps.\n\n   Correlating Alerts: - The importance of killchains in cyb
 ersecurity\n   will be highlighted\, with methods to link attack steps int
 o cohesive\n   killchains. - Participants are guided in creating & analyzi
 ng\n   killchains to identify coordinated attacks.\n\n   Tickets: - Criter
 ia for creating FP Tickets\, Incident Tickets\, &\n   Attack Story Tickets
  will be outlined. - Participants will engage in\n   generating sample tic
 kets\, ensuring each type is comprehensive &\n   actionable.\n\n   Integra
 ting & QA: - The session will cover integration into existing\n   SOC setu
 ps & automation using scripts & tools. - Demonstrations will\n   show how 
 to maintain & update the system for continuous improvement\,\n   emphasizi
 ng cost-effective cloud automation. - QA\, troubleshooting\, &\n   further
  resources.\n\n   By the end of this interactive workshop\, participants w
 ill have\n   experience with AI tools mapping alerts to Techniques\, clust
 ering them\n   into contextualized attack steps\, & constructing comprehen
 sive\n   killchains to uncover coordinated attacks. Additionally\, they wi
 ll\n   learn to generate actionable tickets for immediate response &\n   l
 ong-term improvements in their security posture\, all without needing\n   
 advanced data science knowledge. This session encourages practical\n   app
 lication in participants' environments & further exploration of the\n   va
 st capabilities of open-source AI in cybersecurity\, & showcases the\n   p
 ower of cloud cost-effectiveness in big data analytics (sagemaker\,\n   s3
 \, lambda\, etc.).\n\n   SpeakerBio:  Ezz Tahoun\n\n   Ezz Tahoun\, a dist
 inguished cyber-security data scientist\, who won AI\n   & innovation awar
 ds at Yale\, Princeton and Northwestern. He also got\n   innovation awards
  from Canada’s Communications Security\n   Establishment\, Microsoft US\
 , Trustwave US\, PIA US\, NATO\, and more. He\n   ran data science innovat
 ion programs and projects for OrangeCyber\n   Defense\, Forescout Technolo
 gies\, Royal bank of Canada\, Governments\,\n   and Huawei Technologies US
 . He has published 20 papers\, countless\n   articles and 15 open source p
 rojects in the domain. When he was 19\n   years old he started his CS PhD 
 in one of the top 5 labs in the world\n   for cyber & AI\, in the prestigi
 ous University of Waterloo\, where he\n   published numerous papers and be
 came a reviewer for top conferences.\n   His designations include: SANS/GI
 AC-Advisory-Board\, aCCISO\, CISM\,\n   CRISC\, GCIH\, GFACT\, GSEC\, CEH\
 , GCP-Professional-Cloud-Architect\, PMP\,\n   BENG and MMATH. He was an a
 djunct professor of cyber defense and\n   warfare at Toronto’s school of
  management.\n\n   '\n\n   1. #LVCCW_Level1_Hall2\n\n\n
DTEND:20240810T225000Z
DTSTART:20240810T205000Z
LOCATION:CLV - LVCC West/Floor 1/Hall 2/HW2-09-01
SUMMARY:Connecting the Dots: Mastering Alert Correlation for Proactive Defe
 nse in the Cloud
END:VEVENT
END:VCALENDAR
