November 22, 2017
-
Anissa Khalid
,

10 Reasons to be Thankful for a Security Analyst

<p>The global number of internet users hit 3.8 billion in 2017, and is expected to reach <a href="https://www.csoonline.com/article/3153707/security/top-5-cybersecurity-facts-figures-and-statistics-for-2017.html" target="_blank">6 billion by 2022</a>. We’re rapidly approaching the point where people without access to the internet will be in the minority, and where the internet is not only accessible but also ingrained into daily life. Succinctly stated, this is a pretty exciting time for humans.</p><p>However, with these technological advancements also comes the sobering realization that more access for the layman means more access for cyber criminals. These people are responsible for <a href="https://www.csoonline.com/article/3197582/leadership-management/ransomware-damages-rise-15x-in-2-years-to-hit-5-billion-in-2017.html" target="_blank">over $5 billion in damages</a> in 2017 alone, as well as countless other non-financially related incidents.</p><p>Luckily, we have people out on the front lines already - Security Analysts. The title covers a range of specific job functions, but each one contributes in some way to the defense of individuals, organizations, and nations. This Thanksgiving we’d like to give thanks to these hardworking individuals. There are as many reasons to be thankful for an analyst as there are threat alerts in a day, but for the sake of brevity here are ten of our favorites:</p><p><strong>1) They’re incredible detectives</strong> - Working as an analyst is a mix of technical research, intelligence analysis, and communicating results. They’re responsible for investigating tiny, seemingly inconsequential clues so they can piece together a larger underlying scheme. All of this depends on a strong foundational core of deductive reasoning and logical rigor. They’re the modern-day Sherlock Holmes.</p><p><strong>2) They’re great researchers</strong> - Security analysts have a penchant for attention to detail, problem solving, and thorough research. Much of this work may take place on their own time and dime, but it’s critical in helping to spur technological innovations and identifying areas that need improvement. Researchers Billy Rios and and Jonathan Butts published findings this year identifying how to <a href="https://www.blackhat.com/docs/us-17/wednesday/us-17-Rios-When-IoT-Attacks-Understanding-The-Safety-Risks-Associated-With-Connected-Devices-wp.pdf" target="_blank">weaponize a car wash</a>, proving that even the most unsuspecting of items can be dangerous.</p><p><strong>3) They balance between two worlds</strong> - Working as an analyst doesn’t just mean understanding what’s going on in the security stack. It also means being able to effectively communicate critical events to executives and security leadership like CISOs. This can be a challenge considering the general lack of understanding not only for security best practices but also for core aspects of the internet and technologies themselves. There’s no Google translate for tech (yet).</p><p><strong>4) Their work never, ever ends</strong> - One of the key functions of a security analyst is to triage as many alerts as possible in a day to determine whether they’re benign or truly dangerous. Sounds easy enough, right? Perhaps, were it not for the fact that these alerts come in the thousands each and every day. No matter how many tools you deploy and staff you employ, your analysts are volunteering to deal with more red flashing lights than America sees at any given Christmas. Alerts aren’t the end of it though - other tasks include conducting research for customers to determine what’s going on in their infrastructure, hiding in underground forums gathering information, or working to piece together security programs.</p><p><strong>5) They operate under pressure</strong> - Speaking of triaging events, there’s a constant pressure to catch each and every malicious event. Any deescalated alert may prove to be the one that lets a threat actor in. On the flip side, any false positive may be wasting someone’s time. It’s a constant balancing act. No matter if your organizations is large or small, the target or the gateway, or simply collateral damage in a global attack, your analysts know that they’re going to be held accountable for the eventual impact.</p><p><strong>6) They work crazy hours</strong> - Security analysts aren’t likely to get a lot of sleep. Hours can be painful, particularly if you’re at a security center operating on a 24x7 schedule. Research and requests for information typically have tight turnaround schedules due to the unknown nature of threats. Any investigation is also unlikely to have a clear “end,” because there’s always the possibility that something was missed. More alarming still is the possibility that on any given workday a zero-day exploit could occur, in which case they’re really not going to get to go home and sleep.</p><p><strong>7) They’re vocationally oriented</strong> - It’s not about the money. Cybersecurity as an industry is vastly underfunded and even more understaffed. Ask an analyst why they’re in the industry and the response will typically be “because they’re passionate about what they’re doing.”</p><p><strong>8) They’re crime fighters</strong> - Analysts sign up to deal with crazy hours, pressure, and task lists because they’re truly passionate about finding evil and stopping bad guys. Many are responsible for keeping critical infrastructure like our electricity, energy, and public health systems safe. The dangers of these sectors being targeted are very real, and have the potential to seriously harm untold numbers of people.</p><p><strong>9) They’re willing to accept risk</strong> - The dangers of cyber threats aren’t limited to the masses. Analysts themselves can be targeted by threat actors. Earlier this year a <a href="https://www.reuters.com/article/us-cyber-fireeye/fireeye-researcher-hacked-firm-says-no-evidence-its-systems-hit-idUSKBN1AG1TP" target="_blank">researcher from FireEye was hacked</a> by unknown attackers, who defaced his social media sites and published private data. In a move reminiscent of Richard Connell’s "<a href="https://en.wikipedia.org/wiki/The_Most_Dangerous_Game" target="_blank">The Most Dangerous Game</a>," threat hunters might find themselves the hunted.</p><p><strong>10) They’re just plain fun</strong> -  Despite the ever-present dangers to themselves and the systems they’re responsible for, analysts are an incredibly eclectic and entertaining community. All the proof you need comes from this year’s <a href="https://www.derbycon.com/" target="_blank">Derbycon 7.0</a>. A participant by the name of Grifter found a cockroach in his milkshake at a nearby restaurant, later <a href="https://twitter.com/Grifter801/status/911663096552402944" target="_blank">tweeting out a warning</a> to others and naming him Trevor. As the restaurant was fumigated, fellow Derbycon participants created a memorial outside in Trevor’s honor. Trevor was later inducted as a Saint in the Church of WiFi, starred in a commemorative <a href="https://twitter.com/sehnaoui/status/912151355799859201" target="_blank">film</a> about himself, and made an <a href="https://twitter.com/TrevorTheRoach">appearance on Twitter</a>. Funds have even been raised in his honor for <a href="https://www.gofundme.com/trevor-the-roach-memorial-fund">disaster relief in Puerto Rico</a>. RIP Trevor.</p><p style="text-align: center;"><img alt="" src="https://cdn.filestackcontent.com/SkIqiiSqaU6fe4J5XsFQ"/></p><p style="text-align: center;"><em>#TrevorForget  (Photo credit to Steve Ragan @SteveD3)</em></p>

Get the Latest Anomali Updates and Cybersecurity News – Straight To Your Inbox

Become a subscriber to the Anomali Newsletter
Receive a monthly summary of our latest threat intelligence content, research, news, events, and more.