SlideShare a Scribd company logo
Proactive Monitoring: Playing Offense for the Win
Dror Mann | CO-Founder, VP Product
Confidential and Proprietary
Dror Mann
VP Product & Co-Founder
Loom Systems
Head of Product
Voyager Labs
Head of Operations
IDF elite Intelligence unit
dror@loomsystems.com
Hi!
Confidential and Proprietary
• Intro – The Digital Era
• Today’s Monitoring
• What can we expect from AI
• Proactive Monitoring, 3 types of Predictions
• Live Demo
• Q&A
Agenda
Reality
DevOps
The Challenge
Confidential and Proprietary
We get you!
Confidential and Proprietary
Detect issues using Metrics (Thresholds)
Monitoring Today
Confidential and Proprietary
Monitoring Today
Drill down using Logs
Confidential and Proprietary
• Reactive – Detecting issues after they happened - see #oncallselfie
• Extracting metrics and maintaining thresholds takes time
• Metrics tell you (only) part of the story
• You monitor (only) what you know
Problems
What if there’s a better way?
Confidential and Proprietary
Pattern Recognition
Strict Methodology
Large Dimensionality
HUMANS
Good at top-down, open-ended tasks
BOTS
Superior at defined, bottom-up tasks
Deep reasoning
Contextual thinking
(Hungry)
(Get tired)
Confidential and Proprietary
• Proactive – Tell me about issues before they affect my business
• Monitor everything! Detect Unknowns and Knowns
• Automatic as possible - without defining thresholds
• Yes, also logs, they have better answers:
Desired Solution
Credit:XKCD
Confidential and Proprietary
“I’ve been hearing this for 20 years”
Total Recall, a movie based on a book from 1966, featuring a
self-driving car as science fiction.
If Artificial-Intelligence has matured enough to drive your car,
it can probably also help with your IT.
Skeptic?!
Collect + Parse Learn Baselines and
Predict failures
Correlate & Trace Enrich with
Insight/Action
Proactive Monitoring using AI
Confidential and Proprietary
• Behavioral
• Probabilistic
• Semantic
3 Types of Predictions
Confidential and Proprietary
Behavioral
Vector analysis
Rate of change
Threshold
Confidential and Proprietary
Probabilistic
Extrapolation
Confidential and Proprietary
Semantic
Certificate for local system with Thumbprint 7e 2f ce f9 7e 33 fb 1a 59 16
f5 0f a5 d3 fc a2 ed 18 21 2f is about to expire or already expired.
Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Date: 22/06/2012 2:43:56 PM
Data
Meta Data 2017-07-21 04:23:35 app web.1 WARN : Detected yajl-ruby version 1.1.0 which
can cause segfaults with newrelic_rpm's thread profiling features. We
strongly recommend you upgrade to the latest yajl-ruby version available.
2017-07-21 04:22:17 app web.1 WARN : Detected yajl-ruby version 1.1.0 which
can cause segfaults with newrelic_rpm's thread profiling features. We
strongly recommend you upgrade to the latest yajl-ruby version available.
2017-07-21 04:21:17 app web.1 WARN : Detected yajl-ruby version 1.1.0 which
can cause segfaults with newrelic_rpm's thread profiling features. We
strongly recommend you upgrade to the latest yajl-ruby version available.
Poll Question
Let’s see it live
Confidential and Proprietary
Past vs. Future
Past:
ITUSED
DASHBOARDS
TO DO MONITORING
Future:
AIDOES THE
MONITORINGFOR IT
Q&A
Thank You!
dror@loomsystems.com

More Related Content

PDF
Enabling effective hunt teaming and incident response
jeffmcjunkin
 
PPTX
Blame it on you for the false positives
Alexandre Teixeira
 
PDF
MITRE ATT&CKcon 2.0: Lessons in Purple Team Testing with MITRE ATT&CK; Daniel...
MITRE - ATT&CKcon
 
PDF
Sigma Open Tech Week: Bitter Truth About Software Security
Vlad Styran
 
PDF
From Theory to Practice: How My ATTACK Perspectives Have Changed
MITRE - ATT&CKcon
 
PDF
Resistance Isn't Futile: A Practical Approach to Threat Modeling
Katie Nickels
 
PPTX
Determining the Fit and Impact of CTI Indicators on Your Monitoring Pipeline ...
Alex Pinto
 
PPTX
Towards a Threat Hunting Automation Maturity Model
Alex Pinto
 
Enabling effective hunt teaming and incident response
jeffmcjunkin
 
Blame it on you for the false positives
Alexandre Teixeira
 
MITRE ATT&CKcon 2.0: Lessons in Purple Team Testing with MITRE ATT&CK; Daniel...
MITRE - ATT&CKcon
 
Sigma Open Tech Week: Bitter Truth About Software Security
Vlad Styran
 
From Theory to Practice: How My ATTACK Perspectives Have Changed
MITRE - ATT&CKcon
 
Resistance Isn't Futile: A Practical Approach to Threat Modeling
Katie Nickels
 
Determining the Fit and Impact of CTI Indicators on Your Monitoring Pipeline ...
Alex Pinto
 
Towards a Threat Hunting Automation Maturity Model
Alex Pinto
 

What's hot (11)

PDF
Measure What Matters: How to Use MITRE ATTACK to do the Right Things in the R...
MITRE - ATT&CKcon
 
PDF
MITRE ATT&CKcon 2.0: Prioritizing Data Sources for Minimum Viable Detection; ...
MITRE - ATT&CKcon
 
PDF
Avoid Rolling a Critical Fail
DomainTools
 
PDF
MITRE ATTACKcon Power Hour - October
MITRE - ATT&CKcon
 
PDF
ATTACKers Think in Graphs: Building Graphs for Threat Intelligence
MITRE - ATT&CKcon
 
ODP
Negative Unemployment and Great Job Satisfaction? Why infosec is AWESEOME
jeffmcjunkin
 
PDF
Beyond Matching: Applying Data Science Techniques to IOC-based Detection
Alex Pinto
 
PDF
CSA Raleigh application security and deception in the cloud
Phillip Maddux
 
PDF
MITRE ATT&CKcon 2018: Helping Your Non-Security Executives Understand ATT&CK ...
MITRE - ATT&CKcon
 
PPTX
Amy DeMartine - 7 Habits of Rugged DevOps
SeniorStoryteller
 
PDF
Shift Left. Wait, what? No, Shift Right!!!
Phillip Maddux
 
Measure What Matters: How to Use MITRE ATTACK to do the Right Things in the R...
MITRE - ATT&CKcon
 
MITRE ATT&CKcon 2.0: Prioritizing Data Sources for Minimum Viable Detection; ...
MITRE - ATT&CKcon
 
Avoid Rolling a Critical Fail
DomainTools
 
MITRE ATTACKcon Power Hour - October
MITRE - ATT&CKcon
 
ATTACKers Think in Graphs: Building Graphs for Threat Intelligence
MITRE - ATT&CKcon
 
Negative Unemployment and Great Job Satisfaction? Why infosec is AWESEOME
jeffmcjunkin
 
Beyond Matching: Applying Data Science Techniques to IOC-based Detection
Alex Pinto
 
CSA Raleigh application security and deception in the cloud
Phillip Maddux
 
MITRE ATT&CKcon 2018: Helping Your Non-Security Executives Understand ATT&CK ...
MITRE - ATT&CKcon
 
Amy DeMartine - 7 Habits of Rugged DevOps
SeniorStoryteller
 
Shift Left. Wait, what? No, Shift Right!!!
Phillip Maddux
 
Ad

Similar to Proactive Monitoring: Playing Offense for the Win (20)

PPTX
Democratizing AI with Apache Spark
Spark Summit
 
PDF
Machine Learning & IT Service Intelligence for the Enterprise: The Future is ...
Precisely
 
PDF
Technical track chris calvert-1 30 pm-issa conference-calvert
ISSA LA
 
PPTX
20160000 Cloud Discovery Event - Cloud Access Security Brokers
Robin Vermeirsch
 
PPSX
Motion based security alarm
Akshay Surve
 
PDF
Visualization in the Age of Big Data
Raffael Marty
 
PDF
AI for Manufacturing (Machine Vision, Edge AI, Federated Learning)
byteLAKE
 
PPTX
AI in the Enterprise at Scale
Ganesan Narayanasamy
 
PDF
Security Breakout Session
Splunk
 
PPTX
Privacy Preserved Data Augmentation using Enterprise Data Fabric
Atif Shaikh
 
PPTX
Innovate Better Through Machine data Analytics
Hal Rottenberg
 
PDF
Dev and Ops Collaboration and Awareness at Etsy and Flickr
John Allspaw
 
PDF
Defcon 21-pinto-defending-networks-machine-learning by pseudor00t
pseudor00t overflow
 
PDF
Bridging the Gap: Analyzing Data in and Below the Cloud
Inside Analysis
 
PPTX
High time to add machine learning to your information security stack
Minhaz A V
 
PPT
Troubleshooting: A High-Value Asset For The Service-Provider Discipline
Sagi Brody
 
PDF
Linkurious Enterprise: graph visualization platform neo4j
Linkurious
 
PPTX
Virtual Data : Eliminating the data constraint in Application Development
Kyle Hailey
 
PPTX
2016 Cybersecurity Analytics State of the Union
Cloudera, Inc.
 
PPTX
SplunkLive! London 2016 Splunk for Devops
Splunk
 
Democratizing AI with Apache Spark
Spark Summit
 
Machine Learning & IT Service Intelligence for the Enterprise: The Future is ...
Precisely
 
Technical track chris calvert-1 30 pm-issa conference-calvert
ISSA LA
 
20160000 Cloud Discovery Event - Cloud Access Security Brokers
Robin Vermeirsch
 
Motion based security alarm
Akshay Surve
 
Visualization in the Age of Big Data
Raffael Marty
 
AI for Manufacturing (Machine Vision, Edge AI, Federated Learning)
byteLAKE
 
AI in the Enterprise at Scale
Ganesan Narayanasamy
 
Security Breakout Session
Splunk
 
Privacy Preserved Data Augmentation using Enterprise Data Fabric
Atif Shaikh
 
Innovate Better Through Machine data Analytics
Hal Rottenberg
 
Dev and Ops Collaboration and Awareness at Etsy and Flickr
John Allspaw
 
Defcon 21-pinto-defending-networks-machine-learning by pseudor00t
pseudor00t overflow
 
Bridging the Gap: Analyzing Data in and Below the Cloud
Inside Analysis
 
High time to add machine learning to your information security stack
Minhaz A V
 
Troubleshooting: A High-Value Asset For The Service-Provider Discipline
Sagi Brody
 
Linkurious Enterprise: graph visualization platform neo4j
Linkurious
 
Virtual Data : Eliminating the data constraint in Application Development
Kyle Hailey
 
2016 Cybersecurity Analytics State of the Union
Cloudera, Inc.
 
SplunkLive! London 2016 Splunk for Devops
Splunk
 
Ad

More from Deborah Schalm (20)

PDF
Exploring Prometheus: Combining Metrics and Alerting to Improve Incident Mana...
Deborah Schalm
 
PDF
Discovering Dark Debt in your Culture
Deborah Schalm
 
PDF
A Discussion of Automated Infrastructure Security with a Practical Example
Deborah Schalm
 
PDF
Protect Your Organization Against Known Security Defects
Deborah Schalm
 
PDF
Putting the Ops in DevOps
Deborah Schalm
 
PDF
Machine Learning to Turbo-Charge the Ops Portion of DevOps
Deborah Schalm
 
PDF
Post-Equifax: How to Trust But Verify Your Software Supply Chain
Deborah Schalm
 
PDF
30 Minutes to a Private Cloud
Deborah Schalm
 
PDF
Taking DevOps Monitoring to the Next Level - The 5 Step Guide to Monitoring N...
Deborah Schalm
 
PDF
Top 5 Considerations for Operating a Kubernetes Environment at Scale
Deborah Schalm
 
PPTX
Is a Monolith Standing in the Way of Your Digital Transformation? Refactor fo...
Deborah Schalm
 
PDF
EMA: Ten Priorities for Hybrid Cloud, Containers and DevOps in 2017
Deborah Schalm
 
PDF
Application Discovery! The Gift That Keeps on Giving
Deborah Schalm
 
PDF
Top 5 Challenges in Scaling DevOps in Brownfield Environments
Deborah Schalm
 
PDF
The Coming Earthquake in WebSphere Application Server Configuration Management
Deborah Schalm
 
PDF
Planet of the APIs: Monitoring Transactions in the Wild
Deborah Schalm
 
PDF
Get Loose! Microservices and Loosely Coupled Architectures
Deborah Schalm
 
PDF
No Tool is an Island: Building DevOps into your business
Deborah Schalm
 
PDF
Scale Continuous Deployment to Production with DeployHub and CloudBees
Deborah Schalm
 
PDF
Monitoring First - Instrumenting Your Entire Stack for the Ultimate in Observ...
Deborah Schalm
 
Exploring Prometheus: Combining Metrics and Alerting to Improve Incident Mana...
Deborah Schalm
 
Discovering Dark Debt in your Culture
Deborah Schalm
 
A Discussion of Automated Infrastructure Security with a Practical Example
Deborah Schalm
 
Protect Your Organization Against Known Security Defects
Deborah Schalm
 
Putting the Ops in DevOps
Deborah Schalm
 
Machine Learning to Turbo-Charge the Ops Portion of DevOps
Deborah Schalm
 
Post-Equifax: How to Trust But Verify Your Software Supply Chain
Deborah Schalm
 
30 Minutes to a Private Cloud
Deborah Schalm
 
Taking DevOps Monitoring to the Next Level - The 5 Step Guide to Monitoring N...
Deborah Schalm
 
Top 5 Considerations for Operating a Kubernetes Environment at Scale
Deborah Schalm
 
Is a Monolith Standing in the Way of Your Digital Transformation? Refactor fo...
Deborah Schalm
 
EMA: Ten Priorities for Hybrid Cloud, Containers and DevOps in 2017
Deborah Schalm
 
Application Discovery! The Gift That Keeps on Giving
Deborah Schalm
 
Top 5 Challenges in Scaling DevOps in Brownfield Environments
Deborah Schalm
 
The Coming Earthquake in WebSphere Application Server Configuration Management
Deborah Schalm
 
Planet of the APIs: Monitoring Transactions in the Wild
Deborah Schalm
 
Get Loose! Microservices and Loosely Coupled Architectures
Deborah Schalm
 
No Tool is an Island: Building DevOps into your business
Deborah Schalm
 
Scale Continuous Deployment to Production with DeployHub and CloudBees
Deborah Schalm
 
Monitoring First - Instrumenting Your Entire Stack for the Ultimate in Observ...
Deborah Schalm
 

Recently uploaded (20)

PDF
Bandai Playdia The Book - David Glotz
BluePanther6
 
PPTX
ConcordeApp: Engineering Global Impact & Unlocking Billions in Event ROI with AI
chastechaste14
 
PDF
49785682629390197565_LRN3014_Migrating_the_Beast.pdf
Abilash868456
 
PPTX
GALILEO CRS SYSTEM | GALILEO TRAVEL SOFTWARE
philipnathen82
 
PDF
Enhancing Healthcare RPM Platforms with Contextual AI Integration
Cadabra Studio
 
PPTX
Presentation about Database and Database Administrator
abhishekchauhan86963
 
PDF
New Download FL Studio Crack Full Version [Latest 2025]
imang66g
 
PDF
Generating Union types w/ Static Analysis
K. Matthew Dupree
 
PDF
Summary Of Odoo 18.1 to 18.4 : The Way For Odoo 19
CandidRoot Solutions Private Limited
 
PDF
10 posting ideas for community engagement with AI prompts
Pankaj Taneja
 
PDF
WatchTraderHub - Watch Dealer software with inventory management and multi-ch...
WatchDealer Pavel
 
PPTX
Presentation about variables and constant.pptx
safalsingh810
 
PDF
49784907924775488180_LRN2959_Data_Pump_23ai.pdf
Abilash868456
 
PDF
New Download MiniTool Partition Wizard Crack Latest Version 2025
imang66g
 
PDF
Salesforce Implementation Services Provider.pdf
VALiNTRY360
 
PPTX
ASSIGNMENT_1[1][1][1][1][1] (1) variables.pptx
kr2589474
 
PPT
Activate_Methodology_Summary presentatio
annapureddyn
 
PPTX
classification of computer and basic part of digital computer
ravisinghrajpurohit3
 
PDF
Balancing Resource Capacity and Workloads with OnePlan – Avoid Overloading Te...
OnePlan Solutions
 
PPTX
Odoo Integration Services by Candidroot Solutions
CandidRoot Solutions Private Limited
 
Bandai Playdia The Book - David Glotz
BluePanther6
 
ConcordeApp: Engineering Global Impact & Unlocking Billions in Event ROI with AI
chastechaste14
 
49785682629390197565_LRN3014_Migrating_the_Beast.pdf
Abilash868456
 
GALILEO CRS SYSTEM | GALILEO TRAVEL SOFTWARE
philipnathen82
 
Enhancing Healthcare RPM Platforms with Contextual AI Integration
Cadabra Studio
 
Presentation about Database and Database Administrator
abhishekchauhan86963
 
New Download FL Studio Crack Full Version [Latest 2025]
imang66g
 
Generating Union types w/ Static Analysis
K. Matthew Dupree
 
Summary Of Odoo 18.1 to 18.4 : The Way For Odoo 19
CandidRoot Solutions Private Limited
 
10 posting ideas for community engagement with AI prompts
Pankaj Taneja
 
WatchTraderHub - Watch Dealer software with inventory management and multi-ch...
WatchDealer Pavel
 
Presentation about variables and constant.pptx
safalsingh810
 
49784907924775488180_LRN2959_Data_Pump_23ai.pdf
Abilash868456
 
New Download MiniTool Partition Wizard Crack Latest Version 2025
imang66g
 
Salesforce Implementation Services Provider.pdf
VALiNTRY360
 
ASSIGNMENT_1[1][1][1][1][1] (1) variables.pptx
kr2589474
 
Activate_Methodology_Summary presentatio
annapureddyn
 
classification of computer and basic part of digital computer
ravisinghrajpurohit3
 
Balancing Resource Capacity and Workloads with OnePlan – Avoid Overloading Te...
OnePlan Solutions
 
Odoo Integration Services by Candidroot Solutions
CandidRoot Solutions Private Limited
 

Proactive Monitoring: Playing Offense for the Win