From the Target breach to the latest Sony breach, data leakage has proved to be the most expensive and serious loss to their stakeholders. While DLP solutions provides a preventive mechanism to organizations' confidential and sensitive data from going out (or leaked) to unauthorized destinations. SIEM goes beyond and presents the correct and accurate picture to us, by telling the reason of particular Data Leakage. Its help us in stitching and correlating two discrete events (obviously in this case at least one event from DLP) from different log sources and present us with the correct and apparent picture about the event that happened just before the data leakage event. So, in a way it tells us the cause and motivation of the alert triggered by DLP system.
If we look at the kill chain stages (which are the intrusion stage attempts usually followed by Advanced Persistent Threat) then data ex-filtration will be the last stage. So our aim should be to detect the intrusion in an early stage rather then detecting at later stage.
When we use SIEM + DLP then probability for an alert to be True positive is more than when we only use DLP.
We can only get the motivation and cause of the attack, when we can correlate and chain more than one events. And that is only possible when we can integrate DLP with SIEM. So in this way, each previous event tells the story to the next followed event. We can consider the below scenarios that may happen just before the DLP generated any alert. So in the below diagram, we can track the different event of attacks, detected by different security devices being monitored by SIEM to tell the complete story.
While, if we only uses DLP, then we will only get DLP alerts that have less information about the cause and motivation of APT.
So, it is always better to use DLP tools with SIEM that helps SIEM to get more information about any Data Leakage alert generated by DLP tools.
If we look at the kill chain stages (which are the intrusion stage attempts usually followed by Advanced Persistent Threat) then data ex-filtration will be the last stage. So our aim should be to detect the intrusion in an early stage rather then detecting at later stage.
When we use SIEM + DLP then probability for an alert to be True positive is more than when we only use DLP.
We can only get the motivation and cause of the attack, when we can correlate and chain more than one events. And that is only possible when we can integrate DLP with SIEM. So in this way, each previous event tells the story to the next followed event. We can consider the below scenarios that may happen just before the DLP generated any alert. So in the below diagram, we can track the different event of attacks, detected by different security devices being monitored by SIEM to tell the complete story.
While, if we only uses DLP, then we will only get DLP alerts that have less information about the cause and motivation of APT.
So, it is always better to use DLP tools with SIEM that helps SIEM to get more information about any Data Leakage alert generated by DLP tools.


