Defending the Cloud: Lessons from Intrusion Detection in SharePoint Online

DerbyCon 7.0 - Legacy

Presented by: Matt Swann
Date: Friday September 22, 2017
Time: 18:00 - 18:55
Location: Track 3 - Teach Me

Over the past four years we've tried, failed, and now begun to succeed at defending the SharePoint Online service. In my talk, I describe the approaches we tried (focusing on our existing telemetry; focusing on anomalies; focusing on adversaries) and how we put into practice an adversary-focused approach that works. Finally, I describe what we're doing next - using graph analytics to cluster related activity and building incident response capabilities that allow us to locate and track an adversary in real-time. I close with a "hierarchy of needs" that defenders can follow to build defensive capabilities in their own organization.

Matt Swann

Matt is a Principal Engineering Manager in the OneDrive and SharePoint team at Microsoft. He drove the security development process for SharePoint 2010 and 2013, then built a team focused on cloud security for SharePoint Online. Matt is passionate about intrusion detection, incident response and catching adversaries. When he’s not catching bad guys, you can find him at home with his kids or hiking in Washington's beautiful Cascades. @MSwannMSFT


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats