
Vincenzo Iozzo
Senior Director at CrowdStrike
DEIB - Conference Room "E. Gatti" (building 20)
March 21st, 2019
2.00 pm
Contacts:
Stefano Zanero
Research Line:
System architectures
Abstract
The hard part about security is to do simple things at scale", in this talk we will discuss the gotchas of building endpoint protection at scale. The talk is focused on the engineering aspects of building an EDR (endpoint detection and response) solution as opposed to the security requirements.EDR solutions rest on the idea that collecting as much information as possible from the OS allows to detect malicious patterns. The challenges of that approach are threefold: what and how to collect, where and how to store and how to analyze what has been collected. All these questions become non-trivial past a certain scale. In this talk we will cover some of those challenges and lessons learned while implementing such a solution.
