BAB 20 - SECURITY ANALYST
PENGANTAR BAB
Selamat datang di bab terakhir yang akan membawa Anda ke dunia Security Analyst - peran kunci dalam pertahanan siber organisasi. Security analyst adalah "mata dan telinga" organisasi yang memantau, mendeteksi, dan merespons ancaman keamanan 24/7.
Menurut Ponemon Institute 2023, organisasi dengan SOC (Security Operations Center) yang matang dapat mengurangi waktu deteksi insiden hingga 70% dan mengurangi dampak insiden hingga 60%. Ini menunjukkan betapa pentingnya peran security analyst dalam organisasi modern.
Bab ini akan membawa Anda melalui seluruh workflow security analyst - dari monitoring, log collection, log analysis, incident identification, incident response, threat analysis, hingga dokumentasi dan pelaporan.
IBM 2023
Ponemon 2023
Ponemon 2023
IBM 2023
- Memahami peran dan tanggung jawab security analyst
- Memahami cara kerja Security Operations Center (SOC)
- Membedakan security event dan security alert
- Memahami proses security monitoring
- Mengumpulkan log dari berbagai sumber
- Menganalisis log untuk mendeteksi anomali
- Mengidentifikasi Indicator of Compromise (IOC)
- Melakukan incident identification
- Melakukan incident response
- Melakukan threat analysis
- Mendokumentasikan incident
- Menulis security incident report
PENGERTIAN SECURITY ANALYST
Apa itu Security Analyst?
Security Analyst adalah profesional yang bertanggung jawab untuk memantau, mendeteksi, menganalisis, dan merespons insiden keamanan dalam organisasi. Mereka adalah "garda terdepan" dalam pertahanan siber organisasi.
"A security analyst is a cybersecurity professional who monitors, detects, analyzes, and responds to cybersecurity incidents to protect an organization's information systems and data."
Peran dan Tanggung Jawab
| TANGGUNG JAWAB | DESKRIPSI |
|---|---|
| Monitoring | Memantau sistem dan jaringan 24/7 untuk mendeteksi anomali |
| Detection | Mendeteksi security events dan alerts |
| Analysis | Menganalisis events untuk menentukan apakah itu incident |
| Response | Merespons incidents sesuai prosedur |
| Documentation | Mendokumentasikan semua aktivitas dan findings |
| Reporting | Membuat laporan untuk management dan stakeholders |
| Improvement | Merekomendasikan perbaikan untuk security posture |
Tier Levels
| TIER | ROLE | TANGGUNG JAWAB |
|---|---|---|
| Tier 1 | Security Analyst (Junior) | Triaging alerts, initial analysis, escalation |
| Tier 2 | Security Analyst (Senior) | Deep analysis, incident response, threat hunting |
| Tier 3 | Security Engineer/Threat Hunter | Advanced threat hunting, threat hunting, malware analysis |
| Tier 4 | SOC Manager/Lead | Management, strategy, coordination |
Skills dan Certifications
Technical Skills:
- SIEM - Splunk, QRadar, ArcSight, ELK
- Log Analysis - Log parsing, correlation
- Network Analysis - Wireshark, tcpdump
- Incident Response - Incident handling procedures
- Threat Intelligence - Threat hunting, IOC analysis
Certifications:
- CompTIA Security+ - Entry level
- CompTIA CySA+ - Cybersecurity Analyst
- GIAC GCIH - Incident Handler
- GIAC GCIA - Intrusion Analyst
- EC-Council CDSA - Certified Defensive Security Analyst
- Monitoring = satpam yang mengawasi CCTV 24/7
- Detection = satpam yang melihat aktivitas mencurigakan
- Analysis = detektif yang menganalisis apakah itu ancaman nyata
- Response = satpam yang merespons ancaman
- Documentation = detektif yang mendokumentasikan investigasi
- NIST SP 800-61 - Computer Security Incident Handling Guide
- SANS - SEC450: Security Operations and Incident Analysis
- CompTIA - CySA+ Certification Guide
SECURITY OPERATIONS CENTER
Apa itu SOC?
Security Operations Center (SOC) adalah pusat komando yang bertanggung jawab untuk memantau, mendeteksi, menganalisis, dan merespons insiden keamanan 24/7. SOC adalah "jantung" dari operasi keamanan organisasi.
"A Security Operations Center (SOC) is a centralized unit that deals with security issues on an organizational and technical level. A SOC includes the people, processes, and technology required to monitor, detect, and respond to security incidents."
SOC Tools
| TOOL | FUNGSI | CONTOH |
|---|---|---|
| SIEM | Security Information and Event Management | Splunk, QRadar, ArcSight, ELK |
| EDR | Endpoint Detection and Response | CrowdStrike, Carbon Black, SentinelOne |
| IDS/IPS | Intrusion Detection/Prevention System | Snort, Suricata, Palo Alto |
| Firewall | Network firewall | Palo Alto, Fortinet, Cisco |
| Log Management | Log collection and management | Splunk, ELK, Graylog |
| Threat Intelligence | Threat intelligence platform | MISP, ThreatConnect, Anomali |
SOC Best Practices
- 24/7 monitoring - monitoring non-stop
- Clear procedures - prosedur yang jelas
- Automation - otomatisasi untuk efisiensi
- Threat intelligence - integrasi threat intelligence
- Continuous improvement - perbaikan berkelanjutan
- Training - training berkelanjutan untuk analyst
- Metrics - metrik untuk mengukur kinerja
- SOC = menara pengawas yang mengawasi seluruh area
- Analyst = pengawas yang mengawasi monitor
- Tools = CCTV dan sensor
- Procedures = SOP untuk merespons ancaman
- NIST SP 800-61 - Computer Security Incident Handling Guide
- SANS - SEC450: Security Operations and Incident Analysis
- SOC-CMM - SOC Capability Maturity Model
SECURITY EVENT & ALERT
Event vs Alert
Penting untuk membedakan antara security event dan security alert:
| ASPEK | SECURITY EVENT | SECURITY ALERT |
|---|---|---|
| Definisi | Setiap aktivitas yang terjadi dalam sistem | Event yang terdeteksi sebagai potensi ancaman |
| Severity | Bervariasi (info, low, medium, high) | Medium, high, critical |
| Action Required | Tidak selalu | Ya, perlu investigasi |
| Contoh | User login, file access, network connection | Failed login attempts, malware detection |
Jenis Security Events
| JENIS | DESKRIPSI | CONTOH |
|---|---|---|
| Authentication Events | Login attempts, password changes | Successful login, failed login |
| File Access Events | File access, modification, deletion | File read, file write, file delete |
| Network Events | Network connections, traffic | Connection established, connection blocked |
| System Events | System changes, updates | System started, service started |
| Application Events | Application activities | Application started, error occurred |
Jenis Security Alerts
| JENIS | SEVERITY | CONTOH |
|---|---|---|
| Brute Force | High | Multiple failed login attempts |
| Malware Detection | Critical | Malware detected on endpoint |
| Intrusion Detection | High | Intrusion attempt detected |
| Data Exfiltration | Critical | Large data transfer to external |
| Policy Violation | Medium | Policy violation detected |
Best Practices
- Clear definitions - definisi yang jelas untuk event dan alert
- Proper tuning - tuning untuk mengurangi false positives
- Proper correlation - korelasi events untuk mendeteksi patterns
- Proper prioritization - prioritas berdasarkan severity
- Proper documentation - dokumentasi semua alerts
- Events = semua aktivitas di gedung (orang masuk, keluar, dll)
- Alerts = alarm yang berbunyi karena aktivitas mencurigakan
- Incidents = ancaman yang terkonfirmasi
- NIST SP 800-61 - Computer Security Incident Handling Guide
- SANS - SEC450: Security Operations and Incident Analysis
SECURITY MONITORING
Apa itu Security Monitoring?
Security monitoring adalah proses memantau sistem dan jaringan secara continuous untuk mendeteksi anomali dan potensi ancaman. Ini adalah aktivitas utama SOC.
Monitoring Sources
| SUMBER | DESKRIPSI | CONTOH |
|---|---|---|
| Network Traffic | Network traffic logs | Firewall logs, IDS/IPS logs |
| Endpoint Logs | Endpoint activity logs | Windows Event Logs, Syslog |
| Application Logs | Application activity logs | Web server logs, database logs |
| Security Tools | Security tool alerts | EDR alerts, SIEM alerts |
Monitoring Tools
| TOOL | FUNGSI | CONTOH |
|---|---|---|
| SIEM | Security Information and Event Management | Splunk, QRadar, ArcSight, ELK |
| EDR | Endpoint Detection and Response | CrowdStrike, Carbon Black, SentinelOne |
| NIDS/NIPS | Network Intrusion Detection/Prevention | Snort, Suricata |
| Network Analysis | Network traffic analysis | Wireshark, tcpdump |
Best Practices
- Comprehensive coverage - cakupan yang komprehensif
- Proper correlation - korelasi events dari berbagai sumber
- Proper tuning - tuning untuk mengurangi false positives
- Proper prioritization - prioritas berdasarkan severity
- Continuous monitoring - monitoring 24/7
- Automation - otomatisasi untuk efisiensi
- Monitoring = CCTV yang mengawasi seluruh area
- Sources = kamera CCTV di berbagai lokasi
- Tools = monitor dan sistem perekam
- Analyst = satpam yang mengawasi monitor
- NIST SP 800-61 - Computer Security Incident Handling Guide
- SANS - SEC450: Security Operations and Incident Analysis
LOG COLLECTION
Apa itu Log Collection?
Log collection adalah proses mengumpulkan log dari berbagai sumber untuk dianalisis. Log collection adalah langkah pertama dalam security monitoring dan incident response.
Log Sources
| SUMBER | DESKRIPSI | CONTOH |
|---|---|---|
| Windows Event Logs | Windows system and application logs | Security, System, Application |
| Linux Syslog | Linux system logs | /var/log/syslog, /var/log/auth.log |
| Firewall Logs | Firewall activity logs | Firewall allow/deny logs |
| IDS/IPS Logs | Intrusion detection/prevention logs | Snort alerts, Suricata alerts |
| Web Server Logs | Web server activity logs | Apache access/error logs |
| Application Logs | Application activity logs | Application logs, database logs |
Log Collection Tools
| TOOL | FUNGSI | CONTOH |
|---|---|---|
| Syslog | Linux log forwarding | rsyslog, syslog-ng |
| WinEventLog | Windows log forwarding | Windows Event Forwarding |
| Filebeat | Log file forwarding | Filebeat, Fluentd |
| SIEM Agents | SIEM log collection agents | Splunk Universal Forwarder |
Log Collection Examples
Log Collection Examples # Linux syslog configuration # /etc/rsyslog.conf *.* @@siem-server:514 # Windows Event Forwarding # Configure Windows Event Collector wecutil qc wecutil cs subscription.xml # Filebeat configuration # /etc/filebeat/filebeat.yml filebeat.inputs: - type: log paths: - /var/log/*.log output.logstash: hosts: ["logstash-server:5044"] # Splunk Universal Forwarder # /opt/splunkforwarder/etc/system/local/inputs.conf [monitor:///var/log/] disabled = false index = main
Best Practices
- Comprehensive coverage - kumpulkan log dari semua sumber
- Proper configuration - konfigurasi yang benar
- Secure transmission - transmisi yang aman (TLS)
- Proper storage - penyimpanan yang aman
- Proper retention - retensi yang sesuai dengan kebijakan
- Proper rotation - rotasi log untuk manajemen storage
- Log collection = pengumpulan bukti dari TKP
- Sources = sumber bukti (CCTV, saksi, dll)
- Tools = alat untuk mengumpulkan bukti
- Storage = penyimpanan bukti yang aman
- NIST SP 800-92 - Guide to Computer Security Log Management
- SANS - SEC450: Security Operations and Incident Analysis
LOG ANALYSIS
Apa itu Log Analysis?
Log analysis adalah proses menganalisis log untuk mendeteksi anomali, pola, dan potensi ancaman. Log analysis adalah aktivitas inti dari security analyst.
Log Analysis Techniques
| TEKNIK | DESKRIPSI | CONTOH |
|---|---|---|
| Pattern Matching | Mencari pola tertentu dalam log | Mencari failed login attempts |
| Anomaly Detection | Mendeteksi anomali dalam log | Deteksi unusual traffic patterns |
| Correlation | Mengkorelasikan events dari berbagai sumber | Korelasi firewall dan IDS logs |
| Statistical Analysis | Analisis statistik dari log | Analisis traffic patterns |
Log Analysis Tools
| TOOL | FUNGSI | CONTOH |
|---|---|---|
| SIEM | Security Information and Event Management | Splunk, QRadar, ArcSight, ELK |
| Log Analysis | Log analysis tools | Splunk, ELK, Graylog |
| Command Line | Command line log analysis | grep, awk, sed |
Log Analysis Examples
Log Analysis Examples # Search for failed login attempts $ grep "Failed password" /var/log/auth.log # Search for successful login attempts $ grep "Accepted password" /var/log/auth.log # Search for specific IP $ grep "192.168.1.100" /var/log/auth.log # Count failed login attempts per IP $ grep "Failed password" /var/log/auth.log | \ awk '{print $(NF-3)}' | sort | uniq -c | sort -nr # Search for specific time range $ grep "Sep 9" /var/log/auth.log | grep "Failed password" # Search for multiple patterns $ grep -E "Failed password|Invalid user" /var/log/auth.log # Count events per hour $ grep "Failed password" /var/log/auth.log | \ awk '{print $3}' | cut -d: -f1 | sort | uniq -c
Best Practices
- Proper filtering - filtering yang tepat untuk mengurangi noise
- Proper correlation - korelasi events dari berbagai sumber
- Proper prioritization - prioritas berdasarkan severity
- Proper documentation - dokumentasi semua findings
- Continuous improvement - perbaikan berkelanjutan
- Log analysis = analisis bukti dari TKP
- Filtering = memilah bukti yang relevan
- Correlation = menghubungkan berbagai bukti
- Prioritization = memprioritaskan bukti yang paling penting
- NIST SP 800-92 - Guide to Computer Security Log Management
- SANS - SEC450: Security Operations and Incident Analysis
INDICATOR OF COMPROMISE
Apa itu IOC?
Indicator of Compromise (IOC) adalah artefak yang menunjukkan bahwa sistem telah dikompromikan. IOC digunakan untuk mendeteksi dan merespons insiden keamanan.
"An Indicator of Compromise (IOC) is an artifact observed on a network or in an operating system that with high confidence indicates a computer intrusion."
Jenis IOC
| JENIS | DESKRIPSI | CONTOH |
|---|---|---|
| File Hash | Hash dari file malicious | MD5, SHA1, SHA256 hash |
| IP Address | IP address yang malicious | C2 server IP, malicious IP |
| Domain | Domain yang malicious | Malicious domain, C2 domain |
| URL | URL yang malicious | Malicious URL, phishing URL |
| Email yang malicious | Phishing email, malicious email | |
| Registry Key | Registry key yang malicious | Malicious registry key |
| File Name | Nama file yang malicious | Malicious file name |
| Mutex | Mutex yang dibuat oleh malware | Malicious mutex |
IOC Sources
| SUMBER | DESKRIPSI | CONTOH |
|---|---|---|
| Threat Intelligence Feeds | Threat intelligence feeds | AlienVault OTX, Abuse.ch |
| Threat Intelligence Platforms | Threat intelligence platforms | MISP, ThreatConnect, Anomali |
| Incident Response | IOC dari incident response | IOC dari incident investigation |
| Threat Hunting | IOC dari threat hunting | IOC dari threat hunting investigation |
Best Practices
- Proper validation - validasi IOC sebelum digunakan
- Proper context - konteks yang tepat untuk IOC
- Proper sharing - sharing IOC dengan komunitas
- Proper integration - integrasi IOC dengan security tools
- Continuous update - update IOC secara berkala
- IOC = sidik jari penjahat di TKP
- Threat Intelligence = database sidik jari penjahat
- Detection = mencocokkan sidik jari di TKP dengan database
- Response = menangkap penjahat berdasarkan sidik jari
- NIST SP 800-61 - Computer Security Incident Handling Guide
- MITRE - ATT&CK Framework
- MISP - Malware Information Sharing Platform
INCIDENT IDENTIFICATION
Apa itu Incident Identification?
Incident identification adalah proses mengidentifikasi dan mengkonfirmasi bahwa sebuah event adalah insiden keamanan. Ini adalah langkah pertama dalam incident response.
Incident Types
| TYPE | DESKRIPSI | CONTOH |
|---|---|---|
| Malware | Malware infection | Virus, worm, trojan, ransomware |
| Intrusion | Unauthorized access | Unauthorized access, privilege escalation |
| Data Breach | Data exfiltration | Data exfiltration, data leak |
| Denial of Service | Service disruption | DDoS attack, service disruption |
| Insider Threat | Insider threat | Insider threat, malicious insider |
Best Practices
- Clear procedures - prosedur yang jelas untuk identifikasi
- Proper tools - tools yang tepat untuk identifikasi
- Proper training - training untuk analyst
- Proper documentation - dokumentasi semua findings
- Proper escalation - eskalasi yang tepat
- Events = gejala pasien
- Alerts = gejala yang mencurigakan
- Incidents = diagnosis yang dikonfirmasi
- Analyst = dokter yang mendiagnosis
- NIST SP 800-61 - Computer Security Incident Handling Guide
- SANS - SEC450: Security Operations and Incident Analysis
INCIDENT RESPONSE
Apa itu Incident Response?
Incident response adalah proses merespons insiden keamanan untuk meminimalkan dampak dan memulihkan sistem. Incident response adalah aktivitas inti dari security analyst.
Incident Response Phases
| PHASE | DESKRIPSI | AKTIVITAS |
|---|---|---|
| Preparation | Persiapan untuk incident response | Develop procedures, train team |
| Detection & Analysis | Deteksi dan analisis insiden | Detect incident, analyze incident |
| Containment | Mengandung insiden | Isolate affected systems |
| Eradication | Menghapus ancaman | Remove malware, patch vulnerabilities |
| Recovery | Memulihkan sistem | Restore systems, restore data |
| Post-Incident | Setelah insiden | Lessons learned, improve procedures |
Best Practices
- Clear procedures - prosedur yang jelas
- Proper training - training untuk team
- Proper tools - tools yang tepat
- Proper communication - komunikasi yang tepat
- Proper documentation - dokumentasi yang tepat
- Continuous improvement - perbaikan berkelanjutan
- Preparation = pelatihan pemadam kebakaran
- Detection = alarm kebakaran berbunyi
- Containment = mengandung kebakaran
- Eradication = memadamkan api
- Recovery = memulihkan bangunan
- Post-Incident = evaluasi dan perbaikan
- NIST SP 800-61 - Computer Security Incident Handling Guide
- SANS - SEC450: Security Operations and Incident Analysis
THREAT ANALYSIS
Apa itu Threat Analysis?
Threat analysis adalah proses menganalisis ancaman untuk memahami karakteristik, kemampuan, dan motivasi threat actor. Threat analysis membantu organisasi untuk mempersiapkan diri terhadap ancaman.
Threat Analysis Components
| KOMPONEN | DESKRIPSI | CONTOH |
|---|---|---|
| Threat Actor | Siapa yang melakukan serangan | APT groups, cybercriminals |
| Threat Capability | Kemampuan threat actor | Tools, techniques, procedures |
| Threat Motivation | Motivasi threat actor | Financial, espionage, hacktivism |
| Threat Target | Target threat actor | Industri, organisasi, individu |
Threat Intelligence Sources
| SUMBER | DESKRIPSI | CONTOH |
|---|---|---|
| Open Source | Open source threat intelligence | |
| Commercial | Commercial threat intelligence | Mandiant, CrowdStrike, Recorded Future |
| Government | Government threat intelligence | CISA, NCSC, BSSN |
| Community | Community threat intelligence | MISP, threat sharing communities |
Best Practices
- Proper sources - sumber yang tepat
- Proper analysis - analisis yang tepat
- Proper sharing - sharing dengan komunitas
- Proper integration - integrasi dengan security tools
- Continuous update - update secara berkala
- Threat analysis = intelijen militer tentang musuh
- Threat actor = musuh yang akan menyerang
- Threat capability = kemampuan senjata musuh
- Threat motivation = motivasi musuh
- Threat target = target musuh
- MITRE - ATT&CK Framework
- NIST SP 800-61 - Computer Security Incident Handling Guide
- MISP - Malware Information Sharing Platform
INCIDENT DOCUMENTATION
Apa itu Incident Documentation?
Incident documentation adalah proses mendokumentasikan semua aktivitas dan findings selama incident response. Dokumentasi yang baik sangat penting untuk audit, legal, dan improvement.
Documentation Components
| KOMPONEN | DESKRIPSI | CONTOH |
|---|---|---|
| Incident Details | Detail insiden | Incident ID, timestamp, severity |
| Timeline | Timeline insiden | Timeline of events |
| Findings | Findings dari investigasi | IOCs, attack vectors |
| Actions Taken | Tindakan yang diambil | Containment, eradication, recovery |
| Lessons Learned | Pelajaran yang dipelajari | Lessons learned, recommendations |
Best Practices
- Clear structure - struktur yang jelas
- Complete information - informasi lengkap
- Accurate information - informasi yang akurat
- Proper formatting - formatting yang tepat
- Proper storage - penyimpanan yang aman
- Documentation = laporan polisi tentang kejahatan
- Timeline = kronologi kejadian
- Findings = bukti yang ditemukan
- Actions taken = tindakan yang diambil polisi
- Lessons learned = pelajaran untuk masa depan
- NIST SP 800-61 - Computer Security Incident Handling Guide
- SANS - SEC450: Security Operations and Incident Analysis
SECURITY INCIDENT REPORT
Apa itu Security Incident Report?
Security incident report adalah laporan formal tentang insiden keamanan yang terjadi. Laporan ini digunakan untuk komunikasi dengan management, stakeholders, dan untuk dokumentasi.
Report Components
| KOMPONEN | DESKRIPSI |
|---|---|
| Executive Summary | Ringkasan eksekutif untuk management |
| Incident Details | Detail insiden |
| Timeline | Timeline insiden |
| Findings | Findings dari investigasi |
| Impact Assessment | Penilaian dampak |
| Actions Taken | Tindakan yang diambil |
| Recommendations | Rekomendasi untuk perbaikan |
| Lessons Learned | Pelajaran yang dipelajari |
Report Template
Security Incident Report Template # SECURITY INCIDENT REPORT # Executive Summary On [date], a [severity] security incident was detected... # Incident Details Incident ID: [ID] Date/Time: [date/time] Severity: [severity] Affected Systems: [systems] # Timeline [date/time] - [event] [date/time] - [event] # Findings [findings] # Impact Assessment [impact assessment] # Actions Taken [actions taken] # Recommendations [recommendations] # Lessons Learned [lessons learned]
Best Practices
- Clear structure - struktur yang jelas
- Complete information - informasi lengkap
- Accurate information - informasi yang akurat
- Proper formatting - formatting yang tepat
- Proper distribution - distribusi yang tepat
- Report = laporan resmi tentang insiden
- Executive summary = ringkasan untuk management
- Details = detail untuk technical team
- Recommendations = rekomendasi untuk perbaikan
- NIST SP 800-61 - Computer Security Incident Handling Guide
- SANS - SEC450: Security Operations and Incident Analysis
DIAGNOSTIK KOMPETENSI
Uji pemahaman Anda tentang Bab 20! Target minimal: 70% untuk menyelesaikan Fase 4.
- Total 10 pertanyaan pilihan ganda
- Klik opsi untuk menjawab - feedback langsung
- Benar = HIJAU, salah = MAGENTA
- Penjelasan muncul setelah menjawab
- Klik "LIHAT HASIL AKHIR" untuk skor final
-
- NIST SP 800-61 - Computer Security Incident Handling Guide
- NIST SP 800-92 - Guide to Computer Security Log Management
- SANS - SEC450: Security Operations and Incident Analysis
- MITRE - ATT&CK Framework
- MISP - Malware Information Sharing Platform