LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-08-2014, 03:13 PM   #1
borgy95
Member
 
Registered: Mar 2012
Location: England
Distribution: Debian, Kali, CentOS 7
Posts: 64

Rep: Reputation: Disabled
Security analyst, What is it really all about?


Ciao,

I was stuck for what forum and where it was best placed. I figure why not ask you, odds are someone here has experience of being in a security anaylst, specifically in a SOC.

I have an opportunity to take a position as a senior Security Analyst. I could really do with an insightful view?

Graci
 
Old 09-09-2014, 05:40 AM   #2
linosaurusroot
Member
 
Registered: Oct 2012
Distribution: OpenSuSE,RHEL,Fedora,OpenBSD
Posts: 982
Blog Entries: 2

Rep: Reputation: 244Reputation: 244Reputation: 244
It depends ... I've done a lot of host security analysis on configuration of unix/linux hosts (with automated reporting in the mostly vain hope the relevant people will fix the problems).

But there is also log analysis (which I've done some of).

And network traffic analysis.
And examination of computers after suspected wrongdoing to collect evidence.
And pen testing.

So it really depends on how the employer sees the vacancy.

And lots of people when they say "security" don't mean security - they mean compliance (passing audits and/or meeting trivial standards).
 
Old 09-09-2014, 06:08 AM   #3
borgy95
Member
 
Registered: Mar 2012
Location: England
Distribution: Debian, Kali, CentOS 7
Posts: 64

Original Poster
Rep: Reputation: Disabled
Ahh yes, This is definitely not the audit/compliance gig. I'd rather be jobless - maybe...

It is very much focused on what you described:
Quote:
But there is also log analysis (which I've done some of).
And network traffic analysis.
And examination of computers after suspected wrongdoing to collect evidence.
So whats it like? Did it keep you interested? and learning new things? What were you favorite/least favorite aspects?

Thanks
 
Old 09-09-2014, 07:48 AM   #4
linosaurusroot
Member
 
Registered: Oct 2012
Distribution: OpenSuSE,RHEL,Fedora,OpenBSD
Posts: 982
Blog Entries: 2

Rep: Reputation: 244Reputation: 244Reputation: 244
Quote:
log analysis
pretty dull - I made a web display of recent centrally-collected syslog so you could tell who logged in where and when and from where. The idea is if you thought one host was compromised you'd have an idea which other hosts to look at next.

Quote:
network traffic analysis
never done this except for odd debugging (you might look at snort etc)

Quote:
examination of computers after suspected wrongdoing to collect evidence
This tends to fall into using encase etc for catching staff viewing porn on windows boxes (not my area) and using TCT to study actions taken on Unix hosts to know what the bad guy was up to (find what exploit tool he installed). Hopefully these are infrequent actions.


Then there's looking for bugs in s/w - definitely fun. You get to report stuff to the vendors and see if they are willing to fix it. The worst behaviour I found was BMC unwilling to even receive a bug report until I could show I had a support contract.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Software to help a business analyst bmcgonag Linux - Software 5 07-10-2012 03:44 PM
QA Analyst position (Strangeloop Networks) strangeloop LQ Job Marketplace [Archive] 0 11-29-2011 04:21 PM
Security Analyst/Advisor to the Linux Community. hackersgarage LinuxQuestions.org Member Intro 2 07-27-2009 02:54 PM
Disaster Recovery Analyst sphelpspsi AIX 1 05-04-2004 09:54 AM
Vb 6 Analyst Programmer oakley Linux - Software 12 10-27-2003 03:45 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:10 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration