Siren Champion Jeremy Turner shares his perspective on using Siren for cybersecurity analysis, from connecting previously separated data sources to building relational data models that help analysts investigate information more effectively.
Drawing on his experience across government and commercial environments, Jeremy explains why Siren stood out to him as an analyst, how teams can approach their first Siren implementation, and why ontologies and structured data models can give investigators greater leverage over complex data.
Across three videos, Jeremy explores what makes Siren different and how analysts can move from searching isolated datasets towards investigating the relationships between them.
Why Siren? An analyst’s perspective
When Jeremy Turner first encountered Siren, one capability immediately stood out: the ability to bring structure to the way analysts explore connected information.
In commercial cybersecurity, analysts can find themselves working across numerous tools and interfaces, searching individual datasets before manually piecing the results together.
Jeremy had previously experienced more structured analytical methodologies while working in government. Siren offered a way to bring some of that structure into commercial cybersecurity analysis without forcing analysts to become data-modelling experts.
One of the capabilities that particularly resonated with him was field mapping.
Analysts already understand many of the relationships they want to investigate. They know which fields they need to join, which entities they want to pivot between and which connections could be significant.
Siren allows those relationships to become part of the investigative process itself.
For Jeremy, that provided an intuitive way for analysts to begin building and working with data models while remaining focused on the investigation.
How should analysts get started with Siren?
Jeremy’s advice for organisations beginning a Siren implementation is simple: start with the data and start small.
Teams don’t need to create a complete unified data model before they can begin getting value from Siren.
Instead, analysts can examine how they already work.
Which fields are they regularly comparing? What pivots and joins are they performing manually? Which data sources do they move between during an investigation?
Those existing investigative behaviours can provide the foundation for building relationships within Siren.
Different sources don’t necessarily need identical schemas either. Fields can be mapped between datasets, allowing analysts to work with existing structures while progressively creating a more connected model of their information.
Jeremy recommends approaching this iteratively: begin with a small number of sources, map the relationships that matter and expand the model as analysts become more familiar with working relationally.
Why do ontologies matter for cybersecurity analysis?
Jeremy sees ontologies as one of the most effective ways analysts can gain greater leverage over their data.
Cybersecurity teams frequently have access to enormous quantities of information, but that information can remain divided between individual products and interfaces.
The result can be an analyst working across multiple browser tabs, running searches in different systems and manually combining the results elsewhere.
Creating structured relationships between datasets offers another approach.
By mapping fields, developing data models and introducing ontologies and taxonomies, analysts can begin examining information relationally rather than treating every dataset independently.
This provides a stronger foundation for more rigorous analysis and allows investigators to explore how different entities, events and datasets relate to one another.
For Jeremy, the opportunity is to move beyond simply putting more data in front of analysts and instead give them the structure required to understand what that data means when it is connected.
Key takeaways
- Siren enables analysts to investigate relationships across multiple data sources rather than treating each dataset independently.
- Field mapping provides an intuitive way to connect information even when different sources use different schemas.
- Analysts don’t need to create a complete unified data model before getting started with Siren.
- Existing investigative workflows can help teams identify which relationships should be modelled first.
- Starting small allows teams to build their Siren data model iteratively as their requirements develop.
- Ontologies and taxonomies can give cybersecurity analysts greater structure and analytical leverage over complex information.