• No results found

HP ESP 2013 Solution Roadmap

N/A
N/A
Protected

Academic year: 2021

Share "HP ESP 2013 Solution Roadmap"

Copied!
18
0
0

Loading.... (view fulltext now)

Full text

(1)

HP ESP 2013

Solution Roadmap

C. K. Lin (林傳凱)

Senior Channel Solution Manager, North Asia [email protected]

(2)
(3)

3

議程

HP ESP 簡介

HP ESP 解決方案

HP ESP 2013 Solution Roadmap

(4)
(5)

HP Enterprise Security Products

–1,500 由ArcSight, Fortify, TippingPoint and Atalla 團隊來的資安專家

–1,500 在HP Enterprise Security Services的資安專家

–唯一的一家資安公司所有的指標性的產品都居於領導者的地位(Gartner’s leaders quadrant)

Magic Quadrant Leadership One Team, One Vision

ATALLA

DATA SECURITY

(6)

Gartner report 2013:

“ArcSight should be on the list of every large

organization building a SOC”

(7)
(8)

Controls Reporting Application

Monitoring Controls

Monitoring Monitoring Identity

HP ArcSight 解决方案

資料蒐集

日誌整合

事件關聯

HP ArcSight Express HP ArcSight Connector HP ArcSight Logger HP ArcSight ESM

日誌源

ArcSight 讓電信客戶每天接獲的 安全事件通報從 4000 萬降低到 只有 45 件重大事件。改善率達 百萬倍! 支援350+ 種資 料來源及格式, 業界第一 最高可達100,000 EPS 的效能

(9)

HP Fortify 完整軟體開發生命週期的解决方案

9 HP Fortify SS

Dynamic Test

SecurityScope HP Fortify SCA

Develop

Static Code Analyzer HP Fortify RTA

Deploy

Real-Time Analyzer

Coding Integration QA Deploy Maintenance

HP Fortify Software Security Center

Tool Integration Data Integration Correlation HP WI

Penetration Test

WebInspect HP Fortify SCA (静態程式碼分析)

HP WebInspect & Security Scope

(動態應用檢測) HP Fortify RTA (軟體防火牆)

HP Software Security Center(安全管理中心)

方案最完整 性價比最高

(10)

TippingPoint 解决方案

IPS Platform Solutions

網路延遲最低,網路埠數業界最多

Security

Intelligence

Reputation DB 引領業界風潮

Digital Vaccine

Broadest Coverage • Evergreen Protection Web App DV and Scanning

Web Scan• Custom Filters • PCI Report Reputation DV

IP Reputation • DNS Reputation ThreatLinQ

Real Time Threat Intelligence Core Controller

20Gbps • 3x10GbE Security Management System (SMS)

Manage Multiple Units • Central Dashboard SSL Appliance S 1500S

Transparent SSL Bridging and Off-Loading Secure Virtualization Framework

vController & vIPS S 10 20Mbps • 2 Segments S 110 100Mbps • 4 Segments S 330 300Mbps • 4 Segments S 2500N 3Gbps • 11 Segments S 5100N 5Gbps • 11 Segments S 6100N 8Gbps • 11 Segments S 660N 750Mbps • 10 Segments 5200NX 5Gbps • Segments on Demand S 1400N 1.5Gbps • 10 Segments 7100NX 13Gbps • 10 Segments on Demand

ROBO, Perim eter, Zon e isolation , MSPs…

10GE Net w ork s, Core, Data Cen ter, Serv ice

P rov iders…

Man agem en t, Accessories, Virtu alization

(11)

Atalla 解決方案

Network Security Processor (banking/retail)

• Also Secure Configuration Assistant, Boxcar, premium/custom commands • ASPs $15-35K/unit, typical customer investment $100K-$1M

• 90% attach rate to NonStop FSI customers, but 60% attached to other hosts • Competitors: Thales, Futurex, SafeNet

Enterprise Secure Key Manager (all verticals)

• Also Client Licenses for each enrolled encryption device • ASP $20-25K/unit, typical customer investment $100K-$1M

• 100% attach rate to HP NonStop volume encryption, HP Storage enterprise tape library encryption, HP Storage SAN encryption, HP Cloud Services, HP ES Backup/Restore

(12)

HP ESP 2013

(13)

什麼是 ESM 6.0c?

ESM 5.x and earlier

Relies on Oracle database technology

• RDBMS like Oracle is not optimized for today’s

SIEM requirements

• Complex to Deploy

• Hard to maintain – requires DBAs to maintain it

ESM 6.0c

Embeds our own CORRE technology

• is optimized for today’s SIEM requirements • Simpler, faster and easier

• Management console makes life much easier –

eliminates DBAs.

Our performance-oriented enterprise SIEM solution

ESM 5.x Manager

Oracle Database

ESM 6.0c Manager

(14)

效能大大超越 5.2

1 1 1 20 3 15 0 5 10 15 20 25

Storage EPS Query

Oracle CORR

Detect More Incidents

Up to 3x the current performance using the same hardware

Faster Query up to15x

Address More Data

Up to 20x the current capacity for correlated events using the same disk space

Operate More Efficiently

Frees up security analyst cycles for proactive monitoring

(15)

Fortify 3.80 & WebInspect 10

1. Programming Environments – Visual Studio 2012 & .NET 4.5.

2. Batch Bug Management – Selection Criteria, Grouping Strategy,

State Management. (Integrated with Quality Center)

3. Moderate improvements – Search syntax AND and ORs. Speed.

4. Competitive Heads-up

5. WebInspect 10 (Integrated with WAF & TippingPoint)

(16)

Reputation-based threat intelligence

What is it?

RepSM actively manages “reputation-based” security

policies to detect and prevent communication with “known bad” actors.

• Detect additional threats including peer-to-peer network

use and potential spear phishing

• Accumulate and analyze suspicious connections, including

internal, over time further

• Integration with HP TippingPoint IPS to automatically block

attacks and exfiltration

• Integration with HP ThreatDetector to detect and verify zero

day attack and APT spread patterns

HP Reputation Security Monitor (RepSM 1.5)

Database Network s Servers Apps HP threat research Devices Events HP SIEM Reputation Data Responses

Bad IPs/ DNS names

(17)

HP ESP 於 RSA Conference 2013 公佈的新產品

1. ArcSIght & Hadoop (處理與保存大量資料的雲端運算平台

)

2. ArcSight & Autonomy (HP Big Data 解決方案 – 非結構化)

3. ArcSight & Vertica (HP Big Data 解決方案 – 結構化)

4. ArcSight Express 4.0

5. ArcSight cloud connector

(18)

References

Related documents

conferences on disaster recovery, HA, maintenance, and internals • Course author/instructor for Microsoft Certified Master qualifications • Wrote + presented SQL Server 2008

The aims of this study were to evaluate the proper management and the prognostic factors that influence the long-term outcomes of patients treated for bone metas- tasis

Whilst the businesses based on services and smaller products most frequently described being location independent, some businesses that sold larger products described how the

In the interests of designing a simple empirical study of entrepreneurship that will trace opportunity changing over time, and then explore what prompts those changes, this chapter

users are able to control the simulation time (pause or speed up) using a button in the tool bar (see Figure 2.4). This feature is particularly useful when users use fast

As experiments have shown the Max-sum algorithm applied over the proposed factor graph framework, where each robot has its own function and variable nodes, is very attractive for

Rocket trajectories are optimized to achieve the target, by either minimum time, control forces or fuel. To study the rocket motion under the influence of gravitational field,

When the versatility of the machines is high (i.e., the number of machines capable of processing an operation is, on average, relatively high) the average earliness and