• No results found

What is SIEM? Security Information and Event Management. Comes in a software format or as an appliance.

N/A
N/A
Protected

Academic year: 2021

Share "What is SIEM? Security Information and Event Management. Comes in a software format or as an appliance."

Copied!
36
0
0

Loading.... (view fulltext now)

Full text

(1)
(2)

 Security Information and Event Management

Centralised security log

management

Long term storage, analysis

and reporting

Real-time monitoring, alerting,

correlation and dashboards

 Comes in a software format or as an appliance.

What is SIEM ?

(3)

 Which security events and alerts require my attention?

 How do I obtain meaningful information from the events

collected from the ever-increasing number of devices across my enterprise?

Fundamentals

Collection Analysis Escalation

EVENTS ALERTS

Security Monitoring Process

(4)
(5)

 Where to look for Inspiration ?

Industry Analysts and Market Observations

 Within Gov’t and Private Sector with similar technology

What do we really trying to achieve ?

Requirements

Who are we trying to satisfy?

 Software vs Appliances ?

 Proof Of Concept

Realistic– Multiple Log Sources and Use Cases

(6)

Requirements

 Drivers

Functional and Non-Functional Requirements

 Log Sources

Platforms, Systems and Applications

 Deployment Scale

 Budget

 Resources

(7)

 SIEM Stakeholders are IT Security, Technical Operations, Audit, Compliance

 Functional requirements and Scalability must be known at Purchase time

 Road Map into the future

 Solution to match your capabilities

 Identify what you don’t know – services to cover capability gaps.

 Use Case development

(8)

 Event Collection and Management

 Monitoring, Analysis and Alerting

 Built-in Functionality

 Scalability and Storage

 Minimal Performance Impact

Ease of Use with User Friendly Interface  Support within Australia

 Software or Appliance

(9)

Revenue and Growth

400 800 1000 850 950 1000 1050 50 30 30 15 15 15 25 0 10 20 30 40 50 60 70 80 90 200 300 400 500 600 700 800 900 1000 1100 2006 2007 2008 2009 2010 2011 2012 P e r c e n t a g e G r o w t h M i l l i o n s $ Revenue Growth

(10)

Gartner Magic Quadrant

Niche Players

Smaller or regional

vendors

More specific or narrow

focus

(11)

Gartner Magic Quadrant

Challengers

Well funded, good

(12)

Gartner Magic Quadrant

Visionaries

Good functional match

to market requirements

Lower execution

capabilities, well funded

(13)

Gartner Magic Quadrant

Leaders

Good functional match

to market requirements

Good installed base and

revenue stream and growth

 Superior execution of

(14)

Retrospective Look

2008 2013

(15)

ArcSight acquired in 2010 ESM for large scale

deployments

Express appliance for

midsized

Connector and Logger

appliances

CORR replacing Oracle Feature rich but most

complex

Complete set of capabilities

HP ArcSight

2008 2013

(16)

IBM QRadar

2008 2013

 IBM acquired Q1 Labs in late 2011

 Juniper appliances (STRM)

 Good general SIEM capabilities

 Straightforward to deploy and maintain

Behaviour analysis for

NetFlow and log events

2008

(17)

McAfee ESM

2008 2013 2008 2013  Acquired NitroSecurity 2011

 Integration within Stable

 High-performance analytics under high-event-rates

Network-based packet

(18)

LogRhythm

 Appliances and software

 Scalability

Light and Nimble  Good fit for limited

deployment and support resources

 Wizards for fast deployment

2008 2013

(19)

Symantec SSIM

2008 2013 2008 2013

 Integrates with SEP

 DeepSight provides

threat and vulnerability data.

 Narrow Fit

(20)

EMC-RSA

 Early success

 Now most replaced

EnVision to Security

Analytics

 Based on NetWitness platform

 Watch this space !

2008

2013 2008

(21)

NetIQ Sentinel

2008 2013 2008

2013

Acquired Novell in late

2010

Based on Sentinel Agent and content

technology from Security Manager

Integration within Stable Large-scale processing in

(22)
(23)

 Poor Log Management Predates SIEM

 Log Management Issues Still Exist

Big Data Sets and Archival Incomplete captures

Auditing turned off

Log format standards and specifications Applications security logging

 SIEM dependant upon Audit and Logging Regime

(24)

 Three layers of Architecture

Event Collectors

Event Indexing and Storage

Processing/Mgt/Admin/Console

 Collection/Storage is High Volume

Ranging up to 100K EPS.

 Event Processing against a subset

Aggregation and Filtering consolidate to 10-20%

 What you collect isn’t what you keep nor use !!

Distilling Events

Collection

Storage

(25)

 Built-In Support for Most Common Devices

 Poor Back-End Systems Capability (e.g. Mainframe)

 Custom Log Sources

Cost and Expertise

 Events Normalised into Proprietary Format

Makes Migration Difficult Raw Logs Still Needed

 Adoption of a Standard (CEF)

(26)

 Correlation Faster Against Known Bad Events

 Log Volumes Can Overwhelm SIEM systems

 SIEM licences often based on EPS

 Filtering at Source

 Best approach for Log Filtering  Control – know what you log

Lower System Resources utilization

Filtering at Destination

Most practical and easiest to implement  SIEM takes care of filtering

 Source Devices will be generating tons of logs

 Higher System Resources and Bandwidth Utilization

(27)

Correlation is a Vital and Powerful

Analysis of :

Attack Vectors

Threat Scenarios specific to You

 Start with Built-In Rules

 Understand, Investigate, Tune and then Build

(28)

 SIEM is Only as Good as the Administrator

 Ecosystem Maintenance and Care

 Technical Skills

Across ALL Platforms and Systems Across O/S and Applications

SIEM Itself

 Training

 Mentoring

 Managed Service Offerings

(29)

(30)
(31)

…we can get rid of…

…archiving native logs“

…other ‘similar’ software, like Splunk”

…alert me whenever fraud occurs”

…generate Web Application Analytics Reports”

…we can tick that Compliance box”

(32)

 Uncompressed Syslog over NW

 DNS Lookups

(33)

 Beware, the colour, Red

 Default colours may send the wrong signals

 Dashboards MUST give

Info at a Glance Clarity of Alerts Drive Behaviour

Not there to just look

colourful !!

(34)

 Don’t be over-awed by Sheer Numbers !

 Forest and Trees Syndrome

The Devil is often in the

Detail

(35)

 Managing SIEM is Not Simple

 Poor People Investment = Poor Return

 SIEM is not a Silver Bullet

Identifies security issues Needs Response and

Remediation resources

(36)

SIEM is not about acquiring a tool, but about gaining intimacy with your logs and events, your configuration

and business goals, commensurate with your environment and requirements.

References

Related documents

The  rates  of  the  Electricity  Charges  payable  to  RSO  by  the  Applicant  for  the  Electricity  Services  will  be  be  based  on  the  reasonable  costs 

E-SPIN Professional book on Security Management will focuses on Security Information and Event Management (SIEM), Compliance Management, PCI Data Security

For example, implementation of McAfee Enterprise Security Manager, a security information and event management (SIEM) system for event collection and incident response, will

Security intelligence solutions offer SIEM (security information and event management), log management, configuration and vulnerability management, and behavioral

Network Access Control Endpoint Web Protection Host Intrusion Protection Mobile Device Management.?. McAfee’s Open Platform for Security

The SIEM market is composed of vendors with products that can provide at least basic support for all three use cases, but there is wide variation in the architectural approach and

SIEM solutions should: • Support the real-time collection and analysis of events from host systems, security devices and network devices combined with contextual information

The SIEM market is composed of technology providers that support all three use cases; however, there are variations in the relative level of capability for each use case,