Security
Information and
Event
Management
(SIEM)
Implementation
DAVID R. MILLER
SHON HARRIS
I
ALLEN
A. HARPER
STEPHEN VANDYKE
CHRIS
BLASK
Mc
Graw
Hill
NewYork
Chicago
San Francisco Lisbon London Madrid MexicoCity Milan New Delhi SanJuan Seoul SingaporeSydney
TorontoContents
Foreword i xxi
Acknowledgments
xxiiiIntroduction xxv
1 Business Models 3
What Are IT Business Models? 4
What You Haveto
Worry
About .. 5Overview
ofCIA
9Government 10
Military
10Three-Letter
Agencies
12Social Services Infrastructure 13
Commercial Entities 14
Retail Services 14
Manufacturing/Production
15Banking
15Universities 16
How Does Your
Company's
Business Model AffectYou? .... 18xiv
Security
Information and EventManagement
(SIEM)Implementation
2 Threat
Models
19The Bad
Things
That CouldHappen
21Vulnerabilities 21
Malicious
Intent 23Recognizing
Attacksonthe ITSystems
. 25Scanning
orReconnaissance 26Exploits
26 Entrenchment29
Phoning
Home
30 Control 31 After That 32Summary
33 3Regulatory Compliance
35Compliance Regulations
38Sarbanes-Oxley
Act(2002)
-SOX 38Gramm-Leach-Bliley
Act(1999)
-GLBA 38Healthcare Insurance
Portability
andAccountability
Act
(1996)
-HIPAA 39Payment
Card
Industry
DataSecurity
Standard-PCI DSS 39
California Senate Bill 1386
(2003)
-CA SB1386 40Federal Information
Security Management
Act
(2002)
-FISMA 40Cyber
Security
Act of 2009(SB 773)
40Recommended BestPractices 41
Prudent
Security
42Summary
49
4 SIEM
Concepts:
Components
for Small andMedium-size
Businesses
53The
Homegrown
SIEM 54Log
Management
55Syslog
56Alerts 56
Flow Data 56
Vulnerability
Assessment Data 57Let the Collection
Begin
57Event Correlation 63
Event
Normalization
64Correlation Rules 65
Commercial SIEM for SME 65
Endpoint
Security
67Securing
theEndpoints
67Protecting
the Network from theEndpoints
70IT
Regulatory
Compliance
71Compliance
Tools 73Implementation Methodology
74Tools Reference 75
Summary
765
The
Anatomy
ofaSIEM
77Source Device 78
Operating
Systems
79Appliances
79Applications
79Determining
Needed
Logs
80Determining
Needed SIEM Resources 80Log
Collection 81Push
Log
Collection 82Pull
Log
Collection 82Prebuilt
Log
Collection 83Custom
Log
Collection 83Mixed Environments 83
Parsing/Normalization
ofLogs
84Rule
Engine/Correlation Engine
i 86Correlation
Engine
-1 87Log Storage
90Database 90
Flat Text File 90
Binary
File, 91
Monitoring
91Summary
926
Incident
Response
93WhatIsanIncident
Response
Program?
94Grown fromthe
Security Program
94Where the IR
Program
Fits In 96How toBuildanIncident
Response
Program
97The IR Team 97
xvi
Security
Information and EventManagement (SIEM)Implementation
Socio/Political
Aspects
100The Price
Tag
100Security
Incidents andaGuidetoIncidentResponse
101 ATypical
Escalation FlowtoSecurity
Incident
101Finally!
An Incident 102Incident
Response
Procedures 104Automated
Response
IllAutomated
Response—a
GoodThing
112Automated
Response—a
BadThing
113Summary
1147
Using
SIEM forBusiness
Intelligence
115What
Is BusinessIntelligence
116Business
Intelligence Terminology
117Common Business
Intelligence
Questions
119Answerstothe CommonBusiness
Intelligence
Questions
119Developing
BusinessIntelligence Strategies
Using
SIEM 130HowtoUtilize SIEM forYourBI
Objectives
131Using
the Data that YourOrganization Currently
Possesses 132
What Other
Companies
AreDoing
with SIEM and BI 134Summary
135Part III
8
AlienVault
OSSIMImplementation
139Background
140Concept
140Open
Source Tools 140Functionality
142 CommercialVersion 146Design
147 Architecture 147Deployment
Considerations 149Implementation
149Requirements
150 InstallationProcess
151 Profiles 165Modifications
After
Installation 165Web
Console 166Incidents 166
Analysis
167Reports
167 Assets 167Monitors
167Intelligence
167Configuration
168 Tools 168Summary
1689 AlienVault OSSIM
Operation
169Interface 170 Dashboards 170 Incidents 174
Analysis
178 Assets 181Intelligence
182 Monitors 184Analysis
ofaBasic Attack 185Analysis
ofaSophisticated
Attack 190Summary
19510 Cisco
Security:
MARSImplementation
197Introductionto MARS 198
Topology,
Sessions,
and Incidents 199Scaling
aMARSDeployment
201Analyze Requirements
202Objectives
202Unique
ThreatConcerns
203Infrastructure
Inventory
204Design
205Resourcesand
Requirements
205Roles
and
Responsibilities
206Deployment
206Installing
the Device and ConnecttoNetwork 206Configuring
the Web Interface 208Assigning
MARS
UserAccounts
208Adding
Monitored
Devices 209Integrating
Flow Data 212Generating
Topology
212Operation:
Queries, Rules,
andReports
216Queries
217xvlll
Security
Information and EvontManagement
(SIEM)Implementation
User
Inspection
Rules
220Reports
221Limitations 223
Summary
22311 Cisco MARS Advanced
Techniques
225Using
the MARS Dashboard 226Summary Page
228Incidents
Page
233Query/Reports Page
234 RulesPage
235Management Page
238 AdminPage
240Adding
Unsupported
DevicestoMARS 243Importing
DeviceSupport Packages
244Building
Your Own CustomParsers 246A
Typical
Day
in theLifeofaMARSOperator
252Limitations 259
Summary
25912
Ql
Labs
QRadar
Implementation
261QRadar
Architecture Overview 262Ql
Labs TermstoKnow 266Planning
267Know Your Network 267
Plan Your
QRadar
SIEMDeployment
268Initial Installation 270
Configuring
theUnderlying
CentOSSystem
270The
QRadar
Administrative Interface 271Getting
Flow andEvent Data intoQRadar
285Event Sources and Data 286
Flow
Sources
and Data 287Summary
28713
Ql Labs
QRadar
Advanced
Techniques
289Using
theQRadar
Dashboard 291QRadar
DashboardDefault
Views 292QRadar
Views 292Custom Views 295
The
Equation
Editor 296QRadar
Sentries 299QRadar
Sentry Components
300QRadar
Rules 301QRadar
RuleTypes
302QRadar
RuleComponents
302QRadar
Custom Rules Wizard 303The Offense
Manager
307Searching
QRadar
Offenses 308QRadar Tuning
309QRadar
False Positive Wizard 309QRadar
DSMs and Custom DSMs 311Replacing
theQRadar
SSLCertificates
314Stepping Through
the Process 317Analyzing
Events 317Summary
32714
ArcSight
ESM
v4.5Implementation
329ArcSight
Terminology
andConcepts
330Overview of
ArcSight
Products 331ArcSight
ESM v4.5 332ArcSight
SmartConnectors 335ArcSight Express
336ArcSight
Logger
336ArcSight
ESM v4.5 Architecture Overview 337Planning
YourDeployment
340Determine Goals 340
Manage
Assets 341Determine
ArcSight
HardwareRequirements
341Initial Installation 342
Mountand Cable Servers 343
Installand
Configure Operating System
.. . .\.,
343Install
ArcSight
ESM v4.5 Database Softwareand
Oracle
Database 344Install
ArcSight
ESM v4.5Manager
348Configure ArcSight
Partition Archiver 350Install
ArcSight
SmartConnector
351Install
ArcSight
Console 353Summary
35415
ArcSight
ESM v4.5 AdvancedTechniques
355Operations: Dealing
withData 356Filters 356
Rules 357
Lists 360
XX Security Information and Event Management
(SIEM)
ImplementationActive Channels 361
Notifications
363Cases 364
Exporting
Information
364Managing
Assets and Networks 365The
ArcSight
SmartConnector 365The
ArcSight
AssetModel
366The
ArcSight
Network Model 367Management
andTroubleshooting
368Log
andConfiguration
Files 368Database 373