wisemonkeys logo
FeedNotificationProfileManage Forms
FeedNotificationSearchSign in
wisemonkeys logo

Blogs

SIEM Empowering Security

profile
Mohnishsingh
Sep 07, 2017
0 Likes
0 Discussions
1029 Reads

SIEM Empowering Security with deeper detection and faster response

Security today is a perfect blend of people process and technology. People have to follow process and use technology to secure our critical IT infrastructure and respond to threats in well-organized fast we can detect and remediate the hack.     As we know IT infrastructure can grow in size and complexity which makes it difficult to implement and manage security. The basic actionable intelligence we have in our system is the logs of the system. These logs record everything .with a right practise of logging storing and analysing these logs we can detect prevent and remediate threats. To manage the it security  needs of organisation we need to implement SIEM solutions SIEM stands for "Security Incident and Event Management" Few examples of these solutions are : HP Arcsight, RSA SA(dell), IBM Qradar, Splunk  
SIEM objective:
SIEM solutions have been around for many years and they were designed primarily for two objectives:
  1. Collect, analyze, report and store log data from hosts, applications and security devices to support security policy compliance management and regulatory compliance initiatives
  2. Process and correlate in real time event data from security devices, network devices and systems to identify security issues that pose the biggest risk to an organization .
  To fulfil the above objective we need data from the following data sources Data Sources – Full Packet Capture, NetFlowand Logs We also need visibility of our environment having Threat Vectors – Endpoint, Network and Cloud. SIEM Architecture & terms Collection, Aggregation, Normatisation, Correlation, EPS Collection layer is where all logs are feed into the siem solution it uses two technologies PUSH , PULL Push when a device is able to send its logs to the SIEM eg SPAN Checkpoint OLE etc. Pull is when the collector has to register and get logs to siem solution e.g. windows snare etc. Since the number of logs created by our IT devices is huge in number we need optimize way to store and retrieve our security related logs. We make use of process of aggregation. Similar logs are stored with a number describing the number of events .we can set thresholds to be alerted after aggregation . The logs created by different machines have different format which makes it difficult to manage and detect alerts syslog of cisco is different from that of checkpoint .Normalisation maps these logs to a common event format on which co relation can be applied . Correlation is a process which helps use to distinguish between a false positive and a true incident False positive can be termed as  a false detection of a possible threat. Incident is  termed as an event that cause disruption to our Infrastructure. Using correlation alerts are created in siem solutions E.g. of alerts: Windows machine created /deleted Virus detected Web attack detected EPS events per second is a parameter which is used to know in a second how many events does a data source create. This information is also used to decide on how much storage would our SIEM consume Conclusion In many instances, organizations go through multiple SIEM deployments to arrive at the Same level of understanding as the TDBUMO process provides but with Significantly more effort, more financial investment, And more Resource utilization. As mentioned previously, “garbage in, garbage out” is often Used to Describe SIEM correlation. As it is with correlation, poor analysis andPoorplanning Will only result in poor SIEM Coverage and performance, i.e., “garbage in, garbage out”.

Comments ()


Sign in

Read Next

Marvel Cinematic Universe

Blog banner

computer security

Blog banner

How to tie a Tie

Blog banner

Annual Day Preparation for Toddlers: What Helps and What to Avoid

Blog banner

Device driver

Blog banner

Business Intelligence v/s Big Data

Blog banner

"Mahakali cave"

Blog banner

10 Interesting Facts about Death Note

Blog banner

Ghee vs. Coconut Oil vs. Mustard Oil: Which Cooking Fat Wins for Indian Food?

Blog banner

LISP - Library Management System

Blog banner

From Procrastinator to Performer: How to Beat the Last-Minute Rush

Blog banner

Security requirements for Safe E-Payments

Blog banner

How College Events Build Real-world Skills You Can’t Learn From Textbooks

Blog banner

Admissions Open: Why This Is the Right Time to Choose the Best School for Your Child

Blog banner

MEMORY MANAGEMENT FILE

Blog banner

Service Transition Process in ITSM

Blog banner

MailChimp

Blog banner

QUANTUM COMPUTING IN SECURITY:A GAME CHANGER IN DIGITAL WORLD

Blog banner

HR Automation : Need of the hour

Blog banner

Modern Operating System - Khush bagaria

Blog banner

VIRTUAL MACHINES

Blog banner

How To Invest in Indian Stock Market For Beginners. ~ Tutorial 2 (NSDL And CSDL) Continued...

Blog banner

Types of E-Commerce

Blog banner

Europe Through My Lens

Blog banner

Direct memory access (DMA)

Blog banner

Malware

Blog banner

Smartsheet

Blog banner

IT RISK

Blog banner

Why Every Preschooler Learns at Their Own Pace?

Blog banner

Service Operations Principles

Blog banner

Hosting basics

Blog banner

Intrusion Detection System

Blog banner

PHONE TECHNOLOGY

Blog banner

Stephen Hawking : A Remarkable Physicist

Blog banner

How Preschools Help Children Make Their First Friends

Blog banner

IT GOVERNANCE

Blog banner

Why Are So Many Adults Getting Diagnosed with ADHD?

Blog banner

MYNTRA

Blog banner

The House ??of Patola Designs: Traditional Weaves with a Modern Twist

Blog banner

When Is the Right Time to Enrol My Toddler Into Preschool? NEP

Blog banner

Types of Malware in Cyber Security

Blog banner

PERSONALITY DEVELOPMENT

Blog banner