What factors should we consider in selecting security-log-auditing software?

| Posted in General Techologies

Information Week has a small blurb on What factors should we consider in selecting security-log-auditing software? I have also written here before on Five Factors of Logging Infrastructure.

More...
December 6th, 2004 | Jian Zhen | No Comments

Cons of using MSSPs

| Posted in General Techologies

Last week we went over some of the Pros of Outsourcing to MSSPs, today we will go over some of the Cons in more details. Here are the reasons why you should think twice before outsourcing. 1. Device control Once you outsource your security infrastructure such as firewalls and IDS, you may lose some or [...]

More...
December 5th, 2004 | Jian Zhen | No Comments

CSO Magazine Analyst Reports

A couple of interesting and relevant articles from CSO Magazine. Trends 2005: Risk And Compliance Management by Michael Rasmussen. Clearing Up the Muddled Security Management Market by Andrew Braunberg

More...
November 30th, 2004 | Jian Zhen | No Comments

Report Quality NOT Quantity

| Posted in General Techologies

If you look at any of the SEM/SIM products these days, they all tout how many pre-built reports they have prepared for you. Most of them have a hundred or more, some even have a couple hundred!! How are you ever going to have time to go through that many reports and find out if [...]

More...
November 29th, 2004 | Jian Zhen | No Comments

Log Management Requirements for MSPs

| Posted in General Techologies

I spent five years at one of the largest MSSPs as an architect and development manager. We had a couple thousand firewall, VPN, NIDS and HIDS devices that we manage for various hosting and managed service customers. We needed to aggregate all the logs generated by these devices and be able to provide reports and [...]

More...
November 28th, 2004 | Jian Zhen | No Comments

SGUIL – The Analyst Console for Network Security Monitoring

| Posted in General Techologies

InformIT has a detailed article on Sguil, Why Sguil Is the Best Option for Network Security Monitoring Data. According to the website, Sguil (pronounced sgweel) is built by network security analysts for network security analysts. Sguil’s main component is an intuitive GUI that provides realtime events from snort/barnyard. It also includes other components which facilitate [...]

More...
November 24th, 2004 | Jian Zhen | No Comments

Comments Broken!! Now Fixed!!

| Posted in General Techologies

Darn, w/ all the tweaking I’ve been doing to combat the spammers, I actually broke my comments!! No one has been able to post any comments. In any case, it’s fixed now and hopfully there won’t be any more issues.

More...
November 24th, 2004 | Jian Zhen | No Comments

Pros and Cons of MSSPs

| Posted in General Techologies

We will be a bit off topic today as I am thinking about a few-parts blog on MSSPs. Today we will discuss the pros and cons of outsourcing to a MSSP. Other ideas I have in the pipe for the next few days are: Requirements for Choosing a MSSP Log Management Requirements for a MSSP [...]

More...
November 23rd, 2004 | Jian Zhen | No Comments

AT&T Getting Into the SEM Game

| Posted in General Techologies

So it looks like AT&T wants to get into the SEM game as well, according to this eWeek article. AT&T is also working on a security event management system called Aurora that it plans to sell as a software solution. The system relies on the company’s Daytona database and is designed to do more than [...]

More...
November 22nd, 2004 | Jian Zhen | No Comments

A Firewall Log Analysis Primer

| Posted in General Techologies

Found this while googling. A Firewall Log Analysis Primer From LURHQ. (pdf version) It’s fairly basic but a good start nonetheless.

More...
November 21st, 2004 | Jian Zhen | No Comments