• Share
  • Email
  • Embed
  • Like
  • Save
  • Private Content
What's New in AlienVault v3.0?
 

What's New in AlienVault v3.0?

on

  • 31,221 views

Learn more about the major features in AlienVault's Unified Security Management platform (AV-USM) and open-source project.

Learn more about the major features in AlienVault's Unified Security Management platform (AV-USM) and open-source project.

Statistics

Views

Total Views
31,221
Views on SlideShare
31,166
Embed Views
55

Actions

Likes
1
Downloads
0
Comments
1

9 Embeds 55

http://www.linkedin.com 18
https://twitter.com 14
http://twitter.com 9
http://us-w1.rockmelt.com 7
http://a0.twimg.com 2
http://a0.twimg.com 2
http://paper.li 1
https://si0.twimg.com 1
http://www.docshut.com 1
More...

Accessibility

Categories

Upload Details

Uploaded via as Microsoft PowerPoint

Usage Rights

© All Rights Reserved

Report content

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate.

Cancel

11 of 1 previous next

  • Full Name Full Name Comment goes here.
    Are you sure you want to
    Your message goes here
    Processing…
  • The new 3.0 release looks great! Thanks to the entire AlienVault engineering team for your hard work and persistence!
    Are you sure you want to
    Your message goes here
    Processing…
Post Comment
Edit your comment

    What's New in AlienVault v3.0? What's New in AlienVault v3.0? Presentation Transcript

    • What´s new in AlienVault 3.0?
      Copyright AlienVault. 2011. Confidential
    • AlienVault Unified SIEM 3.0
      AlienVault Professional SIEM changes its name to
      AlienVault Unified SIEM.
      AlienVault Unified SIEM 3.0 represents a sea change in information security management, increasing operational effectiveness and unifying global interface from HIDS to SIEM.
      AlienVault Unified SIEM 3.0 offers unique Unified Management, Reporting, Vulnerability Scanner, Situational Awareness…
    • Unified Management
      • From a single interface, maintain a unique asset structure and a unique user permission structure.
      1 unique login
      1 unique asset structure
      1 unique user structure
    • Reporting &
      Analysis
    • Unified Reporting
    • Unified Dashboards
      New security dashboards with drill-down capabilities.
    • New tickets customization
      Ability to create completly customizable tickets with new fields: calendars, maps, text, slides…
    • Alarms
      Alarm tagging.
      New options for group alarms.
    • SIEM and Logger Advancements
      General improved performance.
      A SIEM or a logger can send to multiple SIEM and loggers.
    • Logger
      New architecture:
      Index process improved
      Search among billions of events in 0,2 seconds.
      Support for remote loggers: unified interface, queries for multiple loggers.
    • Advanced Analysis
      Usability enhancements.
      Unique IP link representation in Google Maps.
    • Advanced Analysis
      Generates a report from a customized data view.
      Timeline analysis:
    • UnifiedDetection
    • New HIDS & NIDS interface
      Integrated OSSEC HIDS Management web interface.
      Manage the built-in wireless agents from web console: installation, configuration, real time monitoring …
    • New HIDS & NIDS interface
      Remote monitoring through ssh (Linux, Solaris and other network devices)
      Facilitates password interchange.
      HIDS rules configuration through web interface:
      IMAGEN
    • Unified Vulnerability Scanner
      • Define jobs, policies, roles, report permissions within the same console, assets, and users…
    • Improved Vulnerability Scanner
      Import/Export scans in nbe format.
      Ability to consult status, stop, re start, pause a scan.
      New Vulnerability Scanner version speed up scans.
    • User Management
    • User management
      True Multitenancy in a single instance
      High abstraction in Asset categorization and user grouping
    • User management
      New user management options for PCI compliance requirements: ability to suspend users, impose complex passwords, expiring passwords…
    • User session
      Real time information about active users.
      Further information about sessions, ability to remove undesired users, etc.
    • SituationalAwareness
    • Inventory
      Ability to include icons/logos in order to identify assets (networks, hosts…) in web interface:
    • Network Discovery
      Passive inventory from information taken with ntop.
      Auto inventory through Active Directory/nedi…
    • Traffic Capture
      New traffic capture feature with filtering options.
      Results in pcap files for their analysis and solve possible network problems (wireshark).
      10 Gbps Sensor.
      Upgraded libpcap in order to increase amount of data to process.
    • Renovated Application Integration
      Stylized Ntop & Nagios.
    • Configuration
    • Global Usability Enhancements
      Better usability in forms: auto complete, error correction...
    • Data visibility
      Global vision of the entire system in one look.
    • Time zones management
      Upgraded support for collecting events from multiple time zones: every log is storage with original date and utc.
      Each user keeps their time zone in order to facilitate analysis.
      IMAGEN
    • Backup system
      Improvements in SIEM backups management.
      Users can restore SIEM events.
    • System status
      Real time information about system status: hardware, software, processes, etc.
    • Sensor Upgrades
      New plugins.
      Ability to use aliases.local
      Unicode support.
      Plugins with ssh remote support.
      Ability to use: ssh.cfg.local to customize plugins and maintain the changes after updates.
      Keywords to match a rule in order to avoid processing with the regexp.
      Multiple output servers configuration.
      Improved plugins.
      Stored events in memory/harddisk when connectivity problems with SIEM/Logger arise.
    • Software updates
      Ossec 2.5, Openvas 4, Snort-2.9, Pf_ring 4.6.3, Ntop 4.0, Nmap 5.51, Libpcap 1.1…
    • Feed Improvement
      Empowered Feed subscription, including Emerging Threats private feeds.
      ET Pro feeds include, e.g., SCADA systems coverage and real up-to -date malware protection.