Active Insight for SIEM (Security Information and Event Management)

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    Active Insight for SIEM (Security Information and Event Management) - Presentation Transcript

    1.  
    2. Real-time Detection and Reaction to User Behavior ActiveInsight for SIEM ACTIVE INSIGHT
    3. Background
      • Successful SIEM deployments have been collecting data and events from infrastructure and security devices
    4. Background
      • Various regulations and business needs require application-level event collection , audit trail and correlation (FISMA, HIPPA, PCI, 357/257, etc.)
    5. Background
      • The business application tier is where actual business events occur and where damage can be done
      • “ Application layer monitoring for fraud detection or internal threat management is emerging as a new use case for SIEM technology ”
      • Gartner Magic Quadrant for Security Information and Event Management, 2008.
    6. The Business Need
      • Application level audit trail
      • Detailed user-session-application level data
      • Real-time visibility of user behavior and application events
      • Real-time, value-based, event detection and reaction
      • “ Zero-touch” application event detection (no code modifications or complex log configuration and management)
      • “ Zero-impact” on application performance and user experience
      • Quick deployment
    7. ACTIVE INSIGHT External Users System Mgmt Risk Mgmt SIEM Fraud Detection Internal Users Device API ACTIVE INSIGHT Detect React
    8. ActiveInsight Unique Value Proposition
      • Deeper, richer user-application level data
      • Non-intrusive, event driven architecture
      • Zero-touch, zero-impact deployment
      • Real-time visibility and reactions
      • Minimized integration efforts
      • Multiple feeders for various risk mgmt applications
      • Computational, I/O and log management off-loading
    9. Main Technological Challenges
      • Detecting relevant user-application events, in real-time , without harming application performance and availability
      • Reacting to relevant events by feeding SIEM or other security/risk management applications or initiating defensive actions
      • Offloading application servers and provide a central log source bus
      • Providing a simple , flexible and non-intrusive solution that can be deployed without requiring application code changes
    10. Technology
      • Distributed, high-performance, extreme transaction processing technology
      • Integrated in-memory distributed data caching
      • Unlimited server scale-out (scalable by design)
      • A-sync or sync (w/o time-out) processing
      • Low latency computational de-coupling
      • Unique and simple, xml based, “behavioral processing language”
      • Asynchronous, multi target feeders
      • Real-time, pattern based, 2-way user interaction
    11. Summary
    12. Q&A Thank you! http://www. activeinsight .net

    + ActiveInsightActiveInsight, 3 months ago

    custom

    149 views, 0 favs, 1 embeds more stats

    ActiveInsight provides real-time, value-based detec more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 149
      • 136 on SlideShare
      • 13 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 4
    Most viewed embeds
    • 13 views on http://www.activeinsight.net

    more

    All embeds
    • 13 views on http://www.activeinsight.net

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories