Successfully reported this slideshow.
We use your LinkedIn profile and activity data to personalize ads and to show you more relevant ads. You can change your ad preferences anytime.

What's New in AlienVault v3.0?


Published on

Learn more about the major features in AlienVault's Unified Security Management platform (AV-USM) and open-source project.

Published in: Technology
  • The new 3.0 release looks great! Thanks to the entire AlienVault engineering team for your hard work and persistence!
    Are you sure you want to  Yes  No
    Your message goes here

What's New in AlienVault v3.0?

  1. 1. What´s new in AlienVault 3.0?<br />Copyright AlienVault. 2011. Confidential<br />
  2. 2. AlienVault Unified SIEM 3.0<br />AlienVault Professional SIEM changes its name to<br />AlienVault Unified SIEM.<br />AlienVault Unified SIEM 3.0 represents a sea change in information security management, increasing operational effectiveness and unifying global interface from HIDS to SIEM.<br />AlienVault Unified SIEM 3.0 offers unique Unified Management, Reporting, Vulnerability Scanner, Situational Awareness…<br />
  3. 3. Unified Management<br /><ul><li> From a single interface, maintain a unique asset structure and a unique user permission structure.</li></ul>1 unique login<br />1 unique asset structure<br />1 unique user structure<br />
  4. 4. Reporting &<br />Analysis<br />
  5. 5. Unified Reporting<br />
  6. 6. Unified Dashboards<br />New security dashboards with drill-down capabilities.<br />
  7. 7. New tickets customization<br />Ability to create completly customizable tickets with new fields: calendars, maps, text, slides…<br />
  8. 8. Alarms<br />Alarm tagging.<br />New options for group alarms. <br />
  9. 9. SIEM and Logger Advancements<br />General improved performance.<br />A SIEM or a logger can send to multiple SIEM and loggers.<br />
  10. 10. Logger<br />New architecture: <br />Index process improved<br /> Search among billions of events in 0,2 seconds.<br />Support for remote loggers: unified interface, queries for multiple loggers.<br />
  11. 11. Advanced Analysis<br />Usability enhancements.<br />Unique IP link representation in Google Maps.<br />
  12. 12. Advanced Analysis<br />Generates a report from a customized data view.<br />Timeline analysis:<br />
  13. 13. UnifiedDetection<br />
  14. 14. New HIDS & NIDS interface<br />Integrated OSSEC HIDS Management web interface.<br />Manage the built-in wireless agents from web console: installation, configuration, real time monitoring …<br />
  15. 15. New HIDS & NIDS interface<br />Remote monitoring through ssh (Linux, Solaris and other network devices)<br />Facilitates password interchange.<br />HIDS rules configuration through web interface:<br />IMAGEN<br />
  16. 16. Unified Vulnerability Scanner<br /><ul><li>Define jobs, policies, roles, report permissions within the same console, assets, and users…</li></li></ul><li>Improved Vulnerability Scanner<br />Import/Export scans in nbe format.<br />Ability to consult status, stop, re start, pause a scan.<br />New Vulnerability Scanner version speed up scans.<br />
  17. 17. User Management<br />
  18. 18. User management<br />True Multitenancy in a single instance<br />High abstraction in Asset categorization and user grouping<br />
  19. 19. User management<br />New user management options for PCI compliance requirements: ability to suspend users, impose complex passwords, expiring passwords…<br />
  20. 20. User session<br />Real time information about active users.<br />Further information about sessions, ability to remove undesired users, etc.<br />
  21. 21. SituationalAwareness<br />
  22. 22. Inventory<br />Ability to include icons/logos in order to identify assets (networks, hosts…) in web interface:<br />
  23. 23. Network Discovery<br />Passive inventory from information taken with ntop.<br />Auto inventory through Active Directory/nedi…<br />
  24. 24. Traffic Capture<br />New traffic capture feature with filtering options.<br />Results in pcap files for their analysis and solve possible network problems (wireshark).<br />10 Gbps Sensor.<br />Upgraded libpcap in order to increase amount of data to process.<br />
  25. 25. Renovated Application Integration<br />Stylized Ntop & Nagios.<br />
  26. 26. Configuration<br />
  27. 27. Global Usability Enhancements<br />Better usability in forms: auto complete, error correction...<br />
  28. 28. Data visibility<br />Global vision of the entire system in one look.<br />
  29. 29. Time zones management<br />Upgraded support for collecting events from multiple time zones: every log is storage with original date and utc.<br />Each user keeps their time zone in order to facilitate analysis.<br />IMAGEN<br />
  30. 30. Backup system<br />Improvements in SIEM backups management.<br />Users can restore SIEM events.<br />
  31. 31. System status<br />Real time information about system status: hardware, software, processes, etc.<br />
  32. 32. Sensor Upgrades<br />New plugins.<br />Ability to use aliases.local<br />Unicode support.<br />Plugins with ssh remote support.<br />Ability to use: ssh.cfg.local to customize plugins and maintain the changes after updates.<br />Keywords to match a rule in order to avoid processing with the regexp.<br />Multiple output servers configuration.<br />Improved plugins.<br />Stored events in memory/harddisk when connectivity problems with SIEM/Logger arise.<br />
  33. 33. Software updates<br />Ossec 2.5, Openvas 4, Snort-2.9, Pf_ring 4.6.3, Ntop 4.0, Nmap 5.51, Libpcap 1.1…<br />
  34. 34. Feed Improvement<br />Empowered Feed subscription, including Emerging Threats private feeds.<br />ET Pro feeds include, e.g., SCADA systems coverage and real up-to -date malware protection.<br />