SIEM
Brief history of SIEM!!!
 1996 – Birth of SIEM
 2000 – SIEM winner: ArcSight launches
 Big players in the market
ArcSight-HP
QRadar-IBM
Nitro-McAfee
SecureVue–EiQ
Splunk, RSA envision and so on….
What is a SIEM??
 SIEM - Security Information Event Management
 Logging and Event Aggregation
 Network (Routers, Switches, Firewall ,etc.)
 System (Server ,workstation ,etc.)
 Application (Web, DB, etc.)
 Correlation Engine
 2+ related events = higher alarm
SIEM Advantages
 Correlation of data from multiple systems
 Prioritization based on risk of threat to assets
 Alerting and monitoring on events of interest to escalate
priority
 Monitor and log the access and use of sensitive data
 Limits exposure to breach
 Allows organizations to demonstrate adherence to polices
and controls
Present world !!!
 Attackers are more sophisticated in their attacks.
 Defenders need systems which help provide visibility and
altering across numerous security systems.
 SIEM adoption driven by compliance
 Gartner says “more than 80%”
 Put “Security” back into SIEM using real world examples.
5 reasons why SIEM is important…
 Compliance
 Operations Support
 Zero-day & APT
 Forensics
FIM
What does it do
 Directory Policy
 File Policy
 Registry Policy
 USB Policy
SIEM – It’s usage
How is SIEM helpful in the following Security concerns??
 Countermeasures to detect attempts to infect internal
system
 Identification of infected systems
 Mitigation of risk for infected systems
 Detection of outbound sensitive information ( DLP)
"Sep 01 2015 01:52:37: %ASA-4-402119:
IPSEC: Received an ESP packet (SPI=
0x8C623E78, sequence number= 0x193D)
from xxx.xxx.xxx.xxx (user= ezvpn2) to
xxx.xxx.xxx.xxx that failed anti-replay
checking. "
uid=asa1.int.xnxx.edu ip=10.1.9.55
extip=10.1.9.55 sev=local6.warn
ec=402119 et=3 sip=
xxx.xxx.xxx.xxx dip=xxx.xxx.xxx.xxx npri=4
dir=1 sgrp=Extranet dgrp=Extranet
proto=IPSEC act=1 family=Others
user=ezvpn2 cnt=1 msg="Invalid
sequence number in the recvd. IPSEC packet."
seq=0x193D ecat=System
ecatsubcat=Error ecatresult=Attemp
RAW log  Parsed logRAW log
Architecture
Screens 
Dashboard
Creating Alert
Triggered Alerts
Forensic Search
Asset Configuration
Alarms
Generated Events
Ticketing System for Customers
Reports
Security Information Event Management - nullhyd

Security Information Event Management - nullhyd

  • 1.
  • 2.
    Brief history ofSIEM!!!  1996 – Birth of SIEM  2000 – SIEM winner: ArcSight launches  Big players in the market ArcSight-HP QRadar-IBM Nitro-McAfee SecureVue–EiQ Splunk, RSA envision and so on….
  • 3.
    What is aSIEM??  SIEM - Security Information Event Management  Logging and Event Aggregation  Network (Routers, Switches, Firewall ,etc.)  System (Server ,workstation ,etc.)  Application (Web, DB, etc.)  Correlation Engine  2+ related events = higher alarm
  • 4.
    SIEM Advantages  Correlationof data from multiple systems  Prioritization based on risk of threat to assets  Alerting and monitoring on events of interest to escalate priority  Monitor and log the access and use of sensitive data  Limits exposure to breach  Allows organizations to demonstrate adherence to polices and controls
  • 5.
    Present world !!! Attackers are more sophisticated in their attacks.  Defenders need systems which help provide visibility and altering across numerous security systems.  SIEM adoption driven by compliance  Gartner says “more than 80%”  Put “Security” back into SIEM using real world examples.
  • 6.
    5 reasons whySIEM is important…  Compliance  Operations Support  Zero-day & APT  Forensics
  • 7.
  • 8.
    What does itdo  Directory Policy  File Policy  Registry Policy  USB Policy
  • 9.
    SIEM – It’susage How is SIEM helpful in the following Security concerns??  Countermeasures to detect attempts to infect internal system  Identification of infected systems  Mitigation of risk for infected systems  Detection of outbound sensitive information ( DLP)
  • 10.
    "Sep 01 201501:52:37: %ASA-4-402119: IPSEC: Received an ESP packet (SPI= 0x8C623E78, sequence number= 0x193D) from xxx.xxx.xxx.xxx (user= ezvpn2) to xxx.xxx.xxx.xxx that failed anti-replay checking. " uid=asa1.int.xnxx.edu ip=10.1.9.55 extip=10.1.9.55 sev=local6.warn ec=402119 et=3 sip= xxx.xxx.xxx.xxx dip=xxx.xxx.xxx.xxx npri=4 dir=1 sgrp=Extranet dgrp=Extranet proto=IPSEC act=1 family=Others user=ezvpn2 cnt=1 msg="Invalid sequence number in the recvd. IPSEC packet." seq=0x193D ecat=System ecatsubcat=Error ecatresult=Attemp RAW log  Parsed logRAW log
  • 11.
  • 13.
  • 14.
  • 15.
  • 16.
  • 17.
  • 18.
  • 19.
  • 20.
  • 21.
  • 22.