Improve Threat Detection with OSSEC and AlienVault USM

12

Transcript of Improve Threat Detection with OSSEC and AlienVault USM

Page 1: Improve Threat Detection with OSSEC and AlienVault USM
Page 2: Improve Threat Detection with OSSEC and AlienVault USM

About AlienVault

AlienVault has unified the security products, intelligence and community essential for mid-sized businesses to defend against

today’s modern threats

Page 3: Improve Threat Detection with OSSEC and AlienVault USM

Agenda

OSSEC capabilities

AlienVault USM capabilities

Demo – See it in action

• Remote OSSEC agent deployment, configuration and management

• Behavioral monitoring of servers and workstations

• Logging and reporting for PCI compliance

• Data correlation with IP reputation data, vulnerability scans and more

• Correlating OSSEC events to detect attacks

Page 4: Improve Threat Detection with OSSEC and AlienVault USM

OSSEC & AlienVault USM

Learning the Basics…

Page 5: Improve Threat Detection with OSSEC and AlienVault USM

OSSEC capabilities

Log analysis based intrusion detection

File integrity checking

Registry keys integrity checking (Windows)

Signature based malware/rootkits detection

Real-time alerting and active response

Page 6: Improve Threat Detection with OSSEC and AlienVault USM

OSSEC Architecture

Agent components:

Logcollectord: Read logs (syslog, WMI, flat files)

Syscheckd: File integrity checking

Rootcheckd: Malware and rootkits detection

Agentd: Forwards data to the server

Server components:

Remoted: Receives data from agents

Analysisd: Processes data (main process)

Monitord: Monitor agents

Page 7: Improve Threat Detection with OSSEC and AlienVault USM

ASSET DISCOVERY

• Active Network Scanning

• Passive Network Scanning

• Asset Inventory

• Host-based Software Inventory

VULNERABILITY ASSESSMENT

• Continuous

Vulnerability Monitoring

• Authenticated / Unauthenticated

Active Scanning

BEHAVIORAL MONITORING

• Log Collection

• Netflow Analysis

• Service Availability Monitoring

SECURITY INTELLIGENCE/SIEM

• SIEM Event Correlation

• Incident Response

THREAT DETECTION

• Network IDS

• Host IDS

• File Integrity Monitoring

USM Platform

Integrated, Essential Security Controls

Page 8: Improve Threat Detection with OSSEC and AlienVault USM

AlienVault USM Architecture

Embedded tools:

Asset discovery: Nmap, Prads

Behavioral monitoring: Netflow, Ntop, Nagios

Threat detection: Snort, Suricata, OSSEC

Vulnerability assessment: OpenVas

External collectors:

Syslog

WMI

SDEE

Page 9: Improve Threat Detection with OSSEC and AlienVault USM

AlienVault Event Correlation

AlienVault USM correlates events from multiple sources, crossing OSSEC alerts with information collected from embedded detectors and external sources.

Page 10: Improve Threat Detection with OSSEC and AlienVault USM

OSSEC Management Interface

• Status monitor

• Events viewer

• Agents control manager

• Configuration manager

• Rules viewer/editor

• Logs viewer

• Server control manager

• Deployment manager

• Rules viewer/editor

AlienVault USM provides a comprehensive GUI for OSSEC alerts management:

Page 11: Improve Threat Detection with OSSEC and AlienVault USM

Let’s See It In Action

Page 12: Improve Threat Detection with OSSEC and AlienVault USM

888.613.6023

ALIENVAULT.COM

CONTACT US

[email protected]

Test Drive AlienVault USM

Download a Free 30-Day Trial

http://www.alienvault.com/free-trial

Try our Interactive Demo Site

http://www.alienvault.com/live-demo-site

Now for some Q&A..

Questions? [email protected]

Twitter : @alienvault