Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
When networks fail, hams to the rescue
Alliance to promote Windows-managed Macs in enterprise
Lockheed Martin gets $89 million to converge DoD distribution networks
Clothes don't make this man: Sweatshirt helps nail Citibank card scammer
Microsoft readies new try for Yahoo
Gartner: Seven cloud-computing security risks
Autonomy, Endeca rate among top enterprise search vendors
Barracuda countersues Trend Micro in patent case
Mozilla's Firefox 3 sets geeky world record
Microsoft SharePoint popularity comes with issues
IBM mainframe acquisition raises antitrust concerns
Diary of a deliberately spammed housewife
Report: Tech giants forming 'patent troll' alliance
Trojan lurks, waiting to steal admin passwords
California enacts cell-phone driving ban
Security /

Users shoring up net security with SIM

Today's breaking news
Send to a friendFeedback

Advertisement:


Matt Speare estimates that it would require a staff of nine to monitor just one security event console consolidating logs from 30 devices 24-7 on his network at Ohio Savings Bank in Cleveland.

"And that's including weekend coverage, with no breaks, no lunch and no sick days," he says. Speare, director of IT risk management at Ohio Savings, quickly does the math again and concludes, "Obviously, that type of round-the-clock management with staff is cost-prohibitive."

To address the problem, Speare turned to security information management (SIM) software, an increasingly popular type of product designed for automating the collection of event log data from security devices and helping users make sense of it through a common management console.

Advertisement:

Ohio Savings uses netForensics' Security Information Platform, which cost it about $55,000 in hardware and software to install - half of what Speare estimates it would have cost the bank to outsource its security management.

"There's a huge return on investment for us," he says.

Spelling out SIM

SIM products use data aggregation and event correlation features similar to those of network-management software and applies them to event logs generated from security devices such as firewalls, proxy servers, intrusion-detection systems and antivirus software. What's more, SIM products can normalize data - that is, they can translate Cisco and Check Point Software alerts, for example, into a common format so the data can be correlated.

Like network-management software, SIM tools generally consist of server software, agents installed either on servers or security devices, and a central management console.

SIM providers range from smaller companies such as netForensics, Network Intelligence, GuardedNet, Intellitactics and OpenService to more established players such as Computer Associates, IBM Tivoli, Micromuse and NetIQ (see related story).

Charles Kolodgy, Internet security research manager at IDC, says companies have lots of choice when it comes to SIM: Vendors find the market attractive in that IDC estimates it is worth $15 million today and is set to quadruple to $61.3 million by 2005.

But he warns that many products are immature.

"These tools are great to collect and correlate events, but they offer little control over the security infrastructure," he says.

While vendors have adopted the SIM moniker, industry analysts prefer to call most of the products security event managers. Pete Lindstrom, a research director with Hurwitz Group, says the latter better describes what the current software offerings actually do, while SIM refers to a broader set of tasks the tools eventually should evolve to perform.

Real-world experiences

Charles Watson, data network specialist for Cellular South in Jackson, Miss., says his netForensics software actually pinpointed vulnerabilities in his network upon installation. Apparently, some end users unwittingly had tapped into open ports unbeknownst to the security staff.

"We had no idea those ports were open until the software pointed it out," Watson says. Because netForensics "logs everything," Cellular South could plug those holes and prevent a possible security breach - "and without running around to each server," he adds.

Keeping it SIMple
Early adopters of security in-formation management (SIM) products say such offerings must:
Correlate security events in real time.
Collect and filter alarms from a large variety of firewall, intrusion- detection and other security systems.
Include an easily scripted agent to add support for other security systems.
Require little configuration to start collecting events.
Boast strong reporting features.
Perform their own security functions, such as pinpointing network vulnerabilities.

While Speare and Watson reported relatively easy SIM implementations, Jeffrey Hormann says the software requires a fair amount of upfront work.

Hormann, director of technology operations at Metromedia Fiber Network in White Plains, N.Y., says it took him about a month to get e-Security's e-Sentinel software product operational on his network. "It's not out-of-the-box ready to go," he says. "It took a bit of effort to get it rolled out [and customized]."

Yet Hormann says e-Sentinel has saved him from hiring a dozen security specialists and lets him offer more services with a downsized staff.

SIM users and industry watchers agree that while the software can serve as an extra set of eyes across security devices, the tools need to evolve to take corrective actions.

"Security event managers want to be smart and to ultimately move toward being able to prioritize assets and applications without much configuration from users," Hurwitz's Lindstrom says. "We're probably one or two generations of software away from policy- and configuration-based security information management software."

RELATED LINKS

Contact Staff Writer Denise Dubie

Other recent articles by Dubie

NetIQ upgrades security management tools
NetIQ next month will boost its security information management offering by enabling it to collect data from a wider selection of vendors' security products and by improving its reporting capabilities.
Network World, 09/30/02.

Senate delays vote on surveillance bill until July 6/27/2008
House approves surveillance bill, protects telecoms 6/20/2008
Infowar resources 6/17/2008
Powered by Inform

NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.