Skip Links

Network World

  • Social Web 
  • Email 
  • Close

ArcSight updates SIM software

By Ellen Messmer , NetworkWorld.com , 06/10/2004

ArcSight last week rolled out its bolstered security information management product used for aggregating data from multi-vendor equipment by adding a way for customers to spot patterns of attacks and automate a response. 

ArcSight’s SIM software today can aggregate security-related information from more than 50 different vendors to present data on a single management console. The company is adding the ability to correlate information it receives so that, for example, intrusion-detection system (IDS) activity can be matched with vulnerability assessment to reduce false positives in IDS.

The security firm’s CTO, Hugh Njemanze, said ArcSight 3.0 will include a pattern-discovery capability so the SIM software can recognize threats such as repeated attempts to break into a network from multiple sources over a designated period.

“ArcSight 3.0 will discover patterns of activity based on a sequence of events that share targeted IP addresses,” Njemanze says. “For example, if there is a repeated attempt at a brute-force break-in, it will use data mining to discover that.”

ArcSight software runs on several server platforms, including Microsoft Windows, Sun Solaris and IBM’s AIX. It has a management console that presents status reports that are based on data it collects from multiple vendor IDS, firewalls, routers, switches, servers and other vendor management consoles. The software stores the data it collects in an Oracle database or DB2 Enterprise Edition. Njemanze says ArcSight 3.0 will more actively use data mining of historical events to recognize patterns of attacks.

In addition, ArcSight 3.0 will be adding what he called “command-and-control” features that will let customers automate a response to an attack.

ArcSight customer Union Bank of California says it has already started making use of the automated response capability that will part of ArcSight 3.0.

If a person appears to be interacting with malicious intent against the bank’s e-commerce servers, for example, ArcSight can issue a command to block the user’s access to applications for at least a minute, says Bob Justus, senior vice president of corporate information security at the bank, which is based in San Francisco.

A Web server should not be originating an outbound packet, Justus says, and if that ever appeared to be occurring at Union Bank, ArcSight would help identify that and initiate a means to block an outbound connection.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

I finaly beat level 26 six the begining was the biggest problem- Anonymous

Join the Discussion