- Insider threat looms large in San Francisco
- Woman fired over death threat
- IT admin pleads not guilty
- Tape storage gets more dense
- Top 10 worst uses for Windows
News | Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
ArcSight last week rolled out its bolstered security information management product used for aggregating data from multi-vendor equipment by adding a way for customers to spot patterns of attacks and automate a response.
ArcSight’s SIM software today can aggregate security-related information from more than 50 different vendors to present data on a single management console. The company is adding the ability to correlate information it receives so that, for example, intrusion-detection system (IDS) activity can be matched with vulnerability assessment to reduce false positives in IDS.
The security firm’s CTO, Hugh Njemanze, said ArcSight 3.0 will include a pattern-discovery capability so the SIM software can recognize threats such as repeated attempts to break into a network from multiple sources over a designated period.
“ArcSight 3.0 will discover patterns of activity based on a sequence of events that share targeted IP addresses,” Njemanze says. “For example, if there is a repeated attempt at a brute-force break-in, it will use data mining to discover that.”
ArcSight software runs on several server platforms, including Microsoft Windows, Sun Solaris and IBM’s AIX. It has a management console that presents status reports that are based on data it collects from multiple vendor IDS, firewalls, routers, switches, servers and other vendor management consoles. The software stores the data it collects in an Oracle database or DB2 Enterprise Edition. Njemanze says ArcSight 3.0 will more actively use data mining of historical events to recognize patterns of attacks.
In addition, ArcSight 3.0 will be adding what he called “command-and-control” features that will let customers automate a response to an attack.
ArcSight customer Union Bank of California says it has already started making use of the automated response capability that will part of ArcSight 3.0.
If a person appears to be interacting with malicious intent against the bank’s e-commerce servers, for example, ArcSight can issue a command to block the user’s access to applications for at least a minute, says Bob Justus, senior vice president of corporate information security at the bank, which is based in San Francisco.
A Web server should not be originating an outbound packet, Justus says, and if that ever appeared to be occurring at Union Bank, ArcSight would help identify that and initiate a means to block an outbound connection.
I finaly beat level 26 six the begining was the biggest problem- Anonymous
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.
Download the white paper.
Unauthorized applications: Taking back control
Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?
Download the white paper.
Comment