RE: SIM Tools, and endpoint security.

THolman_at_toplayer.com
Date: 05/20/05

  • Next message: David DiGennaro: "Re: IDS ISS"
    To: eric.hines@appliedwatch.com, focus-ids@securityfocus.com
    Date: Thu, 19 May 2005 20:11:24 -0400
    
    

    Hi Kevin,

    I would recommend taking a look at OpenService - http://www.open.com/.
    Also, look toward a network IPS to cut out the white noise at the perimeter
    and reduce the logging load on your internal devices.
    Don't discount the power of Microsoft Group Policy at a desktop level - they
    offer state of the art file integrity checking systems that are far more
    cost-effective and comprehensive than the 3rd party add-ons that proliferate
    the market.

    Regards,

    Tim

    -----Original Message-----
    From: KJP [mailto:kjp011975@gmail.com]
    Sent: Friday, April 22, 2005 6:18 AM
    To: focus-ids@securityfocus.com
    Subject: SIM Tools, and endpoint security.

    I am looking to get some information and some input on SIM Tools.

    Currently we have looked at the Protego (now Cisco) Mars product as well at
    NetForensics.

    We are looking to such a tool to fill the gaps in the Host Intrusion from a
    syslog type perspective to complement our Network Intrusion plan. We would
    dump OS logs, app logs, fw logs, router and switch logs to the SIM and would
    like to retain logs for an extended period.

    Looking for feedback on SIMs.

    Another area we are looking in is for Endpoint security and policy
    enforcement. We are currently looking at Cisco CSA. Who else should we
    look at and any feedback on CSA or other products?

    Thanks,

    Kevin Phillips

    --------------------------------------------------------------------------
    Stop hurting your network!
     
    The NeVO passive vulnerability sensor continuously finds vulnerabilities,
    applications and new hosts without the need for network scanning.
    It also finds compromised systems with application-based intrusion
    detection.
    Go to http://www.tenablesecurity.com/products/nevo.shtml to learn more.
    --------------------------------------------------------------------------

    --------------------------------------------------------------------------
    Stop hurting your network!
     
    The NeVO passive vulnerability sensor continuously finds vulnerabilities,
    applications and new hosts without the need for network scanning.
    It also finds compromised systems with application-based intrusion
    detection.
    Go to http://www.tenablesecurity.com/products/nevo.shtml to learn more.
    --------------------------------------------------------------------------

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    --------------------------------------------------------------------------


  • Next message: David DiGennaro: "Re: IDS ISS"

    Relevant Pages

    • RE: SIM Tools, and endpoint security.
      ... If you are a Cisco shop neuSECURE does a very good job of integrating with Cisco products. ... syslog type perspective to complement our Network Intrusion plan. ... dump OS logs, app logs, fw logs, router and switch logs to the SIM and would ... The NeVO passive vulnerability sensor continuously finds vulnerabilities, ...
      (Focus-IDS)
    • Re: Log file full of security problems!
      ... having with my small peer-to-peer network. ... Primary User Name: Mark ... Primary Logon ID: ... Disable the logging for the time being; Clear the logs or copy them to ...
      (microsoft.public.windowsxp.network_web)
    • Re: account not allowing domain access
      ... It sounds like it could be a problem with wrong credentials, network ... Have the admin check the security logs of LT2000s to see if there are any ... have basic connectivity to it and if you can not ping by name try it's IP ... like profile settings, please let me know where to get that so I can post ...
      (microsoft.public.windowsxp.security_admin)
    • RE: Anon Logon Events 538/540
      ... The event 540 logs the Successful Network Logon and the event 538 logs the ... Successful Network Logoff. ... Windows 2000, and Windows XP) ...
      (microsoft.public.windowsxp.security_admin)
    • RE: Setting up an IDS system
      ... and filtering my logs for sensibly viewing i.e. colour coded etc. ... earlier post about filters on routers). ... but this is to be aware of traffic patterns and network activity. ... Setting up an IDS system ...
      (Security-Basics)