Re: Log Analysis Service?

From: Jem Berkes (jb_at_users.pc9.org)
Date: 02/23/04


Date: 23 Feb 2004 00:33:29 GMT


> Thanx for the reply, but, TBH, it wasn't particularly helpful. Or
> perhaps you misunderstood me.
>
> I am well aware of how difficult it is to go from "oops, something bad
> happened" to dragging someone before the ol' bar of justice.
>
> The question I asked is much simpler: since >>I<< am not an expert in
> analyzing log files of a hacked machine, are there companies that sell
> such a service? If so, who are the good/reputable ones?

There's Counterpane Internet Security, which was founded by cryptographer
and security guru Bruce Schneier.

As I understand it, what they pretty much do is centralized IDS and other
monitoring. I could see this being a valuable service for a very large
site, but for smaller sites I doubt they can do much better than what a
free IDS, like Snort [ http://www.snort.org/ ] can offer you.

But reading your initial post again, I don't think any of this applies to
you. Your system has already been compromised, and therefore you can't
trust any of the log files you might have kicking around.

You're going to have to reinstall everything from scratch, applying all the
latest upgrades, and then set up an IDS if you want to better monitor your
security for the future.

-- 
Jem Berkes
http://www.sysdesign.ca/


Relevant Pages

  • Re: [fw-wiz] SNMP RW ASA 7.2.1
    ... Security Focus Retired: Cisco Security Monitoring Analysis and Response System multiple vulnerabilities. ... notice I said the VMS replacement. ... VMS with the Firewall Manager add-on ...
    (Firewall-Wizards)
  • Re: Two wireless routers one network
    ... neighborhood kids trying to use my wireless than from any books or web ... I don't expect my customers to ... My level of security and paranoia largely depends on the risks and ... >>I notice you didn't say anything about my comments about monitoring ...
    (alt.internet.wireless)
  • Re: [fw-wiz] SNMP RW ASA 7.2.1
    ... Security Focus Retired: Cisco Security Monitoring Analysis and Response System multiple vulnerabilities. ... notice I said the VMS replacement. ...
    (Firewall-Wizards)
  • Re: Two wireless routers one network
    ... >wireless security in the world didn't do them any good when I can go ... >of wireless and just want it to work. ... Security is more than 50% social engineering. ... >I notice you didn't say anything about my comments about monitoring ...
    (alt.internet.wireless)
  • ARE YOU REALLY BEING MONITORED? READ THIS
    ... security systems is their ability to tell whether your system is ... installers and managers that they NO LONGER send this test signal. ... that many, many customers are out there, that are paying for moitoring, ... IS THE CUSTOMERS RESPONSIBILITY TO CALL THE MONITORING CENTER WEEKLY" ...
    (alt.security.alarms)