Please wait while the page is being loaded Skip this advertisement >
Monday | 8 September, 2008
ARN
Symantec SIM brings friends
Symantec's SIM comes with an active network to help it analyze your events
Curtis Franklin Jr. (InfoWorld) 08 January, 2008 10:33:19

Related Stories
  • +

    Mu Security Analyzer 04 January, 2008 07:28:03

    Mu-4000 fuzzer shines with wizard-driven test configuration, intelligent workflow, excellent vulnerability profiling, and auto-generated zero-day exploits
    I first came across the Mu Security Analyzer when a co-worker on a multi-company government project raved about how the appliance found a zero-day vulnerability in an e-mail inspection device that was protecting a top secret government agency. It was a rather simple script bug in the other vendor's product, but it would have allowed uncontrolled code execution. The implication was that our top secret project could have been compromised by an external hacker running penetration tests against our e-mail services. Initially, the manufacturer of the compromised mail filter refused to believe that a weakness existed in its product. That is, until we sent the exploit, automatically generated by the Mu analyzer, that the vendor's engineers could run to see for themselves.
  • +

    Packeteer rolls out plan for better WAN app performance 07 December, 2007 09:20:29

    Called IntelligenceCenter, the software monitors performance, reports on it and supplies tools to optimize it.
    Packeteer is introducing a new management platform that draws data from its own and other vendors' gear to boost the performance of applications over the WAN and is the first step in a broader application-performance plan.
  • +

    HP looks to SMBs with new shared storage 13 December, 2007 09:18:34

    Modular smart array comes in two products
    HP is preparing to launch a new MSA2000 disk array product family for clustered servers, which it is targeting at SMB deployments and remote offices.
  • +

    Linux, Unix, Mac, Windows PCs get authentication integration 06 December, 2007 08:29:57

    Centeris releases version 4.0 of Likewise with the intent of making Linux a first-class citizen on Windows networks
    Centeris, which provides cross-platform authentication via Microsoft's Active Directory, Tuesday enhanced its Likewise platform (Clear Choice Test of Likewise)Â and an added open source project that will be distributed with the top Linux operating systems.
  • +

    Secure Computing upgrades appliance for Web 2.0 14 September, 2007 08:32:32

    Features are designed to protect from the latest Web-based attacks
    Secure Computing on Wednesday announced a new version of its Webwasher gateway security appliance that adds features designed to help protect users from the new round of security threats introduced by Web 2.0 applications.
Additional Resources
ARN Library

Newsletter Subscription

Sign up for our ARN newsletters!
The premier provider of daily news to the IT channel, covering business, technology, products, and services.
RSS Feeds

What is it, one might reasonably ask, that separates a SIM (security information manager) from a basic log-file aggregator? Both will, of course, aggregate log files, but a SIM must go further, gathering incident alerts and status conditions from a variety of network security and infrastructure sources. A good SIM will then add some intelligence to the mix, helping the security engineer figure out which information is worth his or her immediate attention and which can be ignored until time to pass a compliance audit.

This last step separates the very good SIM from the merely competent, and it's where the security intelligence found in the Symantec SIM (SSIM) 9650 appliance shines. Like many SIMs, the Symantec system improves with each new data point (that is, component providing data) it has to chew on. Unlike many SIMs, Symantec's has its own Global Intelligence Network of analysts, experts, and OPSIMs (other people's SIMs) to throw into the intelligence mix.

If your network can provide a deep pool of data for the Symantec SIM to swim in, it can provide a wealth of detailed information to your security engineer. Be aware, though, that this isn't a product for security novices. If you think of it as an able assistant to your in-house security expert, you're on the right track. Given the system's intelligence, it might be tempting for admins to treat the tool as an expert replacement. Doing so in a small network with relatively few data sources, you're likely to be disappointed. If, on the other hand, you put one of these in a rich network beside a capable security staff, you'll find it a truly valuable addition to your security infrastructure.

Looking at the network

As SIMs go, Symantec's installs quickly. When you first connect to the SSIM appliance, you download the GUI app and get started. You'll find two logical applications built in to the device: a Web interface for simple administration tasks and a dedicated GUI application for most of the heavy lifting in configuration and analysis.

In my testing, the setup process went smoothly. I experienced just a couple instances of whining because of some quirks in my test environment. The SSIM system isn't particularly happy if you try to sequester it away from DNS (though it will operate after complaining for a few moments), and it uses self-signed certificates that are going to make some desktop clients antsy. As I said, for most production deployment, neither of these will be an issue, but there they are.

There are three broad areas of activity required to get you started: building an asset table, scanning for vulnerabilities, and establishing initial rules. You can perform that asset-table build either manually or automatically. Manual means either entering information through the keyboard (not recommended) or importing tables from just about any popular asset management system. If you don't have an existing asset table handy, the SSIM will build a table by sniffing the traffic on the network -- no active probing goes on. If you already have an asset management system in place, you'll want to import the information so that it will be consistent across systems. If you haven't taken the asset management step, discovery works well, though you'll want to go back into the descriptions to add details (regarding certain system details and asset criticality) that just can't be determined from network traffic alone.

The vulnerability scan is, of necessity, more active and intrusive. The system scans the network and compares the results against known vulnerability databases such as the National Vulnerability Database and the Open Source Vulnerability. The scan is the most benign sort; the SSIM doesn't try to confirm the vulnerability by conducting an exploit.

With assets and vulnerabilities in the database, I looked at the rule set that shipped with the SSIM and found not much there: around 40 rules populating the set. The slim rule set might seem inadequate, but Symantec explained it's a simple baseline; most of the production functionality comes from active data collected and is correlated during operations. I found that to be true, as the SSIM was able to construct information for reports and issue alerts based on information it received and built upon during the test. It's certainly possible to add specific rules yourself, but the need to do that should be limited to unusual cases in your particular network

When networks go bad

For most security analysts, the SSIM dashboard will be the primary window into the appliance's operation. The dashboard grants a real-time view of system operations, and it's customizable across a variety of different values, including the usual criteria you want to see (top talkers, top destinations, alerts, and warnings) and others that are specific to the SSIM, such as alerts from the Global Intelligence Network. The dashboard is tightly tied to the GUI application but can be detached and run on a separate monitor while the GUI continues in administration mode.

ARN Directory | Vendors relevant to this article
Market Place

ARN Member Login

 
Panel Sessions
  • ARN Panel Sessions: Day 3

    The last of our panel sessions recorded live at CeBIT 2008. Today, the topic is storage. Data is growing at an enormous rate, so what does the future hold?

Play
ARN news
  • Weekly Tech News Update: 8th September, 2008

    We're back again at the IFA consumer electronics show in Berlin where a virtual mirror helps you see the latest fashions, Samsung introduces a laptop that's lighter than air, and a prototype LCD TV is the thinnest on the show floor.

Play
Channel Watch
  • Brian's bloopers

    It takes a long time to produce an episode of Channel Watch. Maybe you'll understand why after watching this...

Play
Business Continuity & Disaster Recovery Zone

When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
ARN Vendor Directory
ARN Library

V/Line and Oakton use Microsoft SQL Server 2008 to develop an Executive HR Dashboard

With the help of Oakton, V/Line - Victoria's regional public transport provider - utilised Microsoft SQL Server 2008 to develop an Executive HR Dashboard report.

Sponsored Links