Symantec SIM brings friends
What is it, one might reasonably ask, that separates a SIM (security information manager) from a basic log-file aggregator? Both will, of course, aggregate log files, but a SIM must go further, gathering incident alerts and status conditions from a variety of network security and infrastructure sources. A good SIM will then add some intelligence to the mix, helping the security engineer figure out which information is worth his or her immediate attention and which can be ignored until time to pass a compliance audit.
This last step separates the very good SIM from the merely competent, and it's where the security intelligence found in the Symantec SIM (SSIM) 9650 appliance shines. Like many SIMs, the Symantec system improves with each new data point (that is, component providing data) it has to chew on. Unlike many SIMs, Symantec's has its own Global Intelligence Network of analysts, experts, and OPSIMs (other people's SIMs) to throw into the intelligence mix.
If your network can provide a deep pool of data for the Symantec SIM to swim in, it can provide a wealth of detailed information to your security engineer. Be aware, though, that this isn't a product for security novices. If you think of it as an able assistant to your in-house security expert, you're on the right track. Given the system's intelligence, it might be tempting for admins to treat the tool as an expert replacement. Doing so in a small network with relatively few data sources, you're likely to be disappointed. If, on the other hand, you put one of these in a rich network beside a capable security staff, you'll find it a truly valuable addition to your security infrastructure.
Looking at the network
As SIMs go, Symantec's installs quickly. When you first connect to the SSIM appliance, you download the GUI app and get started. You'll find two logical applications built in to the device: a Web interface for simple administration tasks and a dedicated GUI application for most of the heavy lifting in configuration and analysis.
In my testing, the setup process went smoothly. I experienced just a couple instances of whining because of some quirks in my test environment. The SSIM system isn't particularly happy if you try to sequester it away from DNS (though it will operate after complaining for a few moments), and it uses self-signed certificates that are going to make some desktop clients antsy. As I said, for most production deployment, neither of these will be an issue, but there they are.
There are three broad areas of activity required to get you started: building an asset table, scanning for vulnerabilities, and establishing initial rules. You can perform that asset-table build either manually or automatically. Manual means either entering information through the keyboard (not recommended) or importing tables from just about any popular asset management system. If you don't have an existing asset table handy, the SSIM will build a table by sniffing the traffic on the network -- no active probing goes on. If you already have an asset management system in place, you'll want to import the information so that it will be consistent across systems. If you haven't taken the asset management step, discovery works well, though you'll want to go back into the descriptions to add details (regarding certain system details and asset criticality) that just can't be determined from network traffic alone.
The vulnerability scan is, of necessity, more active and intrusive. The system scans the network and compares the results against known vulnerability databases such as the National Vulnerability Database and the Open Source Vulnerability. The scan is the most benign sort; the SSIM doesn't try to confirm the vulnerability by conducting an exploit.
With assets and vulnerabilities in the database, I looked at the rule set that shipped with the SSIM and found not much there: around 40 rules populating the set. The slim rule set might seem inadequate, but Symantec explained it's a simple baseline; most of the production functionality comes from active data collected and is correlated during operations. I found that to be true, as the SSIM was able to construct information for reports and issue alerts based on information it received and built upon during the test. It's certainly possible to add specific rules yourself, but the need to do that should be limited to unusual cases in your particular network
When networks go bad
For most security analysts, the SSIM dashboard will be the primary window into the appliance's operation. The dashboard grants a real-time view of system operations, and it's customizable across a variety of different values, including the usual criteria you want to see (top talkers, top destinations, alerts, and warnings) and others that are specific to the SSIM, such as alerts from the Global Intelligence Network. The dashboard is tightly tied to the GUI application but can be detached and run on a separate monitor while the GUI continues in administration mode.
- +
Mu Security Analyzer 04 January, 2008 07:28:03
Mu-4000 fuzzer shines with wizard-driven test configuration, intelligent workflow, excellent vulnerability profiling, and auto-generated zero-day exploitsI first came across the Mu Security Analyzer when a co-worker on a multi-company government project raved about how the appliance found a zero-day vulnerability in an e-mail inspection device that was protecting a top secret government agency. It was a rather simple script bug in the other vendor's product, but it would have allowed uncontrolled code execution. The implication was that our top secret project could have been compromised by an external hacker running penetration tests against our e-mail services. Initially, the manufacturer of the compromised mail filter refused to believe that a weakness existed in its product. That is, until we sent the exploit, automatically generated by the Mu analyzer, that the vendor's engineers could run to see for themselves. - +
Packeteer rolls out plan for better WAN app performance 07 December, 2007 09:20:29
Called IntelligenceCenter, the software monitors performance, reports on it and supplies tools to optimize it.Packeteer is introducing a new management platform that draws data from its own and other vendors' gear to boost the performance of applications over the WAN and is the first step in a broader application-performance plan. - +
HP looks to SMBs with new shared storage 13 December, 2007 09:18:34
Modular smart array comes in two productsHP is preparing to launch a new MSA2000 disk array product family for clustered servers, which it is targeting at SMB deployments and remote offices. - +
Linux, Unix, Mac, Windows PCs get authentication integration 06 December, 2007 08:29:57
Centeris releases version 4.0 of Likewise with the intent of making Linux a first-class citizen on Windows networksCenteris, which provides cross-platform authentication via Microsoft's Active Directory, Tuesday enhanced its Likewise platform (Clear Choice Test of Likewise)Â and an added open source project that will be distributed with the top Linux operating systems. - +
Cisco speeds up security device 05 December, 2007 14:49:00
Cisco IPS 4270 screens for internal and external attacksCisco is introducing an intrusion-prevention sensor that is twice as fast its previous high-end device designed to protect high-speed connections to data centers and WAN links without slowing traffic.
Click here for case studies, whitepapers and other useful vendor content When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
PGP and Ponemon Institute Unveil Inaugural Australian Data Breach Study 2008 20 November, 2008 17:34:00
Symantec Cloud Services Transform Data Centre Operations Through Proactive Management 20 November, 2008 12:06:00
Verizon Business Offers Tips to Building a Successful Unified Communications and Collaboration Plan 20 November, 2008 12:04:00
NetApp Named 2008 Citrix Ready Solution of the Year by Citrix Systems 20 November, 2008 11:33:00
Extreme Networks Ethernet Transport lowers total cost of ownership for carrier metro networks 20 November, 2008 10:21:00
WebCentral boosts Security and Reliability with Windows Server 2008
WebCentral, Australia's largest web and application hosting company, relies on Microsoft Windows Server 2008 to deliver the security, manageability and reliability their customers require.











