Home > Ask the Security Experts > Network Security Questions & Answers > What reporting tools are available for an enterprise IDS?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What reporting tools are available for an enterprise IDS?

Mike Chapple EXPERT RESPONSE FROM: Mike Chapple

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 11 May 2008
What reporting and correlation tools are available for use when setting up an IDS on an enterprise network? Are there open-source options?

>
EXPERT RESPONSE
Reporting and correlation of security information is a hot topic in our field today. Modern security analysts have a ton of information at their fingertips and can easily become overwhelmed by the variety and quantity of audit records. In addition to intrusion detection systems (IDS), log archives often contain data from operating system logs, network devices, antivirus software, firewalls, authentication systems and numerous other sources.

What's a security professional to do with all of this data? A variety of tools in the security information management/security event management (SIM/SEM) family offer the consolidated reporting and correlation that you seek. In addition to a number of commercial tools, there are open source options, such as the Open Source Security Information Manager (OSSIM) project. For a more detailed look at the SIM/SEM market, read the tip Security Information Management Finally Arrives, Thanks to Enhanced Features.

More information:


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Network Security
What are the differences between intrusion detection and intrusion prevention?
Will there be DMZ routing issues if several firewalls serve as the default gateway?
What are the top LAN security issues in a client-server network environment?
Should tunnel connections be initiated from an ISP to a internal data center, or vice versa?
What warning signs will indicate the presence of a P2P botnet?
Is it possible to allow select access to IP addresses using Windows Server 2003?
Is an IPsec VPN necessary when connecting remote servers that process financial transactions?
What are best practices for creating an IDS and maintaining a signature database?
What are the best ways to hide system information from network scanning software?
What are the security risks of opening all the ports on an internal router?

Security Event Management
Virtual network tool gives firm view into virtualized environment
Mining enterprise SIM logs for relevant security event data
Quiz: Getting the most out of your SIM deployment
NitroSecurity covers its bases with RippleTech deal
Is centralized logging worth all the effort?
Product review: Novell's Sentinel 6.0
Challenges behind operational integration of security and network management
Log management push has its roots in compliance
How well can network behavior anomaly detection (NBAD) products detect rootkits and malware?
SIMs

Open Source Security Tools
Screencasts: On-screen demonstrations of today's IT tools
FISMA compliance made easier with OpenFISMA
Wireshark tutorial: How to sniff network traffic
Screencast: How to use Nipper to create network security reports
Sun launches open source OpenSSO for identity management
Positive changes coming to ModSecurity
Analysis tool uses Intel virtualization to hide from malware
Can IBM's SMash technology secure Web applications?
Using Nessus Attack Scripting Language (NASL) to find application vulnerabilities
What are best practices for creating an IDS and maintaining a signature database?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Back Orifice  (SearchSecurity.com)
Blowfish  (SearchSecurity.com)
Kermit  (SearchSecurity.com)
Open Source Hardening Project  (SearchSecurity.com)
Snort  (SearchSecurity.com)
SnortSnarf  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
Targeted Security Channel Tips for Resellers, Integrators and Consultants
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts