<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Log Management &#38; SIEM for Security, Compliance, Operations &#124; the dialog &#187; botnet</title>
	<atom:link href="http://blog.logrhythm.com/tags/botnet/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.logrhythm.com</link>
	<description>Log Management &#38; SIEM for Security, Compliance, Operations &#124; the dialog</description>
	<lastBuildDate>Tue, 24 Apr 2012 15:35:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
		<item>
		<title>Arming Your Network Against Advanced Persistent Threats (APTs)</title>
		<link>http://blog.logrhythm.com/security/arming-your-network-against-advanced-persistent-threats-apts/</link>
		<comments>http://blog.logrhythm.com/security/arming-your-network-against-advanced-persistent-threats-apts/#comments</comments>
		<pubDate>Fri, 16 Jul 2010 17:40:43 +0000</pubDate>
		<dc:creator>eknight</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[advanced persistent threat]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[log management]]></category>
		<category><![CDATA[security information and event management]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[botnet,security information and event management,advanced persistent threat,log management <a href="http://blog.logrhythm.com/security/arming-your-network-against-advanced-persistent-threats-apts/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Ever since Google was hacked by the notorious <a href="http://en.wikipedia.org/wiki/Operation_Aurora" target="_blank">&#8220;Operation Aurora&#8221;</a>, the term <a href="http://en.wikipedia.org/wiki/Advanced_Persistent_Threat" target="_blank">Advanced Persistent Threat</a> has come to the forefront of the computer security challenges organizations must face.   APTs are attacks originating from groups with government-level funding, with considerable patience to wait for an opportunity to exploit, and have a specific mission they are performing.</p>
<p>I&#8217;ve met the whole concept of APTs with personal skepticism.  After all, the analysis of Google&#8217;s hack did not prove that the Chinese government was directly responsible, that the tools used exceeded the complexity of <a href="http://en.wikipedia.org/wiki/Botnet" target="_blank">botnets</a> formed by malware such as Bagle or Cornflicker, or that a basic penetration test could not have yielded similar results against any company, let alone an open-architected, public minded company such as Google.</p>
<p>Regardless, there are many respected researchers that do claim the attack was government sponsored and that the attack was carried out with significant sophistication.  They claim far more resources are likely pushed into funded cyber attacks against influential organizations as a result of copycats from other governments and well funded criminal groups.</p>
<p>For those who have been dealing with cyber crime during the last decades, these threats sound similar to threats that have been seen all along.  Criminal profit-motivated organizations have created sophisticated malware with command and control systems that, among other things, search and steal anything of value from an infected computer and send it to data collecting exfiltration servers located in shady data centers all around the world.</p>
<p>The role of integrated <a href="http://www.logrhythm.com/Applications/SIEM/tabid/87/Default.aspx" target="_blank">Security Information and Event Management (SIEM)</a> and <a href="http://www.logrhythm.com/Products/LogandEventManagement/LogManagement/tabid/77/Default.aspx" target="_blank">Log Management</a> products such as LogRhythm are coming to the forefront of APT defense, establishing them as a fundamental element of security that is just as important as the old familiar defenses.  APTs are likely to have a centralized command and control, and the defense is to have at least the same capabilities as the attacker, in the form of a Security Information and Event Manager.</p>
<p>Regardless if you are concerned about emerging threats from cyber crime, insider threat or feel your organization has a direct threat from government sponsored APTs, SIEM solutions like LogRhythm are an invaluable tool to respond to complex and targeted threats against your organization by addressing the following:</p>
<p>1) Event Layer collection, analysis, and reducing log data to highlight events of importance.<br />
2) Automatic notification of compromises and security critical events<br />
3) Robust and deep forensics abilities on a wide variety of log sources<br />
4) Understandable dashboard highlighting activities and trends for the organization<br />
5) Internal / External system awareness and <a href="http://www.logrhythm.com/Products/GeolocationVisualization/tabid/365/Default.aspx" target="_blank">GeoLocation</a> identification of attackers<br />
6) Detection and notification of potential data loss events</p>
<p>Without the right SIEM solution an organization may seem blind to even basic threats.  The illumination provided by a SIEM can expose complicated and unknown threats by tracking information with enough detail to spot anomalous behavior that APTs are not capable of hiding.  SIEMs are the most significant countermeasure against Advanced Persistent Threats available and are critical for stepping up to limit the impact of APTs.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.logrhythm.com/security/arming-your-network-against-advanced-persistent-threats-apts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Importance of Real-Time Analysis for Security and Operations</title>
		<link>http://blog.logrhythm.com/security/the-importance-of-realtime-analysis-for-security-and-operations/</link>
		<comments>http://blog.logrhythm.com/security/the-importance-of-realtime-analysis-for-security-and-operations/#comments</comments>
		<pubDate>Sun, 09 May 2010 13:41:00 +0000</pubDate>
		<dc:creator>theisler</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[real-time alerting]]></category>
		<category><![CDATA[siem]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[botnet,information security,real-time alerting,siem <a href="http://blog.logrhythm.com/security/the-importance-of-realtime-analysis-for-security-and-operations/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>As I&#8217;m sitting out on the back patio enjoying a beautiful spring morning on Mother&#8217;s Day morning  I thought I&#8217;d momentarily press the pause button and delay my familial responsibility for cooking the most amazing breakfast ever, to talk for a bit about the significance of real-time information access as it relates to Log and Event Management (SIEM).</p>
<p>What prompted me to address real-time?  The simple fact that there&#8217;s been a lot of action in the news the last couple of weeks dealing with the real-time &#8216;fires&#8217; that need to be put out.  Between the recent unsuccessful Times Square Car Bomber to the &#8216;difficult to wrap-your-head around&#8217; massive oil leaks vomiting hundreds of thousands of barrels of oil into the Gulf, real-time access to relevant is an absolute critical component to our investigative capacity to both identify and stop these types of threats.</p>
<p>Take the <a href="http://news.yahoo.com/s/ap/20100504/ap_on_re_us/us_times_square_car_bomb" target="_blank">Times Square Bomber, Faisal Shahzad</a>, for example.  Despite a wealth of forensic data tying him to the bombing attempt, and a relatively quick path to identifying him as a suspect, Shahzad was minutes from successfully fleeing the country on a commercial airliner.  Why?  Because the process for adding his name to a no-fly list was not in real-time and the TSA was not notified until he had already boarded the plane.  Fortunately federal officials were able to turn the plane around before take-off and apprehend him.</p>
<p>Likewise, the <a href="http://en.wikipedia.org/wiki/Deepwater_Horizon_drilling_rig_explosion" target="_blank">Deepwater Horizon oil spill</a> is the result of a combination of process and technical breakdowns.  A critical mechanical failure combined with a deadly buildup in methane gas going undetected ultimately caused a catastrophic explosion.  The resulting environmental and economic disaster will be felt for years.  It&#8217;s hard not to wonder what might have been different if the right people were notified of the faulty equipment in time to repair it, or if the methane build-up had been detected and eliminated before reaching critical mass.</p>
<p>And it&#8217;s no stretch that these examples are analogous to an enterprise I.T. environment &#8212; the power of real-time analysis is unmistakable.  I&#8217;ve worked in I.T. environments where there was an infection that was undetected by the myriad of security products from the host based security tools to the NIDS product sniffing off the wire.  Whether this infection was a zero-day exploit or simply just missed by the security products is another story &#8211; either way the question is, <a href="http://logrhythm.com/Applications/Security/tabid/87/Default.aspx" target="_blank">&#8216;How do you identify the root cause and prevent it&#8230;rapidly?&#8217;</a> Just as more pieces to a complex puzzle help paint the whole picture, access to log data from disparate sources provide core pieces to the puzzle providing the analyst visibility into the labyrinth of data available to help identify root cause.  In order to accomplish this effectively you&#8217;ll need &#8216;fingertip&#8217; access to all log data.  Moreover, you&#8217;ll want to be able to view the data in real-time, at the time of capture.</p>
<p>In the example above, we were able to quickly identify the port the <a href="http://en.wikipedia.org/wiki/Botnet" target="_blank">botnet</a> was communicating on and quickly target the source IP address for communications from internal systems attempting to communicate on that port.  This uncovered, in real-time, over 25 systems throughout the enterprise that were infected (by DNS name and IP address) and these systems were quickly removed from the network and cleansed.</p>
<p>Although in this example we&#8217;re discussing a security-related issue, the real-time use-case carries over into other parts of our business including operations.  Consider a virtualized environment heavily reliant on the underlying system to run hundreds of production systems.  What happens if the underlying system has an issue that potentially impacts our production environment?  A critical failure in this case could create a significant event, impacting the business as a whole.  I&#8217;ve dealt with this in the field and real-time access to the log data provided the root cause analysis necessary to understand the issue.  This in turn triggered the effort to quickly resolve the &#8216;now known&#8217; issue.  The moral of the story:  Immediate access to real-time log data can provide the magnet every analyst needs to quickly find the needle in their haystack.</p>
<p>Okay &#8211; I think I hear the kids stirring so I better focus on my wife and family before I get in trouble for working on this, of all days.  Happy Mother&#8217;s day to all the moms out there.</p>
<p>To see some ideas for how you can help with the environmental cleanup and humanitarian efforts of what is being predicted to be one of the worst environmental catastrophes in United States history, please visit:<br />
<a href="http://www.sierraclub.org/" target="_blank">http://www.sierraclub.org/</a><br />
<a href="http://crcl.org/" target="_blank">http://crcl.org/</a><br />
<a href="https://secure.oxfamamerica.org/site/Donation2?df_id=4360&amp;4360.donation=form1&amp;JServSessionIdr004=hxfvbljiv1.app240a" target="_blank">https://secure.oxfamamerica.org/site/Donation2?df_id=4360&amp;4360.donation=form1&amp;JServSessionIdr004=hxfvbljiv1.app240a</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.logrhythm.com/security/the-importance-of-realtime-analysis-for-security-and-operations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

