Home > Ask the Security Experts > Network Security Questions & Answers > What reporting tools are available for an enterprise IDS?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What reporting tools are available for an enterprise IDS?

Mike Chapple, featured expert EXPERT RESPONSE FROM: Mike Chapple, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 11 May 2008
What reporting and correlation tools are available for use when setting up an IDS on an enterprise network? Are there open-source options?


BROWSE BY TAG
Network Security,   Security Event Management,   Network Intrusion Detection and Analysis,   Enterprise Network Security,   Application and Platform Security,   Open Source Security Tools and Applications,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Network Security
Should enterprises be running multiple firewalls?
What are best practices for fiber optic cable security?
What are the disadvantages of proxy-based firewalls?
What is the difference between a VPN and remote control?
What are the best practices for IPS implementation?
How to prevent DDoS attacks on websites
How to configure firewall ports for webmail system implementation
How should service providers address VoIP security issues and threats?
Can S/MIME, XML and IPsec operate in one protocol layer?
How to set up a corporate cell phone management strategy

Security Event Management
Mature SIMs do more than log aggregation and correlation
SIMs tools and tactics for business intelligence
SIEM: Not for small business, nor the faint of heart
Should IDS and SIM/SEM/SIEM be used for network intrusion monitoring?
Tying log management and identity management shortens incident response
How to estimate log generation rates
SANS Log Management Survey is "Looking for the ROI"
Review system event logs with Splunk
Virtual network tool gives firm view into virtualized environment
Mining enterprise SIM logs for relevant security event data

Open Source Security Tools and Applications
Screencast: Samurai offers pen-testing nirvana
Rootkit Hunter demo: Detect and remove Linux rootkits
When to use open source security tools over commercial products
Screencasts: On-screen demonstrations of today's IT tools
Maltego demo: Identifying a website's trust relationships
Free HP SWFScan tool detects Adobe Flash flaws
L0phtCrack returns
How to use (almost) free tools to find sensitive data
Should open source disk-encryption software be used?
Open source security concerns can trump cost savings

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Blowfish  (SearchSecurity.com)
Kermit  (SearchSecurity.com)
Open Source Hardening Project  (SearchSecurity.com)
SnortSnarf  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Reporting and correlation of security information is a hot topic in our field today. Modern security analysts have a ton of information at their fingertips and can easily become overwhelmed by the variety and quantity of audit records. In addition to intrusion detection systems (IDS), log archives often contain data from operating system logs, network devices, antivirus software, firewalls, authentication systems and numerous other sources.

What's a security professional to do with all of this data? A variety of tools in the security information management/security event management (SIM/SEM) family offer the consolidated reporting and correlation that you seek. In addition to a number of commercial tools, there are open source options, such as the Open Source Security Information Manager (OSSIM) project. For a more detailed look at the SIM/SEM market, read the tip Security Information Management Finally Arrives, Thanks to Enhanced Features.

More information:




Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
Targeted Security Channel Tips for Resellers, Integrators and Consultants
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts