Home > Information Security Magazine > Features > SIMs maturing and suitable for mid-market
EMAIL THIS
Information Security Magazine

  CURRENT ISSUE  

  FEATURES  

  COLUMNS  

  HOT PICK & PRODUCT REVIEWS  

  ARCHIVES  

  SUBSCRIBE/RENEW  
 

SIMs maturing and suitable for mid-market
Issue: Jun 2007
printer-friendly
< PREV PAGE   |   1  |   2  |   3  |   4  |   5  |   6  |   7  |   NEXT PAGE  >

Stronger Rule Technology
The heart of most SIMs is a set of business rules that help tune the correlation engine and identify what log data, events and security problems are worthy of alerts or active responses. In our 2004 testing, we found that most products had a small set of rules that were inadequate starting points.

In that test, SIM vendor OpenService stood apart with a rule-free approach to correlation, and hasn't changed its approach. No one else has entered that lonely niche. The opposite seems to be true; SIM vendors, particularly those supplying mid-range appliances, have responded with much stronger business rules out-of-the-box aimed at speeding deployment and sharing the considerable expertise they've ga...



ined in what works in a SIM.

For example, High Tower ships its SEM appliance with a set of 65 "mega-rules" that catch everything from unauthorized MySpace.com visits to successful brute-force logins.

Vendors also are enhancing their tools for building rules. TriGeo, which ships its SIM with more than 500 starting point rules, has an elegant rule definition tool that actively encourages the security manager to creatively add protections and alerts within the SIM, rather than making definition of rules an onerous task. Although TriGeo outwardly aims at networks of 100 to 150 devices, the business rule features in its SIM are so well designed that they put to shame this aspect of many other SIMs.

[IMAGE]

< PREV PAGE   |   1  |   2  |   3  |   4  |   5  |   6  |   7  |   NEXT PAGE  >





TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts