Home > Security Security Schools > Integration of Networking and Security School > SIMs: Security and network management integration > Challenges behind operational integration of security and network management
Security Schools: Integration of Networking and Security School:
EMAIL THIS
 START   ENDPOINT 101   SIMS   NAC   NETWORK   UNIFIED COMM   APP SECURITY   SNYDER   REMOTE   FABRIC   WIRELESS   
SIMs: Security and network management integration

<< PREVIOUS | NEXT >>: Quiz:: Marrying security and networking tools
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

Challenges behind operational integration of security and network management


Sasan Hamidi, Contributor
02.05.2008
Rating: -3.20- (out of 5)


Network Security Tactics
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


This tip is part of SearchSecurity.com's Integration of Networking and Security School lesson Marrying security and network management tools. Visit the school and lesson home pages for additional learning resources.

The integration of security and network operation centers has become a hot topic among security and information technology professionals looking to not only consolidate tools and resources of their respective organizations, but also to harness and manage their shared nemesis: risk.

Traditional organizations build separate infrastructure for monitoring security and network events. It makes sense since network operations teams are concerned with statistics like "meantime between failures" (MTBF), which is tied to service level agreements (SLAs), server utilization, heat issues and alike. On the other hand, the information security team is tracking security events generated by the same servers, routers and other infrastructure. They track worms and viruses, check email security status and overall information security health of the organization. With these many varied interests and functions, SOCs and NOCs operate separately using their own tools and resources and all the while, they are both managing risk.

A bit about SIMs
In the past three years, security information management systems (SIMs) have become the type of technology that security operations centers are built on. Intrusion detection and prevention systems (IDS/IPS), firewalls, routers, server farms and network access control infrastructure all can send their security events to a SIM through SNMP or SYSLOG. That means there is no longer a need to have multiple consoles to monitor these environments. SIMs have built-in correlation and intelligence to decipher millions of alerts and report only those that are critical in nature. Today's SIM technology even includes system health information, although this is not a SIM's primary function.

However, the br



oad functionality and other benefits of SIMs come with a price: complexity in implementation and operation. Some of the complexities have been highlighted below.

  • Requires many changes to policies, procedures, and processes
  • Generates constant, ongoing alerts (which requires monitoring)
  • SIM challenges
    Perhaps the biggest challenge in a successful SIM project is not overcoming deployment issues, like training the personnel on using the technology, but managing the aftermath of deployment, when all of the mission-critical and vital business infrastructure components are sending their security events to the SIM database. Even with the correlation engine tuned and most basic out-of-the-box filters in place, the number of alerts generated could be overwhelming.

    In a typical scenario, the number of false positives (false alerts, where one is generated that in actuality does not exist) comprised almost 80% of the total alerts reported. The problem is that without thorough study and investigation, even the most technically knowledgeable staff cannot be certain that an alert is in fact false positive.

    To integrate a SIMs into a useful tool that both SOC and NOC team members can utilize, the process of successfully "filtering" alerts takes utmost priority. Below are helpful tips on filtering SIM events:

  • Mainframe (AS400)
  • Work with SIM vendor to sort through alerts
  • Provide alert detail to CISO
  • Provide alert detail to system administrators
  • Stop message flow from the source
  • Stop message flow at SIM
  • Examine "canned" rules & write rules customized for your environment
  • Cross-training personnel
    In a study designed to measure ROI of integrating SIMs into network services at Interval International Inc., one of the biggest surprises was how beneficial "early" cross training was. Interval sent a senior information security analyst (SISA) and a senior network engineer (SNE) to an offsite vendor cross-training program. For a period of six months following the formal training, two network personnel worked with the SIM team rotating shifts for six hours per week. The SISA also spent time with the network team, working on fine-tuning the HP OpenView tool and managed to send its SNMP traps to the SIM database.

    A study showed that productivity of both department increased by more than 22% in the last quarter of fiscal year 2007. However, the intangible and immeasurable index of team building and increased integration effort are invaluable.

    In summary, despite the numerous challenges of using SIMs to help integrate NOCs and SOCs, it is worthwhile because of the ability to monitor events in real time, introduce an event-correlation engine or network behaviorial analysis detection (NBAD), improve forensics analysis, and essentially have it serve as the foundation for your SOC team and improve the NOC group's efficiency.

    About the author:
    Sasan Hamidi is currently the chief security officer for Interval International, a global vacation and timeshare exchange company headquartered in Miami. Interval is a company under the umbrella of InterActive Corp. with sister organizations such as Expedia, HSH, Hotels.com, TicketMaster, Lendingtree, HotWire and a host of others. Hamidi is a frequent industry speaker, including at Information Security Decisions.


    Rate this Tip
    To rate tips, you must be a member of SearchSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    BROWSE BY TAG
    Network Security Tactics,   Security Event Management,   Network Intrusion Detection and Analysis,   Enterprise Network Security,   Integration of Networking and Security School,   SIMs: Security and network management integration,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    << PREVIOUS | NEXT >>: Quiz:: Marrying security and networking tools
    VIEW ALL IN THIS CATEGORY

    RELATED CONTENT
    Network Security Tactics
    Screencast: Samurai offers pen-testing nirvana
    Firewall rule management best practices
    Chained Exploits: How to prevent phishing attacks from corporate spies
    Rootkit Hunter demo: Detect and remove Linux rootkits
    Enterprise UTM security: The best threat management solution?
    Making the case for network security configuration management
    An inside look at security log management forensics investigations
    How to find sensitive information on the endpoint
    How to perform Microsoft Baseline Security Analyzer (MBSA) scans
    How to spot attacks through Apache Web server log analysis

    Security Event Management
    Mature SIMs do more than log aggregation and correlation
    SIMs tools and tactics for business intelligence
    SIEM: Not for small business, nor the faint of heart
    Should IDS and SIM/SEM/SIEM be used for network intrusion monitoring?
    Tying log management and identity management shortens incident response
    How to estimate log generation rates
    SANS Log Management Survey is "Looking for the ROI"
    Review system event logs with Splunk
    Virtual network tool gives firm view into virtualized environment
    Mining enterprise SIM logs for relevant security event data

    SIMs: Security and network management integration
    Quiz:: Marrying security and networking tools

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Research Solutions for Network Security, Access Control and Security Threats
    More Security Resources for Resellers, VARs and OEMs
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts