SlideShare a Scribd company logo
Improve Threat Detection with OSSEC and AlienVault USM
About AlienVault
AlienVault has unified the security products, intelligence and
community essential for mid-sized businesses to defend against
today’s modern threats
Agenda
OSSEC capabilities
AlienVault USM capabilities
Demo – See it in action
• Remote OSSEC agent deployment, configuration and management
• Behavioral monitoring of servers and workstations
• Logging and reporting for PCI compliance
• Data correlation with IP reputation data, vulnerability scans and more
• Correlating OSSEC events to detect attacks
OSSEC & AlienVault USM
Learning the Basics…
OSSEC capabilities
Log analysis based intrusion detection
File integrity checking
Registry keys integrity checking (Windows)
Signature based malware/rootkits detection
Real-time alerting and active response
OSSEC Architecture
Agent components:
Logcollectord: Read logs (syslog, WMI, flat files)
Syscheckd: File integrity checking
Rootcheckd: Malware and rootkits detection
Agentd: Forwards data to the server
Server components:
Remoted: Receives data from agents
Analysisd: Processes data (main process)
Monitord: Monitor agents
ASSET DISCOVERY
• Active Network Scanning
• Passive Network Scanning
• Asset Inventory
• Host-based Software Inventory
VULNERABILITY ASSESSMENT
• Continuous
Vulnerability Monitoring
• Authenticated / Unauthenticated
Active Scanning
BEHAVIORAL MONITORING
• Log Collection
• Netflow Analysis
• Service Availability Monitoring
SECURITY INTELLIGENCE/SIEM
• SIEM Event Correlation
• Incident Response
THREAT DETECTION
• Network IDS
• Host IDS
• File Integrity Monitoring
USM Platform
Integrated, Essential Security Controls
AlienVault USM Architecture
Embedded tools:
Asset discovery: Nmap, Prads
Behavioral monitoring: Netflow, Ntop, Nagios
Threat detection: Snort, Suricata, OSSEC
Vulnerability assessment: OpenVas
External collectors:
Syslog
WMI
SDEE
AlienVault Event Correlation
AlienVault USM correlates events from multiple sources, crossing OSSEC alerts
with information collected from embedded detectors and external sources.
OSSEC Management Interface
• Status monitor
• Events viewer
• Agents control manager
• Configuration manager
• Rules viewer/editor
• Logs viewer
• Server control manager
• Deployment manager
• Rules viewer/editor
AlienVault USM provides a comprehensive GUI for OSSEC alerts management:
Let’s See It In Action
888.613.6023
ALIENVAULT.COM
CONTACT US
HELLO@ALIENVAULT.COM
Test Drive AlienVault USM
Download a Free 30-Day Trial
http://www.alienvault.com/free-trial
Try our Interactive Demo Site
http://www.alienvault.com/live-demo-site
Now for some Q&A..
Questions? Hello@AlienVault.com
Twitter : @alienvault

More Related Content

PPTX
ciberseguridad.pptx
PDF
Fire Detection System using GSM Module
PDF
Presupuesto a medida. pc componentes PRUEBA
PPTX
Modelo de proceso especializado
PPTX
Smart Home Automation And security System
PPTX
Togaf
PPTX
Seguridad Logica.pptx
PPTX
Arquitectura Multiprocesadores
ciberseguridad.pptx
Fire Detection System using GSM Module
Presupuesto a medida. pc componentes PRUEBA
Modelo de proceso especializado
Smart Home Automation And security System
Togaf
Seguridad Logica.pptx
Arquitectura Multiprocesadores

What's hot (20)

PDF
Arduino Based Home Lighting Control by Android Phone
PPTX
Administración de la función informática: Seguridad fisíca y lógica en el cen...
PDF
Automatic room temperature controlled fan using arduino uno microcontroller
ODP
Ambient intelligence
PPT
Metricas de Codigo Fuente y Metricas de Prueba
PDF
IOT: Home Automation using Android Application
DOCX
Formato guia de aprendizaje sistemas instalacion de software
PDF
Seminario 3 reutilización del software
DOCX
Ubiquitous computing abstract
PPTX
FYP PRESENTATION-ROOM MONITORING SYSTEM USING IOT
PPTX
GEOLOCALIZACION
PPTX
Atm Security System Using Steganography Nss ptt by (rohit malav)
PPTX
Smart Home / Smart Office
PPTX
Seguridad de los Sistemas Operativos
PPTX
Internet of Things Iot presentation with module
PPTX
CYBER-PHYSICAL-SYSTEM.pptx
PPTX
Terminal Server
PPTX
Simulacion y Modelacion
PPTX
Fuente de alimentacion
Arduino Based Home Lighting Control by Android Phone
Administración de la función informática: Seguridad fisíca y lógica en el cen...
Automatic room temperature controlled fan using arduino uno microcontroller
Ambient intelligence
Metricas de Codigo Fuente y Metricas de Prueba
IOT: Home Automation using Android Application
Formato guia de aprendizaje sistemas instalacion de software
Seminario 3 reutilización del software
Ubiquitous computing abstract
FYP PRESENTATION-ROOM MONITORING SYSTEM USING IOT
GEOLOCALIZACION
Atm Security System Using Steganography Nss ptt by (rohit malav)
Smart Home / Smart Office
Seguridad de los Sistemas Operativos
Internet of Things Iot presentation with module
CYBER-PHYSICAL-SYSTEM.pptx
Terminal Server
Simulacion y Modelacion
Fuente de alimentacion
Ad

Similar to Improve Threat Detection with OSSEC and AlienVault USM (20)

PPTX
Advanced OSSEC Training: Integration Strategies for Open Source Security
PPTX
How to Detect a Cryptolocker Infection with AlienVault USM
PPTX
Improve Situational Awareness for Federal Government with AlienVault USM
PPTX
Watering Hole Attacks: Detect End-User Compromise Before the Damage is Done
PPTX
New USM v5.0 - Get Complete Security Visibility Faster & Easier Than Ever
PDF
Incident Response Whitepaper - AlienVault
PPTX
Meltdown and Spectre - How to Detect the Vulnerabilities and Exploits
PPTX
Improve threat detection with hids and alien vault usm
PPTX
How Malware Works
PPTX
Alienvault threat alerts in spiceworks
PPTX
Spice world 2014 hacker smackdown
PDF
USM appliance datasheet 2024 latest 070324
PPTX
How to Solve Your Top IT Security Reporting Challenges with AlienVault
PPTX
Best Practices for Configuring Your OSSIM Installation
PPTX
Security Operations Center (SOC) Essentials for the SME
PPTX
How to Investigate Threat Alerts in Spiceworks!
PPTX
New OSSIM v5.0 - Get Security Visibility Faster & Easier Than Ever
PPTX
Insider Threats: How to Spot Trouble Quickly with AlienVault USM
PPTX
SpiceWorks Webinar: Whose logs, what logs, why logs
PPTX
The Lazy Attacker: Defending Against Broad-based Cyber Attacks
Advanced OSSEC Training: Integration Strategies for Open Source Security
How to Detect a Cryptolocker Infection with AlienVault USM
Improve Situational Awareness for Federal Government with AlienVault USM
Watering Hole Attacks: Detect End-User Compromise Before the Damage is Done
New USM v5.0 - Get Complete Security Visibility Faster & Easier Than Ever
Incident Response Whitepaper - AlienVault
Meltdown and Spectre - How to Detect the Vulnerabilities and Exploits
Improve threat detection with hids and alien vault usm
How Malware Works
Alienvault threat alerts in spiceworks
Spice world 2014 hacker smackdown
USM appliance datasheet 2024 latest 070324
How to Solve Your Top IT Security Reporting Challenges with AlienVault
Best Practices for Configuring Your OSSIM Installation
Security Operations Center (SOC) Essentials for the SME
How to Investigate Threat Alerts in Spiceworks!
New OSSIM v5.0 - Get Security Visibility Faster & Easier Than Ever
Insider Threats: How to Spot Trouble Quickly with AlienVault USM
SpiceWorks Webinar: Whose logs, what logs, why logs
The Lazy Attacker: Defending Against Broad-based Cyber Attacks
Ad

More from AlienVault (19)

PDF
Malware Invaders - Is Your OS at Risk?
PPTX
Simplify PCI DSS Compliance with AlienVault USM
PDF
SIEM for Beginners: Everything You Wanted to Know About Log Management but We...
PDF
Insider Threat Detection Recommendations
PDF
Open Source IDS Tools: A Beginner's Guide
PPTX
Malware detection how to spot infections early with alien vault usm
PDF
Security operations center 5 security controls
PDF
PCI DSS Implementation: A Five Step Guide
PDF
The State of Incident Response - INFOGRAPHIC
PPTX
Incident response live demo slides final
PPTX
Improve Security Visibility with AlienVault USM Correlation Directives
PPTX
AWS Security Best Practices for Effective Threat Detection & Response
PPTX
IDS for Security Analysts: How to Get Actionable Insights from your IDS
PDF
Alien vault sans cyber threat intelligence
PPTX
Security by Collaboration: Rethinking Red Teams versus Blue Teams
PPTX
Prepare to Be Breached: How to Adapt your Security Controls to the “New Normal”
PPTX
How to Detect System Compromise & Data Exfiltration with AlienVault USM
PPTX
Demo how to detect ransomware with alien vault usm_gg
PPTX
Planning your 2015 Threat Detection Strategy with a Broken Crystal Ball
Malware Invaders - Is Your OS at Risk?
Simplify PCI DSS Compliance with AlienVault USM
SIEM for Beginners: Everything You Wanted to Know About Log Management but We...
Insider Threat Detection Recommendations
Open Source IDS Tools: A Beginner's Guide
Malware detection how to spot infections early with alien vault usm
Security operations center 5 security controls
PCI DSS Implementation: A Five Step Guide
The State of Incident Response - INFOGRAPHIC
Incident response live demo slides final
Improve Security Visibility with AlienVault USM Correlation Directives
AWS Security Best Practices for Effective Threat Detection & Response
IDS for Security Analysts: How to Get Actionable Insights from your IDS
Alien vault sans cyber threat intelligence
Security by Collaboration: Rethinking Red Teams versus Blue Teams
Prepare to Be Breached: How to Adapt your Security Controls to the “New Normal”
How to Detect System Compromise & Data Exfiltration with AlienVault USM
Demo how to detect ransomware with alien vault usm_gg
Planning your 2015 Threat Detection Strategy with a Broken Crystal Ball

Improve Threat Detection with OSSEC and AlienVault USM

  • 2. About AlienVault AlienVault has unified the security products, intelligence and community essential for mid-sized businesses to defend against today’s modern threats
  • 3. Agenda OSSEC capabilities AlienVault USM capabilities Demo – See it in action • Remote OSSEC agent deployment, configuration and management • Behavioral monitoring of servers and workstations • Logging and reporting for PCI compliance • Data correlation with IP reputation data, vulnerability scans and more • Correlating OSSEC events to detect attacks
  • 4. OSSEC & AlienVault USM Learning the Basics…
  • 5. OSSEC capabilities Log analysis based intrusion detection File integrity checking Registry keys integrity checking (Windows) Signature based malware/rootkits detection Real-time alerting and active response
  • 6. OSSEC Architecture Agent components: Logcollectord: Read logs (syslog, WMI, flat files) Syscheckd: File integrity checking Rootcheckd: Malware and rootkits detection Agentd: Forwards data to the server Server components: Remoted: Receives data from agents Analysisd: Processes data (main process) Monitord: Monitor agents
  • 7. ASSET DISCOVERY • Active Network Scanning • Passive Network Scanning • Asset Inventory • Host-based Software Inventory VULNERABILITY ASSESSMENT • Continuous Vulnerability Monitoring • Authenticated / Unauthenticated Active Scanning BEHAVIORAL MONITORING • Log Collection • Netflow Analysis • Service Availability Monitoring SECURITY INTELLIGENCE/SIEM • SIEM Event Correlation • Incident Response THREAT DETECTION • Network IDS • Host IDS • File Integrity Monitoring USM Platform Integrated, Essential Security Controls
  • 8. AlienVault USM Architecture Embedded tools: Asset discovery: Nmap, Prads Behavioral monitoring: Netflow, Ntop, Nagios Threat detection: Snort, Suricata, OSSEC Vulnerability assessment: OpenVas External collectors: Syslog WMI SDEE
  • 9. AlienVault Event Correlation AlienVault USM correlates events from multiple sources, crossing OSSEC alerts with information collected from embedded detectors and external sources.
  • 10. OSSEC Management Interface • Status monitor • Events viewer • Agents control manager • Configuration manager • Rules viewer/editor • Logs viewer • Server control manager • Deployment manager • Rules viewer/editor AlienVault USM provides a comprehensive GUI for OSSEC alerts management:
  • 11. Let’s See It In Action
  • 12. 888.613.6023 ALIENVAULT.COM CONTACT US HELLO@ALIENVAULT.COM Test Drive AlienVault USM Download a Free 30-Day Trial http://www.alienvault.com/free-trial Try our Interactive Demo Site http://www.alienvault.com/live-demo-site Now for some Q&A.. Questions? Hello@AlienVault.com Twitter : @alienvault