• Jump to Left Menu
  • Jump to Right Menu
  • Jump to Main Content
  • Jump to Footer
  • Accessibility Page
BARC BI Survey 13 banner
IT-Director.com Logo

 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • EVENTS
  • NEWSWIRE
  • BLOGS

  

Register For Membership | Member Login

 
 
DOMAINS
  • Business Issues
  • Channels
  • Enterprise
  • Services
  • SME
  • Technology
FEATURED EVENTS
  • Performance and Risk Control
    21st June
    Webinar (online)
  • Brainstorm San Francisco 2013
    24th June - 27th June
    Burlingame CA, USA
POPULAR PAPERS
  • Exploiting the Internet of Things with investigative analytics by Bloor Research
USEFUL LINKS
  • Last 7 Days
  • Archives
  • Top Articles
SHARE THIS PAGE
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Observations - "Everyone who ever walked barefoot into his child's room late at night hates Lego." - Tony Kornheiser

PAGE TOOLS
RECENT POSTS
  • CA - Same old same old, or new opportunities?
  • Dreaming of the perfect trip
  • Policing the virtual perimeter
  • Kaspersky Lab - Russia's IT security jewel
  • Is the use of cloud sharing systems worrying you?
  • The age of bring-your-own-identity (BYOID)
ADVERTISEMENT
BLOG ARCHIVE
  • May, 2013
  • April, 2013
  • March, 2013
  • February, 2013
  • January, 2013
  • November, 2012
  • October, 2012
  • September, 2012
  • August, 2012
  • July, 2012
  • June, 2012
  • May, 2012
Blogs > Quocirca

Beyond point security: advance IT security intelligence

Bob Tarzey By: Bob Tarzey, Service Director, Quocirca
Published: 12th June 2012
Copyright Quocirca © 2012
Logo for Quocirca
Tweet

Point security products such as firewalls, host-based anti-virus and email filtering have a job to do and often do it reasonably well. Arguably if they did not businesses would not buy them, although sometimes purchases are made more for compliance purposes than security ones; for example installing full disk encryption on laptops because the data commissioner’s office says it should be.

However, even if the best point security products are in place, this does not mean 100% security; they all miss things. Many anti-virus products rely on malware samples having been previously recorded and added to the vendor’s databases; new malware (a “zero-day” attack) is not so easily spotted. Intrusion prevention systems will do nothing to stop a hacker gaining access with stolen credentials.

To get a broader insight into the effectiveness of their IT security and compliance posture, businesses have been investing in security information and event management (SIEM) tools over the last decade or so. These tools allow them to see what has being going across their systems, for example comparing router logs with server access requests to notice that data was copied to a particular IP address using the credentials of a former employee. Such hindsight is useful, but it would be better if such events could be identified and stopped as they happen.

This is now possible. Some of the leading vendors of SIEM tools have souped them up and linked with intelligence engines that co-ordinate policy. This enables them to act as real time defence mechanisms, providing an additional security overlay to supplement point security products - so called next generation SIEM or advanced IT security intelligence. This enables sophisticated correlations of log data, event data and other IT intelligence data to identify and take action of a wide range of IT security, compliance and other issues.

Quocirca will be discussing how advanced IT security intelligence can be used to protect against a range issues in a webinar on June 19th with McAfee. These include: 

  • Stopping an impossible access request
  • Identifying and preventing zero day attacks
  • Linking physical and IT security to protect critical infrastructure
  • Spotting and stopping suspicious sys-admins’ activity

To find out more and register for the event please click here.

Reader Comments

We have not received any comments against this entry. Why not be the first?

We automatically stop accepting comments 180 days after a post is published. If you would like to know more about this subject, please contact us and we'll try to help.

  • Contact
  • | Site Map
  • | Terms of Use
  • | Privacy Policy
  • | Cookie Policy

Published by: Electronicdawn Ltd.
T: +44 (0)190 888 0760 | F: +44 (0)190 888 0761