Applying Thought Wipro Technologies
About Wipro Newsroom Investors Careers Contact Us
IT Services
Product Engineering
Technology Infrastructure Services
Business Process Outsourcing
Consulting Services
Building on Research
White Papers
Home White Papers e-Business

Understanding event correlation and the need for security information management

Abstract
Enormous logs are produced by various network devices like IDS or Firewall, Webserver, applications and databases which is practically impossible to monitor manually. A single firewall alone can produce over 1 gigabyte of log data in a single day and IDS can produce over 500,000 messages over the same period. What’s worse – much of the information generated by these security systems is dominated by false positives (an indication of hostile activity when there is none). The challenge is to isolate and prioritize the few messages that do indeed indicate real security threats. This need to isolate significant security incidents from the white noise of IDS, FW, OS, APPS, and AVS messages is part of the larger economic reality requiring organizations to utilize their existing security resources more effectively. Automation of the security operations workload and prioritization of tasks in the operations center is critical.

This white paper discusses how event correlation works and how a SIM (security information management) can fit into a corporate network to minimize the challenges faced by the system administrators or security professionals. Also, it discusses ways to reduce the time spend in analyzing huge logs produced by various network devices.

Author
Debasis Mohanty

Download this paper
bullet B2E
dot
bulletBusiness Process
Management

dot
bulletBusiness Intelligence
and Data Warehousing

dot
bullete-Business
dot
bulletEnterprise Applications Services
dot
bulletTechnology Infrastructure Services
dot
bulletEmbedded & Product Services
dot
bulletTalent Transformation
dot
bulletTelecommunication & Internetworking
dot


Industries ServedspacerServices Offered
dwnAnalyst Reports
dwnCase Studies
dwnWhite Papers
Subscribe to our monthly Newsletter Subscribe to 'Peer Ping' our monthly newsletter

Request for InformationRequest for Information

Contact UsContact Us

Related Links
spacer
bullet
India : An outsourcer's paradise
spacer
bulletBPO in insurance sector: Pains
    and prescription