SIEM - Network Security as a Service
In the Day 1 post, I had mentioned that there were better technologies today in place of Intrusion Detection, Intrusion Prevention Systems and Honeypots. Well, let's finally spill the beans. These are called SIEM. SIEM stands for Security information and event management. SIEM (pronounced as 'sim') is a tool that does all the security related work for you starting with keeping a log of the data, analyzing the collected logs and preprocessing them to do further processing on them. Many SIEM tools also have an intelligent aspect attached to them and can detect various malicious content that flows through the network. There are many SIEM tools available today. To name a few:
As you can see, these network security tools act as Security as a Service and are Open Source too. Few other paid tools also exist that provide more functionality (USM from AlientVault).
The discussion so far has been on the lines of the Ransomware attacks and how to protect end hosts from malicious attacks. Given that we are looking at these attacks in an SDN architecture, isn't there more important details we should be looking into? We shall be addressing these pitfalls in the next blog.
Comments
Post a Comment