Wednesday, April 13, 2011

Guest Post: How to Replace a SIEM?

How to Replace a SIEM
by Dr. Anton Chuvakin



Ouch! That “Venus” SIEM appliance that we got with routers has finally croaked. That piece of PHP brilliance that pre-pre-previous security engineer wrote has been buried under the thick pile of XML. That managed SIEM provider has annoyed us one last time.

What do the above situations have in common? The unfortunate time to replace your SIEM has come. What to expect, apart from copious amounts of pain? This post will shed some light on this conundrum, based on author’s experiences.

First, it goes without saying that it is better to choose the right SIEM the first time (e.g. see “On Choosing SIEM” and other posts mentioned below) than to migrate from a SIEM that has been collecting logs (and dust) for a few years. However, you might not have any say in the matter – you might have inherited it, your “evil boss” might have procured the previous SIEM without asking you or you might have built it yourself after a particularly bad hangover… Also, your organization might have simply outgrown the SIEM or your early generation SIEM vendor has not kept up with innovation in the space. In any case, you have a SIEM and you need a new one. 

Let’s look at the good side of the situation:

  • It is very likely that you learned some super-valuable lessons from your previous SIEM experience (other people have to hire consultants to get to those lessons) and now can avoid the common purchasing process pitfalls (some discussed here, BTW)
  • You have much more confidence while discussing confusing SIEM features with vendors – speaking from your previous SIEM experience (this alone will make your new SIEM purchase process much less painful)
  • You have some semblance of the logging policy across the systems that log into SIEM – that puts you ahead of those organizations who are just getting their first SIEM or log management tool
  • It is possible that you built some operational procedures around SIEM (such as for PCI DSS log review or other purposes) and those would be handy for a new SIEM as well
  • If you have to write an RFP (as I discuss here), the chances are that your new RFP would be MUCH better and more likely to result in a good vendor short list
  • Treat this situation as positive, think “I now know more than 90% of people buying a SIEM, thus my new SIEM project will be a success” 
 A few things to avoid and pay attention to:
  • Suppress that “I’d buy anything but this crap” mentality – think “what problems will a new SIEM solve or solve better?”
  • Avoid taking shortcuts (such as not doing a PoC); you are more knowledgeable, but not prescient…
How might a migration process look like? This assumes that you have already selected a new product, tested it in the lab and are ready for production deployment.
  • Prepare to run both products for some time – this might range from a few weeks to months
  • Draft the new SIEM vendor to help you migrate the data; after all, they are getting the prize 
  • Potentially, be prepared to keep the old SIEM running (without paying for the support contract, of course) or at least keep the old data backups – this becomes important if complete data migration is impossible due to architecture differences between the new and old SIEMs. Ideally, your log management tool will hold raw log backups and so keeping the old SIEM in operation won’t be needed.
  • One of the biggest migration efforts will be migrating SIEM content: reports, rules, views, alerts, etc. As well all know, such content is not really portable across SIEMs and you should be prepared to simply recreate all the custom content AND all the default content that you used in the the old SIEM and that the new SIEM might lack.
By the way, I have seen more than a few organizations start from an open source SIEM or home-grown log management tool, learn all the lessons they can without paying any license fees – and then migrate to a commercial SIEM tool. Their projects are successful more often than just pure “buy commercial SIEM on day 1” projects and this might be a model to follow (I once called this “build then buy” approach)

Dr. Anton Chuvakin
.

Sunday, March 06, 2011

AD: 10 Reasons for Migrating from MARS to AccelOps

Sponsor Advertisement

AccelOps, the integrated datacenter and cloud monitoring company, today announced a Competitive Upgrade Package with “10 Reasons for Migrating from CS-MARS to AccelOps” exclusively for Cisco CS-MARS security appliance customers and resellers. This is in response to the market demand from the current CS-MARS user community and resellers seeking a migration path, in response to the recent End-of-Life of CS-MARS. 



The company's new executive brief, "10 Reasons for Migrating from CS-MARS to AccelOps" outlines the many advantages available for CS-MARS clients that migrate to AccelOps' fully integrated datacenter and cloud monitoring platform.

.

Friday, March 04, 2011

Cisco MARS 6.1.2 Released

Looks like Cisco released MARS 6.1.2 towards the end of February.

Obviously no new features, but signature updates, and a couple of fixes.

New Features
This release includes contains no new features. It is a release dedicated to issue resolution. 

You can read the release notes HERE

Monday, February 21, 2011

February Update

WIth the Cisco MARS End of Life dates, being finally announced at the end of last year, I am starting to see more enquires to the blog around replacement products.

So I have lined up some new content for the blog, including some great guest articles, and I am still looking for more.

Saturday, December 04, 2010

Cisco MARS End of Life - Official

Well its official, Cisco have announced the End of Life for Cisco MARS.

"Cisco announces the end-of-sale and end-of life dates for the Cisco Security Monitoring, Analysis, and Response System. The last day to order the affected product(s) is June 3, 2011."

You can read the official End of Life/End of Sales notification HERE.

The end of an Era, for probably the largest deployed SIEM tool out there.

I think its also important to note, Cisco' stance on future SIEM type products from the release notes  "There is no replacement available for the Cisco Security Monitoring, Analysis, and Response System at this time."

Happy hunting for a replacement!

Monday, November 29, 2010

Cisco SIEM Deployment Guide

November updates, a mixture of old and new news.

Cisco has made a few SIEM partner announcements in their efforts to bolster their Secure Borderless Network initiative as deftly referenced by Sean Martin in CIO Insight.


The new rather flashy SIEM Deployment Guide  also references how Cisco is working with some other SIEM vendors.

Also see how others are working with SIEMS such as NetWitness .

And I have updated my part II assessment of the AccelOps SIEM as per their recent announcements.

Friday, November 12, 2010

Where on Earth is MARS?

Found this interesting article in a new infosecurity magazine, on the demise of Cisco MARS, entitled "Where on Earth is MARS?"

The article references MARS past, and surmises on the demise of Cisco MARS, and continues to relay some of the negative sentiment from a handful of analysts in the past year.

I have to say that many people though appreciate and still utilize the many innovations and capabilities that MARS offers.

While a few SIEM vendors have incorporated some of MARS features, MARS is still quite a capable Cisco-centric monitoring solution.

That being said, I also do agree that if you have outgrown your MARS appliance, need to upgrade, require broader device support, and want newer features etc, then it makes sense to look beyond MARS and kick the tires of SIEM alternatives.

Thursday, October 28, 2010

Cisco MARS 6.1.1 Released

Cisco have released MARS Version 6.1.1

You can view the release notes HERE

Changes and Enhancements

ASA 8.2.2 Botnet Traffic Filter
The ASA BTF feature was enhanced in ASA 8.2.2 to add blacklist actions including blocking functionality to Dynamic Filter, as well as additional attributes. MARS Release 6.1.1 supports these enhanced BTF attributes:
•Parses the new BTF-specific syslogs that provide visibility into blocked site traffic
•Supports additional attributes for "threat_level" and "threat_category"
•Adds two system rules and one report 

ASA 8.2.3
In 6.1.1, CS-MARS supports ASA 8.2.3 (Spyker) CLI changes and high priority syslogs for CS-MARS functionality 

Agent-less Windows 2008/Vista/7 Support
In Windows 2008/Vista/7, the Windows Event Log subsystem was substantially overhauled relative to earlier versions supported by CS-MARS. MARS 6.1.1 supports Windows 2008/Vista/7 events pulled by CS-MARS from the Windows hosts (agent-less). [In 6.0.7, MARS supported Windows 2008/Vista/7 events sent by a SNARE agent (agent-based).] 

Ability to Manage SSH Keys
A new CLI command is implemented to handle outdated SSH keys: pnsshfs

 

Wednesday, September 01, 2010

Cisco MARS 6.0.8 Now Available

A couple of weeks, out of date due to my holidays, but Cisco have released MARS 6.0.8

You can review the release notes HERE

There are no new product enhancements, but this release has updated Vendor Signatures, for Cisco (and Non Cisco Devices), as shown below....

New Vendor Signatures
The following table describes the most recent signatures supported for each product or technology:
Revised in 6.0.8
Product
Signature Version Supported
Intrusion Prevention and Detection Signatures
Yes
Cisco IDS 4.0
Cisco IPS 5.x
Cisco IPS 6.x
Cisco IPS 7.x
Current through S496 signature release. Current as of June 16, 2010.
No
Cisco ASA
Current as of March 9, 2010.
No
Cisco IOS 12.2/12.3/12.4
Current as of March 9, 2010.
Yes
Snort 2.8
Current as of June 17, 2010
Latest signature mapped: 16664.
Yes
ISS RealSecure Network Sensor 6.5 and 7.0, and
ISS RealSecure Server Sensor 6.5 and 7.0
XPU 30.061
Release date: June 14, 2010
Yes
McAfee IntruShield 4.1
v4.1.75.24
Release date: June 11, 2010
Yes
McAfee Entercept HIDS 6.x
Current through the June 15, 2010 signature release.
Yes
CheckPoint Application Intelligence
(VPN-1 NG with Application Intelligence R65)
Current through the June 18, 2010 signature release.
Yes
Juniper IPD 4.x
Signature version: 4.0
Release date: June 14, 2010
Yes
Netscreen IDP 3.x
Signature version: 4.0
Release date: June 14, 2010
Yes
Enterasys Dragon 7.2/7.3
Current through the June 14, 2010 signature release.
Vulnerability Scanner Signatures
Yes
Qualys Guard ANY
Current through the June 16, 2010 signature release.
Yes
E-Eye, Retina Scanner Vulnerability Software, version v5.11.1.2181
Current through the June 16, 2010 signature release.
Yes
Foundstone, version ANY
Current through the June 17, 2010 signature release.
Yes
Common Vulnerabilities and Exposures (CVE) Database
Current with the June 18, 2010 definition update.
Miscellaneous Support
No
Oracle 11g
Support for new AUDIT_ACTIONS. 
 

Thursday, August 12, 2010

Book Review: Network Flow Analysis


Book Review: Network Flow Analysis
Author: Michael W.Lucas
Published By: no starch press
ISBN: 1593272030

"Stop asking your users to reproduce problems. Network Flow Analysis gives you the tools and real-world examples you need to effectively analyze your network flow data."

If you have ever read any of Michael W.Lucas' other books, you will know you are in for a humorous and entertaining read.

Network Flow Analysis has a good introduction to flow, what it is, how records are made up and what its actually used for.

"Knowing who talked to whom, when they talked, and how much each party said is terribly valuable"
Flow is not new, and there are many commercial products out there, and a few open source tools also.

Lucas has based the book on the open source Flow-tools

"Analyzing flow data from your internal network will quickly expose problems, mis-configurations, and performance issues."

The book covers how to configure flow, on differing vendors kit, and also how to configure hardware and software flow sensors, like softflowd. (Softflowd is flow-based network traffic analyser capable of Cisco NetFlow™ data export. Softflowd semi-statefully tracks traffic flows recorded by listening on a network interface or by reading a packet capture file. These flows may be reported via NetFlow™ to a collecting host) 

Once you have your devices sending flow, and your open source collector set up, Lucas then demonstrates with a variety of tools, on how to manipulate the data.

"the flow-report program reads flows and produces totals, rankings, per-second and per-interface counts, and other reports"

There are also lots of warnings and help tips, to assist with troublesome installs, "Correct Cflow.pm installation seems to be the single most common reason flow management projects fail"....."do not proceed".."until flowdumper gives correct answers. You have been warned"

Open source tools are not everyones cup of tea, and you may actually prefer commercial tools like the excellent Lancope, which adds NBA functionality if you have budget.

But, if you have no dosh, and are happy installing say BSD, and compiling a few bits and pieces, then "Network Flow Analysis" will definitely be the book to help you every step of the way.