Friday, July 09, 2010

Review: Accelops - Part One




What options have you got, if you are looking to replace or upgrade your MARS appliance or other SIEM/logging solution?

A lot has changed in the SIEM space, since Cisco released the Cisco Monitoring Analysis and Response System, around early 2005.

MARS was one of the first products to collect, normalize and correlate event logs from all the major security vendors, systems and netflow, and run those events against security-based rules to create incidents, producing real time alerts and historical queries and reporting functions.

Times move on and most vendors speak of SIEM 2.0 or second generation, with more intelligent log gathering, useful details, identity information, geo-location databases, more comprehensive windows event collection, etc..

Now you may already know, that the original MARS creators (the Protego folks) have created a new product called AccelOps, and they believe this is a better migration path and alternative to CS-MARS, than any other 2nd generation SIEM.

So what’s so good about AccelOps?

Well a lot, so much, in that I have already decided to do this review in 2 parts, as there is a lot to tell after personally installing and testing the product in my lab.

Given smarter threats within more complex infrastructures, compliance mandate overlaps and the drive for resource efficiencies – security operational requirements have evolved.

Accelops has created a strong SIEM 2.0 comparable product, and then said ok, security events are only one part of the picture.

Lets add not only security devices, but servers, VMs, applications, processes running on those servers, DHCP and DNS information, web servers logs, application response times, Wireless AP logs, FLOW data, and then analyse the whole lot using a highly scalable and cluster capable VM infrastructure.

Now throw in device configs and OS patch information, switch port mappings and grab L2 and L3 topology data across multi-vendor devices.

(So basically I can pull up IP to Port Mappings just as easy from a HP Procurve switch, as I can with a Cisco Catalyst Switch)


And while we are doing that lets collect CPU, disk space, and a whole host of performance and resources stats.   Then you get the picture – literally the whole picture.


AccelOps discovers and monitors the entire infrastructure via agentless receiving or polling using various protocols (SNMP, syslog, Telnet, HTPP, WMI, RPC, JDBC, JMX, VI-SDK).   It also auto detects a device type; if you send it say ASA logs via syslog it will identify and appropriately process the log.  Captured data is parsed and correlated in real-time and can be historically analysed.

The security teams gets the usual SIEM and logging features and will love its NBAD functionality (and the ability to view FLOWS) since it baselines network activity and alerts on anomalous behavior. While network teams will love monitoring traffic, system and application activity, tracking issues and resource consumption, and assessing assets and config. changes.


All the device/system config. data and recent stats get populated in a CMDB (configuration management database), so I always have device details.  I can view my current Palo Alto device config, or do a compare with a DIFF of last weeks working config, a particular users AD group membership, the serial number of my ASA in London, which servers have IIS installed, etc, all from one place.

AccelOps has developed a hybrid data management system that stores unstructured event data in flat file based database (e.g logs, flows and events) and structured data (eg. configs.) in an embedded relational database (PostgreSQL). 

This enables query parallelization, across clusters, and solves slow reporting problems (and storage bloat), encountered with many SIEMS as they grow. There is no database tuning required and all the historical data remains online (no need to restore archives).

This really provides the means to support root-cause analysis, conduct investigations or produce compliance or other reports that much more efficiently. You can more easily determine security issues from non-security issues that much faster, and at the same time support IT collaboration to resolve problems, with a tool everyone can use.

One of the great things in AccelOps is the Identity and Access Monitoring. This feature collates all primary and secondary logins, whether locally on the network, or remote via VPN, or wireless via an access point. Combine with DHCP and AD information, and any IP address can be automatically associated to a specific user, on a specific server/laptop.


This comes in real useful, when you have an incident, and you want to associate, who changed or did what and from where, at that particular time.  Or go back in time to assess access policy, use of terminated accounts, suspicious service account activity, or user/group actions.

Where ever source or destination IP addresses are presented in AccelOps, you can gain further information. If an Internal IP address, the hostname, OS information, version, owner, and if it’s a known server or client machine in the network. If an External IP address, you can do 3rd Party Lookups to dnstuff, SANS, Cisco Senderbase, or a HoneyPot database.

If I had one complaint, it would be that it lacks an on box geo-location database, for country mappings at this present time (I was told – next release).

You would be forgiven if you thought processing all this and other performance data would slow its SIEM like event parsing and analytics. For many solutions it would believe me.

AccelOps marries a virtualization cluster architecture (the system runs on VMware as a turnkey software virtual appliance) to its high-speed event parsing engine (XML based framework) which assures performance. Adding AccelOps VM instances to a cluster offers near-linear performance for event correlation, search and reporting scale (vendor claims).


An XML-based parsing engine and compiler is used to support new devices and applications without a software upgrade – and they already support quite a decent list of mainstream devices.

I actually found this out for myself, when AccelOps created a Tippingpoint parser for me, and I simply copied the provided XML file to the box – took just a couple of days.

In my opinion the google like realtime search, advanced search and historical reporting is superb. You can move fields around, select and filter from over 350 parsable fields, incorporate Boolean and operator logic, and group results in your display. 



The beauty is any of your results can produce on-demand or scheduled reports with charts, tables, etc. And these can be instantly added as dashboard elements. (In fact any of the dashboard fixings can be customized.).   The rule GUI is very similar and powerful, supporting nested rules and attributes to describe alertable scenarios.  For example, certain rules (like different startup from running config) can trigger compliance alerts. Alert notification supports SNMP, SMTP, email, XML and their console (more on rule analytics in part 2).

Reporting wise, AccelOps comes installed with over 800 reports and respective rules, containing security, performance, availability  and compliance with specifics in PCI, COBIT, HIPAA/HITECH, SOX,  ITIL,  which are great for keeping management happy :-)


I found the AccelOps user interface to be very dynamic (it was developed in Adobe Flex) and runs within any browser (no more internet explorer only!), offering anywhere, anytime use.

A word of warning though, is that you may want a large monitor, to get full benefit, of the variety of information presented.

That’s it for Part One.  I will cover rules, dashboards and monitoring of “Business Services”, and compare AccelOps to MARS in Part Two.

I still see organizations making large investments into SIEM alone, and not having the time, or resources to realize its investment.

In my opinion, AccelOps is worth putting on your SIEM/logger shortlist..  They have  intelligently taking bits out of SIEM, Performance Management, Change Management and  Business service management (BSM) and put it all together to create a tool to enable the security and IT teams to work more efficiently.

AccelOps can be deployed on-premise as a virtual appliance or delivered as a Software-as-a-Service.

Thursday, July 08, 2010

MARS Blog Update

You may of noticed that  Gartner left Cisco MARS out of the SIEM Magic Quadrant for 2010 this year. 

And although hard to find, Cisco did come out and say MARS will in future will concentrate on Cisco only devices, and critical host OS. (And then recently released 6.07 with support for Windows 2008)

Cisco have also recently announced Cisco Security Agent has gone End of Sale, but there have been NO similar notices for MARS. It is very much still alive.

But if you are NOT a pure Cisco network, you may be looking at the market, to replace MARS, with another product that can handle your 3rd party applications and devices.

In my next few articles, I am going to review a couple of alternatives, if you are looking to change, and make the most of your network.

But I am, (as always) on the look out for "Guest Articles", on making the most of your MARS deployment. So come on get involved!

Or as I think the direction that the blog may take, Monitoring and Analysis, of your Routers and Switches. (or Monitoring of Applications, Resources and Security.)


Wednesday, June 02, 2010

Book Review: Securing the Borderless Network

Book: Securing the Borderless Network
Published By: Cisco Press
Author: Tom Gillis

"Today’s new Web 2.0, virtualization, mobility, telepresence, and collaborative applications offer immense potential for enhancing productivity and competitive advantage. However, they also introduce daunting new security issues, many of which are already being exploited by cybercriminals. Securing the Borderless Network is the first book entirely focused on helping senior IT decision-makers understand, manage, and mitigate the security risks of these new collaborative technologies."

Honestly when this book arrived, I was very sceptical.

Written by Tom Gillis, Vice president and General Manager of the Security Technology Business Unit at Cisco, and only 150 pages, I was not expecting anything special.

The book I would say is aimed at the IT Manager and senior IT decision makers, ie, no CCIE or CCNA material, but it is good read for the IT Professional.

Gillis obviously knows his stuff, and clearly defines what the current Web 2.0 threats and challenges are to todays businesses and beyond.

The book evolves from discussing yesterdays technologies, right up to the current day, with smartphones, malware, DLP issues etc, and what challenges this evolution has now presented us with, regarding the "Borderless Network"

All a quick and enjoyable read, I'd recommend it.

Wednesday, May 26, 2010

Cisco MARS 6.0.7 Now Available

Cisco have released MARS version 6.0.7

You can read the release notes HERE


Changes and Enhancements

The following enhancement exists in Cisco Security MARS, Release 6.0.7:
•Support for Windows 2008—Cisco Security MARS provides agent based, native log support for Windows 2008 server hosts. Users can send syslog to CS-MARS by installing a Snare agent on their Windows 2008 server hosts.
•Support for Windows IIS 7—Cisco Security MARS provides support for IIS 7 on Windows 2008 servers.

Enjoy :-)

Tuesday, May 11, 2010

Cisco ASA Secure Logging and MARS

Doug McKillip, a Global Knowledge Instructor, has created a white paper, "Using Syslog Effectively for Security Troubleshooting".

Part of this whitepaper, details using The Cisco ASA Secure Logging feature, over TCP to Cisco MARS.


You can get access to this whitepaper HERE.

Further info on secure logging and the ASA, can be found here, in the  Cisco ASA 8.2 CLI Guide.

Wednesday, April 21, 2010

MARS Support for SNMP V3

Rather than re-invent the wheel, there is a good write up on the new SNMP v3 feature, in MARS 6.0.6 on the Global Knowledge Blog.


Wednesday, March 24, 2010

Fancy a new Job?

I have been busy recently on a couple of new demos on making the most of MARS, by interfacing with some 3rd party products, unfortunately these are not finished yet.

But in the meantime I thought i would let you know about some jobs that are going at the United Health Group.

Recession -what recession? !!!

Network Manager – United Health Group

UHG has multiple network operations positions open within our corporate departments and various business segments. These positions offer tremendous growth possibility, a range of variety and responsibility, a high level of visibility and interaction with senior leaders.

Requirements (Skills, Technologies, etc) –

· 2+ Years of experience in a contracting or provider relations role working for a healthcare payor.

· BS degree in Business, or equivalent experience; MBA strongly preferred for some positions

· Ability to supervise staff including related personnel and development issues (i.e. appraisals, career planning, coaching, etc.) required for some positions.

· Advanced analytical skills

· Excellent verbal and written communication skills; ability to speak clearly and concisely, conveying complex or technical information in a manner that others can understand, as well as ability to understand and interpret complex information from others.

You can see more info and apply for these postions HERE


If I find out about any more tech related jobs, I`ll let ya know!


Tuesday, January 26, 2010

Cisco MARS 6.0.6 Now Available

Release Notes for 6.0.6 are available HERE

Miscellaneous Changes and Enhancements

The following changes and enhancements exist in MARS, Release 6.0.6:

•SNMP v. 3.0 Support—Leveraging a secure communication protocol between MARS and Cisco security enforcement devices, customers can be assured that they are securely mitigating attacks and configuring and managing devices. SNMPv3 support enables the following features:

–Per-device SNMPv3 credentials are used for manual discovery and layer 2 mitigation.

–Support for SNMPv3 credentials for an entire network or range of IP addresses. The MARS autodiscovery feature clones the credentials for an autodiscovered device on that network.

–Monitor the health of supported devices via SNMPv3 via the resource utilization charts that you can add to the Summary > My Reports subtab.

See the Release notes for a matrix of SNMP3 support for different Cisco Devices.

Internet Explorer 8 Support—MARS supports Microsoft Internet Explorer 8 without requiring compatibility mode. Due to the nature of security revisions in Internet Explorer, you may find that you must authenticate more frequently to the MARS appliance.

•Improved Device Support—MARS now includes backward compatible support for ASA 8.0.5 and IOS 15.0(1)M. Backward compatible support means that any events that MARS parsed for ASA 8.0.4 or IOS 12.4 (11) T2 have been verified to parse in the corresponding newer release.

There have also been vendor signature updates for some Cisco and some non Cisco devices.


Friday, November 13, 2009

CVE-2009-2977

Thanks to an eagle eyed reader, (though it is a couple of months old now), if you are running 6.0.4 and earlier, there is an Vulnerability when MARS is configured to pull Windows Event Logs.

"The Cisco Security Monitoring, Analysis and Response System (CS-MARS) 6.0.4 and earlier stores cleartext passwords in log/sysbacktrace.## files within error-logs.tar.gz archives, which allows context-dependent attackers to obtain sensitive information by reading these files."

You can view the CVE Here.

This was covered by Cisco Bug: CSCtb52450 , which mentioned it was only a bug when MARS was configured to PULL events rather than using Snare (or Honeycomb, and similar products)

Its was also mentioned , the issue can be mitigated if log files are not exported out of the CS-MARS device. (Only CS-MARS administrators can export log files)

BTW this was resolved in MARS release 6.0.5


Thursday, November 05, 2009

No Updates for Non Cisco Devices?

There has been plenty of rumours recently regarding MARS, and its support for Non Cisco Devices, more so, over the last couple of days...

Whether its Gartner a few days ago, or MARS competitors, like Nitro putting out releases yesterday, (and I`d fully expect the others to follow)

I noticed an official Business Unit response, in the Netpro Forums......

"October 30, 2009
Cisco response to Gartner Research Memo entitled “Cisco MARS Is Becoming Less Viable as a General SIEM Solution”
Summary
• Gartner has alerted its customers that as Cisco continues to focus its security management efforts on Cisco devices, MARS appliances may become less viable for the broad set of “general” SIEM use cases.
• Gartner concludes that Cisco’s focus on native management capabilities for our devices is a positive direction.
• For customers with primarily Cisco event sources on their network, Gartner recommends that MARS still provides a strong platform for security threat management (STM) and network behavior analysis (NBA) capabilities.
Details
On October 29th, 2009, Gartner released a research note titled “Cisco MARS Is Becoming Less Viable as a General SIEM Solution.” This note is in response to Cisco’s stated direction to focus CS-MARS development on supporting Cisco-built network security devices and critical host operating systems. Non-Cisco network device data and signature updates continue to be supported in CS-MARS for the current versions of these 3rd-party systems.
In the memo, Gartner concludes that “Cisco will focus its efforts on improving Cisco's native security management capabilities,” which they note as a positive direction for Cisco’s overall Security portfolio.

In the past, we have encouraged Gartner to break up this crowded space as it encompasses a vast array of use cases spanning compliance reporting, log aggregation, threat identification, and mitigation. While MARS has been placed in the SIEM market, it has never fully covered all aspects of the Gartner-defined space. Over the last year, as we have focused on the core Security Threat Management use cases for Cisco products, Cisco has de-emphasized compliance reporting and non-Cisco devices.

In particular for Cisco customers, it is important to note Gartner’s recommendation that MARS continues to provide strong STM and NBA capabilities for Cisco event sources
. "


Stinky......