
Security, Operations and Compliance Working Together
NitroView's performance and scalability allow security information and log management functions to be tightly integrated. When a security event is generated, the parsed event files are linked directly to the source log file and even to the specific log record--for instant access during the event management and forensic processes. There's no extra step, extra application to launch, or extra time to waste by searching through logs manually.
Why is this important? Because log files alone don't tell us everything that we need: they contain important pieces of evidence and are an important link in establishing chain-of-custody, but they also raise important new questions. For example, we might see a username in an access log, but there is no information about what that user's role is, or what his or her privileges are. We also might know what system was accessed, but we're told nothing about what types of information are used by that system, or who should be accessing it.
- Overview
- Monitoring
- Protection
- Reporting
While most SIEM solutions require you to "tune" existing log and event sources in order to minimize the data being managed, the value of NitroView increases as more information is added. That's why NitroSecurity built a fully integrated suite of monitoring appliances to help obtain that information.
Every one of our appliances is fully integrated, leveraging the power and flexibility of NitroView ESM for central device and policy management in addition to information and event management, providing everything you need to deploy, maintain and operate a cohesive security monitoring and management strategy--all in a "single pane of glass."
The unified NitroView console provides:
- Log management, including log collection, retention, and analysis
- Event management and analysis, including management of IPS and firewall rules, event correlation, and anomaly detection
- Policy management, including IPS, Firewall, database monitoring, and application monitoring policies
- Network discovery and mapping of event data to a network device and interface, including remediation controls
- Configuration change management, to identity configuration changes in the network
- Case management, to manage and track security operations as they occur
NitroView fully integrates SIEM with dedicated database and application monitoring, as well as network monitoring. This allows NitroView to correlate security threats to network activity, database transactions, application and protocol use, and even the contents of those applications—such as the content of an email attachment, or information posted to a web form.
This level of direct monitoring supplements the collection and analysis of information from device logs, vulnerability assessment scanners, identity management systems, and other sources to provide maximum visibility into your network, how its being used, and by whom.
In addition to a wide range of third part information sources, NitroView can directly monitor:
- Application flows and contents
- Database transactions
- Database and Application sessions, including authentications and commands
- Network traffic (for exploits, malware and intrusions)
- Network flows
- SCADA, DCS and other specialized protocols
- Underlying network and application protocols
- Windows servers (using an optional agent)
The NitroGuard Intrusion Prevention System (IPS) is an industrial-class perimeter defense platform designed to monitor network traffic and actively prevent malicious traffic from entering your network. NitroGuard is the highest certified and validated IPS on the market today, and provides advanced features such as an integrated session-aware firewall, network flow collection.
In addition, NitroView is fully integrated with NitroGuard IPS, enabling you to leverage NitroView's advanced threat detection capability to dynamically "lock down" your security perimeter, implementing blacklists in response to observed threat and risk behavior.
Together, NitroView and NitroGuard can actively protect against a wide range of risk and threat activity, including:
- Exploits and vulnerabilities, such as injection attacks
- Malware, trojans and viruses
- Web content usage and policy violations
- Application usage and policy violations
- Blended, "low and slow," and multi-vector attacks
- Denial of Service attacks (including network, application and protocol DOS)
- Hijacked protocols, services or applications
- Covert Command & Control
Creating a compliance report is easy—but populating that report with all of the required information can be extremely difficult. Consider NERC CIP, which like many other compliance regulations requires consolidated reports showing user/personnel activity, asset use and behavior, vulnerabilities, configuration assurance, and other information in addition to observed risk and threat activity.
NitroView's integrated approach overcomes this challenges, by collecting relevant information from a diverse range of third party network and security devices, and presenting all of the necessary information together, including:
- Threat and event activity, including: device alerts from IDS, IPS, firewalls, application whitelists and others, as well as correlated events
- Risk activity, including: open ports and services, configuration changes, personnel changes, and anomalous behavior
- User information, including: identities, roles and privileges
- Asset information, including: open ports and services, applications, baseline behavior, and known vulnerabilities
- Vulnerability information, including: severity adjustment of threat activity based on a target asset's vulnerability
- Network information, including: network location (switch, port), geo-location (city, country) and network flow information
- Policy information, including: acceptable network, user and application behavior; access to sensitive data; and any policy violations
All information is formatted and presented in any one of hundreds of pre-defined compliance reports, making it easy to deliver the required documentation to your compliance auditor.