Advanced OSSEC Training: Integration Strategies for Open Source Security

18
ADVANCED OSSEC TRAINING: INTEGRATION STRATEGIES FOR OPEN SOURCE SECURITY Santiago Bassett Director Professional Services @santiagobassett

description

During this technical one-hour session, Santiago Gonzalez, an OSSEC core team member (System integration, rules & SIEM) and AlienVault Director of Professional Services, will demonstrate how to integrate OSSEC with other 3rd party applications for greater security visibility and response. To learn more, check out the video: https://www.alienvault.com/resource-center/webcasts/advanced-ossec-training-integration-strategies-for-open-source-security

Transcript of Advanced OSSEC Training: Integration Strategies for Open Source Security

Page 1: Advanced OSSEC Training: Integration Strategies for Open Source Security

ADVANCED OSSEC TRAINING:INTEGRATION STRATEGIES FOR OPEN SOURCE

SECURITY

Santiago BassettDirector Professional Services

@santiagobassett

Page 2: Advanced OSSEC Training: Integration Strategies for Open Source Security

AGENDA

Presentation contents (20 minutes)Learning the basics

• OSSEC capabilities

• AlienVault capabilitiesOSSEC and AlienVault integration

• Integration components

• OSSEC Collector anatomy

• OSSEC Correlation rules

• AlienVault Cross-correlation

• Management interface

Demo – See it in action (20 minutes)Deploying OSSEC agents

• Automatic deployment for Windows

• Manual deployment for LinuxAgentless monitoringManaging OSSEC

• Monitoring/Configuring agents

• Editing rulesCorrelating OSSEC events (Brute-force)OSSEC reports

Page 3: Advanced OSSEC Training: Integration Strategies for Open Source Security

ABOUT ME

Developer, security engineer, researcher and

consultant.

Member of AlienVault and OSSEC core teams.

Director of Professional Services at AlienVault

Born in Spain and relocated to Silicon Valley in

2010. Excuse my accent

Page 4: Advanced OSSEC Training: Integration Strategies for Open Source Security

LEARNING THE BASICS…OSSEC and AlienVault USM

Page 5: Advanced OSSEC Training: Integration Strategies for Open Source Security

OSSEC CAPABILITIES

Log analysis based intrusion detection

File integrity checking

Registry keys integrity checking (Windows)

Signature based malware/rootkits detection

Real time alerting and active response

Page 6: Advanced OSSEC Training: Integration Strategies for Open Source Security

OSSEC ARCHITECTURE

Agent components:

Logcollectord: Read logs (syslog, wmi, flat files)

Syscheckd: File integrity checking

Rootcheckd: Malware and rootkits detection

Agentd: Forwards data to the server

Server components:

Remoted: Receives data from agents

Analysisd: Processes data (main process)

Monitord: Monitor agents

Page 7: Advanced OSSEC Training: Integration Strategies for Open Source Security

ALIENVAULT USM CAPABILITIES

Provides threat detection capabilities

Monitors network assets

Centralizes Information and Management

Evaluates threats reliability and risk

Collaboratively learns about APT

Page 8: Advanced OSSEC Training: Integration Strategies for Open Source Security

ALIENVAULT USM ARCHITECTURE

Embedded tools:

Asset discovery: Nmap, Prads

Behavioral monitoring: Netflow, Ntop, Nagios

Threat detection: Snort, Suricata, OSSEC

Vulnerability assessment: Openvas

External collectors:

Syslog, FTP, SCP, NFS

Samba, SNMP, WMI, LEA

SDEE, SQL, Unix Socket

Page 9: Advanced OSSEC Training: Integration Strategies for Open Source Security

OSSEC INTEGRATIONOSSEC and AlienVault USM

Page 10: Advanced OSSEC Training: Integration Strategies for Open Source Security

INTEGRATION COMPONENTS

Page 11: Advanced OSSEC Training: Integration Strategies for Open Source Security

OSSEC COLLECTOR ANATOMY

Page 12: Advanced OSSEC Training: Integration Strategies for Open Source Security

OSSEC CORRELATION RULES

Common web attack detected

XSS (Cross Site Scripting) attempt

SQL injection attempt detected

Windows authentication failure attempts

MySQL authentication attempt failed detected

PostgreSQL authentication attempt failed detected

SonicWall authentication attempt failed detected

Remote access authentication attempt failed detected

SSH service authentication attempts failed detected

Multiple authentication attempt failed detected

Login authentication failed detected

Page 13: Advanced OSSEC Training: Integration Strategies for Open Source Security

OSSEC ALERTS RISK ASSESSMENTAlienVault USM automatically calculate risk based on OSSEC alerts priority, reliability and assets involved.

Page 14: Advanced OSSEC Training: Integration Strategies for Open Source Security

ALIENVAULT CROSS-CORRELATIONAlienVault USM correlates events from multiple sources, crossing OSSEC alerts with information collected from embedded detectors and external sources.

Page 15: Advanced OSSEC Training: Integration Strategies for Open Source Security

OSSEC MANAGEMENT INTERFACEAlienVault USM provides a comprehensive GUI for OSSEC alerts management:

Status monitorEvents viewerAgents control managerConfiguration managerRules viewer/editor

Logs viewerServer control managerDeployment managerRules viewer/editorPDF/HTML reports

Page 16: Advanced OSSEC Training: Integration Strategies for Open Source Security

LET’S SEE IT IN ACTION!OSSEC and AlienVault USM

Page 17: Advanced OSSEC Training: Integration Strategies for Open Source Security

NOW FOR SOME Q&A…

Three Ways to Test Drive AlienVault

Download a Free 30-Day Trial

http://www.alienvault.com/free-trial

Try our Interactive Demo Site

http://www.alienvault.com/live-demo-site

Join our weekly LIVE Demohttp

://www.alienvault.com/marketing/alienvault-u

sm-live-

demo [email protected]