Protecting a corporate data center is like trying to keep an elephant safe from a swarm of flies. Despite your best efforts, bites happen. As the staples of security -- such as firewalls, antivirus software, spam and spyware filters -- come together in suites of products that allow for sophisticated management, there are other security tools either emerging or worth a rethink.
Don't get logrolled
One of the biggest problems CSOs face is figuring out what's actually threatening their data center. Antivirus software, firewalls and intrusion-detection systems can log massive amounts of data about who is trying to do what to your data center. Just tracking it across different software programs-and across departmental systems-presents a vexing challenge, says James Quin, senior research analyst for the Info-Tech Research Group of London, Ontario.
"For organizations to parse through and then correlate and cross-reference all that data is a ridiculous amount of work and very labor-intensive," Quin says. He recommends log analyzers, also known as security information managers (SIMs) and security information and event managers (SIEMs), that can aggregate data from a variety of systems. Such tools allow for centralized correlation and management of logs, and usually come with reporting and analytics tools.
ArcSight is an example of such a tool that would work best for businesses that track large quantities of log data or want lots of features.
ArcSight is kind of a "Swiss army knife for logs," says Dennis Hein, senior information security engineer with Wells Fargo in San Francisco. He uses the product to meld together all the bank's system logs into one place. This saves him from tracking down anomalies, he says. "Things that would take days to investigate we can do in a matter of minutes and hours," Hein says, because the tool can be set to produce well-formatted reports.
For smaller firms or those with less-customized needs, TriGeo from TriGeo Network Security and Symantec's Security Information Manager aren't as robust as ArcSight, but they are simpler to use, especially for firms without particular security expertise.
Another practical reason for using log aggregators: They can stop smart attacks. "If you've got someone coming through who knows how to do it, an attack may raise a succession of yellow flags, but no red ones," says Mike Halperin, vice president of technology at Akibia, a Westborough, Mass., consultancy specializing in data centers.
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #98: The Future of Datacentre IP 18/12/2008 10:33:00
CW Live speaks withLin Nease, Director of Emerging Business for HP ProCurve, to discuss the future of networks, including the effect of IP-based storage on datacentres, new capacity requirements generated by the use of 10Gb Ethernet, and how an efficient network design can slash energy and cooling costs, and help enterprises build a "green" image. - +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport.
IT industry veteran advises caution on outsourcing selection in light of Satyam problems 2009-01-09 21:45:00+11
F-Secure Warns About a Worm Affecting Corporate Networks 2009-01-08 16:42:00+11
Research software developer appoints Susan Dart to new Business Development Director role 2009-01-08 09:08:00+11
Research software developer appoints Susan Dart to new Business Development Director role 2009-01-08 09:08:00+11
Anyware Introduce Two Powerful PCI TV Tuner Cards with S5 Power Up and Windows Media Center Remote 2009-01-07 17:30:00+11
CRM your salespeople will love
Winning over the sales department and obtaining buy-in at all levels is crucial to the success of any CRM initiative. Discover how you can let salespeople work how they want to and reduce their administrative burden with the latest CRM technology.





