Highlighted
Frequent Contributor.
Frequent Contributor.
609 views

Correlate events from Firewalls, IPS and Cisco Routers

Hi, will like to understand if anybody has created use cases that integrate events from Firewalls, IPS and Routers and what kind of results can be expected with this correlation.

Thks

Mario

Labels (1)
0 Likes
Reply
4 Replies
Highlighted
Absent Member.
Absent Member.

Mario,

That is a really open ended question. I'm not sure you're going to get a ton of responses. When you a talking about utilizing event sources in the correlation engine, you can usually look at it one of two ways:

1. Do I have the event sources that I need to create content that answers question or requirement 'X'?

2. I know that I have data coming from event sources X, Y, and Z. What can I do with it?

It sounds like you are in example two.

What you do with these event sources is ultimately up to you. In the end, it all comes down to values in fields. Look at your data and see what it tells you. Come up with a strategy to wring every last drop of data out of every alert and then find ways that you can throw those values against each other in a way that will either deliver you new, actionable data, or answer a question or requirement that you have.

0 Likes
Reply
Highlighted
Respected Contributor.
Respected Contributor.

Justink has a good point there, its a tough question, however correlating events from these devices is certainly possible, check out the protect10 presentation i made called

"evolution of malware detection"

it covers the fundamentals of those technology logs to get to malware.

Enjoy.

0 Likes
Reply
Highlighted
Absent Member.
Absent Member.

Where can I find your presentation on "Evolution of Malware"? I was unfortunately not able to attend this years conference due to budget but I am however very interested in this presentation?

Thanks in advance..

0 Likes
Reply
Highlighted
Respected Contributor.
Respected Contributor.

Naturally,

I should have mentioned where you could find it...;-)

Go to the protect 10 space on this sit eand look through the lists of presentations, they provided audio as well, there are a number of excellent presentations there which can help you in your correlation quest.

0 Likes
Reply
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.