Top Banner
PACKETVIPER NEXT GENERATION GEO-IP FILTER
14

How Next-Generation Geo-IP helps SIEM detection

Jan 08, 2017

Download

Technology

Francesco Trama
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: How Next-Generation Geo-IP helps SIEM detection

PACKETVIPER NEXT GENERATION GEO-IP FILTER

Page 2: How Next-Generation Geo-IP helps SIEM detection

PACKETVIPER PRESENTATION

GOALS

▸ Healthcare State of the Union

▸ PacketViper Internal LAN Use

▸ Challenges facing internal networks ▸ The importance ▸ Cause and Effect

▸ Volume effect on SIEM’s

Page 3: How Next-Generation Geo-IP helps SIEM detection

AHN “STATE OF THE UNION”

UNDERSTANDING HEALTHCARE NEEDS

▸ Current and future challenges (threats, remediation, human resources)

▸ New technologies acquisitions

▸ Problems to solve

Page 4: How Next-Generation Geo-IP helps SIEM detection

PACKETVIPER INTERNAL USE

INTERNAL CHALLENGES

▸ Traffic Volume

▸ Logging and Alerting

▸ Timely Management of Alerts

▸ Investigation and Remediation

▸ Human Network Resources

▸ Consistency and Vigilance

▸ Breakout risk and control

Page 5: How Next-Generation Geo-IP helps SIEM detection

0102030405060708090

100

WEEK 1 WK1 WK2 WK3 WKK4 WK5 WK6 WK7 WK8 WK9 WK10 WK11 WK12

Excitement Alerting Fatigue Oversight

ALERTING, TIME. RISKS OVERSIGHT

Damballa’s State of Infections Report.Average enterprise network generate an aggregate average of 10,000 security events per day

The scope of work required to identify a genuine infection, or questionable connections from the deluge of security events hitting businesses every day. Security Fatigue is a very real thing and as time passes a convergence of the product (SIEM, Event Manager) excitement, alerting, and fatigue leads to a higher risk of oversight, .

"The sheer volume of alerts received and the limited timeframe available to investigate indicates that manual efforts are not enough"

InfoSecurty Magazine:

Page 6: How Next-Generation Geo-IP helps SIEM detection

NETWORK LAN SECURITY

WHY AM I LOOKING AT A EGG?

▸Hard Shell

▸Soft centerVulnerable Soft

Center

Page 7: How Next-Generation Geo-IP helps SIEM detection

INTERNAL NETWORK CHALLENGES

Page 8: How Next-Generation Geo-IP helps SIEM detection

IDENTIFYING THREATS AND POTENTIAL BOTTLE NECKS

NETWORK PEAKS, VALLEYS, AND CONGESTION

▸ Identifying the peak traffic by setting baselines periodically

▸ Understanding the business flow and time frames of the peaks

▸ Understanding what is generating the traffic

▸ Who is receiving the traffic

▸ Limiting or Preventing connection

UNITED STATES - MEXICO BORDER

Page 9: How Next-Generation Geo-IP helps SIEM detection

MANAGE INFORMATION OVERLOAD

‣ Reduce garbage in…garbage out.

‣Manage only essential network information within SIEM

‣ Provide traffic control on top of centralized management

‣ Faster operational decisions

Page 10: How Next-Generation Geo-IP helps SIEM detection

PACKETVIPER SOLUTION

▸ Fast Implementation

▸ Controls threats and risky connections at the source network

▸ Limits breakouts, control floods

▸ Reduces information overload

▸ NOT costly to operate

▸ Improves Network and Security teams efficiency

▸ Does not generate additional network load

▸ Does not require agents

▸ Centralized security management

SIMPLIFY, LESSEN, AND CONTROL

Page 11: How Next-Generation Geo-IP helps SIEM detection

STEP 1 STEP 2

PacketViper EM/SIEM

Take control of the connection

Lower logging

Lower false positives

Lower load

Improves Accuracy

Less Alerts

Lower usage

Less Rules

API

Improves

PACKETVIPER SIEM SYNERGY

Page 12: How Next-Generation Geo-IP helps SIEM detection

W I L L PA C K E T V I P E R R E A L LY H E L P Y O U ?

Try our FREE 5*10*25 ProgramGoal: Prove complimentary internal use case

‣ Hardware evolution form ‣ Identify host network segment ‣ Determine inline or mirror

deployment ‣ Deploy PacketViper ‣ Baseline performance ‣ Review traffic and recommend

configuration ‣ Determine network scope

Page 13: How Next-Generation Geo-IP helps SIEM detection

GET PACKETVIPER A SIEM WILL LOVE YOU FOR IT

Page 14: How Next-Generation Geo-IP helps SIEM detection

END