alienvault threat alerts in spiceworks

17
How to Get Secure in Spiceworks with AlienVault stay spicy

Upload: alienvault

Post on 07-Jan-2017

763 views

Category:

Technology


4 download

TRANSCRIPT

Page 1: Alienvault threat alerts in spiceworks

How to Get Secure in Spiceworks with AlienVault

stay spicy

Page 2: Alienvault threat alerts in spiceworks

About AlienVault Threat AlertsAlienVault Threat Alerts are a simple yet powerful tool that comes built-in with Spiceworks. When a device on your networkhas been interacting with a known malicioushost or suspicious IP, you’ll immediately getan alert in your feed and you’ll get an alert email.

Page 3: Alienvault threat alerts in spiceworks

• The current threat landscape• What to do when you receive a Threat

Alert in Spiceworks• How to monitor cloud services &

internet facing devices with NEW Threat Monitor for Spiceworks

• How to take security even further with AlienVault's Unified Security Management (USM) platform

Overview

Page 4: Alienvault threat alerts in spiceworks

• More and more organizations are finding themselves in the crosshairs of various bad actors for a variety of reasons.

• The number of organizations experiencing high profile breaches is unprecedented.

• The “security arms race” cannot continue indefinitely as the economics of securing your organization is stacked so heavily in favor of those launching attacks that incremental security investments are seen as impractical.

Threat landscape: Our new reality

60% In 60% of cases, attackers

are able to compromise an organization within

minutes.

Source: Verizon Data Breach Report, 2015

Page 5: Alienvault threat alerts in spiceworks

“There are two types of companies that use computers. Victims of crime that

know they are victims of crime and victims of crime that don’t have a clue

yet.”- Jim RouthCISO, Aetna

Page 6: Alienvault threat alerts in spiceworks

Prevent Detect & Respond

Prevention is elusive

vs

Page 7: Alienvault threat alerts in spiceworks

AlienVault Alerts in Spiceworks:Dashboard & Device Details Page

Page 8: Alienvault threat alerts in spiceworks

Investigating Threat Alerts• FREAK OUT• Run thorough malware scan

on suspect machine and address any issues found

• Confirm via other sources (VirusTotal, IPVoid, etc) that IP is a threat

• Record incident• Flag IP address for review if

you believe it is a false positive

Page 10: Alienvault threat alerts in spiceworks

AlienVault Threat Monitor• Affordable, Cloud Security Monitoring in

Minutes• Cloud service with no on-premise technology• Low monthly cost

• Continuous Threat Detection• Real-time alerts integrated within your

Spiceworks desktop• Accelerates and simplifies your ability to

detect and respond to threats on your perimeter devices and cloud platforms

• Ability to scale threat detection without having to add staff

• Built-in security controls with continuous updates from AlienVault Labs

Page 11: Alienvault threat alerts in spiceworks

Q: Who will benefit from Threat Monitor? A: Any Spiceworks user who has:

Lack of visibility into attacks directed at cloud services and internet-facing on-premise systems Limited security expertise due to shortage of IT resources No dedicated security staff No threat intelligence to help identify & research threats No centralized management and control with existing security tools

Page 12: Alienvault threat alerts in spiceworks

Monitor your internet-facing network devices and cloud services including:

for Work

Page 13: Alienvault threat alerts in spiceworks

AlienVault Threat Monitor for Spiceworks

Top Features & Benefits

Security Monitoring of SaaS and Internet-facing Devices

• Scan devices for vulnerabilities• Monitor your cloud services for abuse and

intrusion • Track your company reputation: Know when

your network is being used for malicious activity• Alert you when threats are found or when your

systems have become compromised• Inform you about new and emerging threats

and how to remediate vulnerabilities and misconfigurations

Page 14: Alienvault threat alerts in spiceworks

AlienVault Products Comparison

AlienVault Product Pricing Form Factor Cloud App Monitoring

On-Premise Monitoring

Integrated Threat

Intelligence

FREE Cloud No No No

Starts at $295/ Month Cloud Yes

Internet-Facing

DevicesBasic

Starts at $3900

Virtual orPhysical

ApplianceNo Yes Yes

Page 15: Alienvault threat alerts in spiceworks

USM PlatformASSET DISCOVERY• Active Network Scanning• Passive Network Scanning• Asset Inventory

VULNERABILITY ASSESSMENT• Continuous

Vulnerability Monitoring• Authenticated /

Unauthenticated Active Scanning

BEHAVIORAL MONITORING• Netflow Analysis• Service Availability

Monitoring

SIEM• Log Collection• Event Correlation• Incident Response

INTRUSION DETECTION• Network IDS• Host IDS• File Integrity Monitoring

Built-In, Essential Security Controls

Page 16: Alienvault threat alerts in spiceworks

Unified Security ManagementUnified Security Management Platform

A single platform for simplified, accelerated threat detection, incident response & policy compliance

AlienVault Labs Threat IntelligenceCorrelation rules and directives written by ourAlienVault Labs team and displayed throughthe USM interface

Open Threat Exchange The world’s largest repository ofcrowd-sourced threat data providing acontinuous view of real time threats that mayhave penetrated the company’s defenses.