Skip Links

Network World

Alan Shimel

Open Source Friday Focus: OSSIM / AlienVault

With so many different security devices in the network, a SIEM (Security Information and Event Manager) is a must. There is a great open source alternative, OSSIM

By Alan Shimel on Fri, 03/05/10 - 2:18pm.

I was out in San Francisco all week at the RSA Conference. RSA is where "the security world comes to gather". There was no lack of open source security solutions on the exhibit floor. In fact in security more than in many other areas, open source solutions have found broad acceptance, with many giving birth to commercial entities around them. Snort and Sourcefire are one example, Tripwire, Nessus and ClamAV are others. One I wanted to highlight today is OSSIM.

OSSIM stands for Open Source Security Information Manager. A SIM or SIEM (security information and events manager) is a must have application for any organization of medium size or above. Because there are so many different security devices and technologies working all at once, you need something that correlates and brings together all of the information that is generated. Something that can automate the analysis of event logs. That is what a SIM does.

There are some great commercial SIEMS out there. Arcsight is one. eIQ networks is another and there are even more out there. One open source solution in this arena is OSSIM. OSSIM has been around for a while now and has earned a reputation as an application that works.

OSSIM's open source foundation makes it easy to hook into the wide variety of security devices out there. It's polished GUI and functionality make it a powerful enough tool to compete against some of the biggest name in the SIM market. Here is a screen shot of an Executive Dashboard from OSSIM:

While at RSA I had a chance to sit down with Dominique Karg, one of the founders and CTO of Alien Vault and the lead developer on OSSIM. Who is Alien Vault? Alien Vault is the commercial entity Dominque (who is from Germany) and the other developers (mostly from Spain) launched to develop a commercial upgrade to the open source OSSIM.

Having just raised some venture capital, they are moving the company to the Bay area. The commercial version of OSSIM will feature added functionality like multi-tenant hosting and more. Of course there will always be the open source version. The products will be released under a dual licensed model, with the commercial version considered just an upgrade.

There is no such thing as an easy SIEM, but the role they play is critical in most organizations. If you are in the market for one, you probably have already looked at OSSIM. You may want to look at AlienVault as well. Either way it is a fine product if a SIM is what you are looking for.

 

 

Please visit the Google Subnet home page for more news, blogs and podcasts. Sign up for the weekly Google newsletter.
More blog posts from Alan Shimel:

Subscribe to all Google Subnet bloggers or Follow Google Subnet on Twitter

Check out Alan Shimel's Podcast and other blogs, too.

About Open Source Fact and Fiction

As co-founder and Managing Partner at The CISO Group, Alan Shimel is responsible for driving the vision and mission of the company. The CISO Group offers security consulting and PCI compliance management for the payment card industry. Prior to The CISO Group, Alan was the Chief Strategy Officer at StillSecure. Shimel was the public persona of StillSecure as it grew from start up to helping defend some of the largest and most sensitive networks in the world.

Shimel is an often-cited personality in the technology community and is a sought-after speaker at industry and government conferences and events. His commentary about the state of security, open source and life is followed closely by many industry insiders via his blog and podcast, "Ashimmy, After All These Years" (www.ashimmy.com). Alan is now also a regular contributor to The CISO Group’s security.exe blog and podcast.

Alan has helped build several successful technology companies by combining a strong business background with a deep knowledge of technology. His legal background, long experience in the field, and New York street smarts combine to form a unique personality.

Disclosure: The CISO Group sells a software-as-a-service PCI compliance application called SAQPro. The company is independent and does not represent any other vendor's products as a reseller.

Policy on comments: Respectful discussion is welcomed! However comments that use inappropriate language, consist of name calling or personal attacks, or include accusations of wrongdoing are not appropriate. Those comments will be deleted or edited.

 

Most Discussed Posts

On The Web
Twitter
Facebook
Blog Roll
Podcast
http://www.securityexe.com
Personal blog
http://www.ashimmy.com
Work blog
http:///www.securityexe.com
Sports Blog
http://bleacherreport.com/users/205594-alan-shimel