Security event management vendors evolve tools from simple log collection products.
endif; ?>Growing demands to get their networks in line with compliance regulations and maintain consistent policies are forcing many companies to reassess how they secure and manage their networks.
Network management technologies such as traffic monitoring, packet analysis and policy-based management are finding their way into new and existing security tools. Systems management vendors are adding security capabilities to perform vulnerability scans, distribute patches and help customers maintain compliance.
For example, Lancope and other vendors are developing products to baseline typical network traffic and perform ongoing monitoring to detect problems that might indicate a security breach. Others, such as Elemental Security, provide technology to help IT managers establish policies and monitor network events against the policies to ensure that networks remain compliant. Current security event management (SEM) vendors are adding more automation, remediation and policy-based management features to evolve their tools from simple log-collection products into security-compliance tracking tools.
“I wanted a centralized area where I could see all the security events for the company, but I saw more than just security issues,” says Matthew Keogler, senior security and network engineer at AutoTrader.com in Atlanta. Keogler installed an SEM product from GuardedNet about two years ago and said it not only provided a dashboard of security events but also helped him discover unknown network security threats. “The product immediately showed me misconfigured servers and some network issues that are related to security. I still use it from time to time to patrol and clean up the network.”
The trend toward securing networks with network management technologies has attracted not only a slew of newcomers but also Cisco – with its Network Admission Control (NAC) initiative – and IBM. Industry watchers predict that it’s only the beginning.
A hot market
According to The Yankee Group, the overall security industry in 2004 generated about $12.9 billion in revenue, and of that SEM accounts for a modest $250 million. Yet the research firm projects by year-end, the SEM market will grow by more than 30% to about $330 million. In fact, by 2008 Yankee Group says security management will be an $800 million market.
“This is an area that is going to attract big systems management vendors, like BMC, Computer Associates, HP and IBM,” says George Hamilton, a senior analyst with The Yankee Group.
For instance, systems management vendor Altiris last week announced its Altiris Security Suite, which couples vulnerability scans with remediation tools. NetIQ earlier this month unveiled its Security Compliance Suite, which lets users perform vulnerability scans, security log management and compliance-report generation by using a combination of centralized console software and distributed agents on managed machines. At its annual users’ conference in two weeks, HP also is expected to introduce compliance management wares.
Often referred to as security information management (SIM ), SEM technologies appeared a few years ago with vendors promising to take the legwork out of collecting and making sense of thousands of event logs spit out of intrusion-detection systems, firewalls and other devices. The products typically consist of software, servers and agents, or probe appliances that collect logs from devices.
While the task seemed simple – apply the event collection and correlation technologies of network and systems management tools to security devices – the products provided IT managers with much-needed respite from poring over log data.
“We were literally overwhelmed with security data and information. We were seeing 1,200 events per second from our firewalls alone,” says Sean Curry, infrastructure engineering manager at Calpine, an independent power producer with 102 sites across the country and headquarters in San Jose. “We had six firewalls that produced 60 gigabytes of log data per day – each. It was difficult to back up, difficult to compress quickly, difficult to use for reports.”
|
About 18 months ago, Curry installed an appliance from SEM vendor Network Intelligence to get a handle on the logs and to more easily generate reports, which had become more in demand because of the company’s internal IT governance initiatives. He says while the product was used initially as a tool to reduce manual labor and better manage log data, it now helps Calpine stay in compliance.
“We are in the second phase of [the Sarbanes-Oxley Act], and it has given us the ability to prove we have a segregation of duties because of the data it collects. It also makes getting reports to non-technical people easier,” Curry says.
Vendor parade
As companies face compliance challenges, security management vendors are adding out-of-the-box reporting tools to help ease the process. Companies such as ArcSight, e-Security, Network Intelligence and eIQNetworks this year have separately released products specific to reporting on compliance regulations such as the Health Insurance Portability and Accountability Act (HIPAA), Sarbox and the Gramm-Leach-Bliley Act. The tools generally provide report templates specific to regulations, which helps IT managers automatically generate detailed compliance reports.
Rick Casteel’s purchase of TriGeo technology centered on ongoing HIPAA compliance, but he says the tool has evolved to automate security remediation tasks. The vice president of information security at Upper Chesapeake Health System, a healthcare provider for Hartford County in Bel Air, Md., says the TriGeo software helps him monitor some 30 servers and 600 client machines for malicious activity, investigate port scans and track malicious behavior. More important to HIPAA, though, are the automation features that Casteel says TriGeo provides.
“HIPAA requires us to prove a business continuity planning, which means we have to prove that no matter what we can keep services running,” Casteel explains. He says TriGeo notifies the IT team of events that could affect its HIPAA compliance and automatically generates trouble tickets to the help desk before a user notices the problem. “We can be paged that the service has stopped, set a rule that if this happens then restart the service, and the software does it automatically.”
As SEM vendors continue to tap customers’ compliance concerns, Yankee Group’s Hamilton says enterprise scalability and storage capabilities will hold some back. He also warns the technology – and the smaller niche companies – will become acquisition targets for vendors such as HP and IBM that have begun promising to help IT departments get a better handle on IT controls and policies. Hamilton expects to see the technology serve as a cornerstone for vendors’ IT governance strategies.
“Security management vendors have gotten a lot of attention in the enterprise market because of the present state of urgency over compliance,” Hamilton says. “But the value of the technology is much broader and will be about putting defined IT controls in place and constantly monitoring those controls. Compliance is just one piece of that.”




