DK 'Log


Can OSSIM be considered a SIEM? Is it enterprise ready?
Sat, 20 Jun 2009

The story starts as following. A couple of years ago Dr. Anton Chuvakin (for those who might not know him a well renowned security professional and speaker) made a prediction for 2006: that a Credible Open-Source SIM would not arrive.

A year later he said this goal hasn't been reached (as predicted). I remember being quite pissed off and upset at that time, but his point was right. Development had been slow, we didn't have resources and everything was a bit stalled. But that has changed and AlienVault is about two years old now, we made a huge step forward and I think OSSIM is nowadays more than S/MB as well as Enteprise ready. (And sadly our resources are still very limited compared of those which Arcsight, Symantec or others might have).

Yesterday I followed a couple of quick twitter exchanges where I'd like to quote the most significant ones:

  • I agree but S/M of SMB probably won't have the capabilities to run something like OSSIM and it's not robust enough for Ent.
  • @anton_chuvakin mind you, I simply asked if OSSIM had the potential, not that it was there yet... as always, I wonder, isn't there a better way?
  • @falconsview Re: opn src #SIEM Well, show me a sizable deployment (and not one hand-built by its creators) and I will believe you.
  • @anton_chuvakin Will you change your mind about opensource SIEM if I get you access to a sizable deployment not created by it's authors ? :P
  • @dkarg Re: open src #SIEM Yes, I probably will.

So, there it is, Andrew Hay (another renowned security expert) and Anton say that:

  1. OSSIM is not a SIEM.
  2. OSSIM is too difficult for S/MB and not reliable enough for the Enterprise

Well. Guess I'll have to prove them wrong ;-). And on top I'm not pissed off, so I guess I'm growing up :-)).

So what do I need? I for myself have received news/feedback of pretty big OSSIM installations and have had my hands on another bunch of them. Ranging from 100 person Real Estate companies to >40000pc governmnet environments with distributed deployments and thousands of events per second (this last one using the COSS version of course). But, the point as mentioned by Anton is that we don't have our hands in it, the testimonial has to come from someone who's got a deployment running not managed by us. Both S/MB as well as large enterprise deployments are valid since there are two points to prove. I'd really like to hear from a large company which is supposedly using Splunk+OSSIM, can't say the name but that would be a good example :-).

So, if any of you reading this is in that situation please let Mr. Chuvakin and Mr. Hay know about it so they hopefully can change their minds on the subject. There's contact information on their respective homepages. Otherwise I'll have to eat my words and admit that OSSIM is no Open Source SIEM (like in The Matrix, "there's no spoon").

Thanks in advance for any help :-)

PS: BTW, we did a first run of the webinar yesterday, thanks everybody for assisting and apologies for the, well, mishappenings. I got quite nervous, next demo will be better.

Edit 2009/06/20: Fixed a misunderstanding on who predicted what, see the comments.

posted at: 07:03 | path: /personal | permanent link to this entry | 6 comments |
Tags: siem, ossim, smb, enterprise



* Posted by Dominique Karg at Fri Jun 19 13:25:11 2009
Seems like this is an interesting subject. Nothing is white or black as always and I think our disastrous ability to correctly show what OSSIM can and cannot do is one of the main reasons for this. It requires a lot of clarification and I'll try to post this weekend about the interesting things Andrew says on his post: http://www.andrewhay.ca/archives/912.

Thanks for the support back there Andrew, I'll surely will be able to change both yours and Anton's mind ;-)
* Posted by Anton Chuvakin at Fri Jun 19 16:43:21 2009
"The story starts as following. A couple of years ago Dr. Anton Chuvakin (for those who might not know him a well renowned security professional and speaker) made a prediction for 2006: that a Credible Open-Source SIM would arrive. "

Actually, that was WOULD NOT arrive.
* Posted by Dominique Karg at Fri Jun 19 16:53:42 2009
Don't get you Anton. Here is the original quote:

"
A Credible Open-Source SIM

There's about $100MM spent annually on products that manage and correlate logs. Guess what? None of it is hard to do. The underlying tools are there. Customers know how to do this better than the vendors do. Expect a mainstream open-source combination of Argus and Sguil to own the security management conversation next year.
"

Doesn't that mean you expected some credible open-source solution to arrive and challenge the big players?
* Posted by Anton Chuvakin at Fri Jun 19 21:43:03 2009
That was Thomas Ptacek: original at http://lists.immunitysec.com/pipermail/dailydave/2005-December/002723.html

I actually violently criticized this view:

http://lists.immunitysec.com/pipermail/dailydave/2005-December/002725.html
* Posted by Dominique Karg at Sat Jun 20 07:02:41 2009
Got it, my bad, just fixed it in the originial text and need to get some time to update andrews response. I fear both his and your input is based on:
a) old OSSIM feedback.
b) outdated public information (webs, whitepapers, etc...)

Anyway, as said, that will get into a separate post.

Thanks a lot for the correction.
* Posted by Dominique Karg at Mon Jun 22 09:44:38 2009
Anton also posted a very interesting post regarding SIEM mentioning part of this, check it out at http://chuvakin.blogspot.com/2009/06/why-no-open-source-siem-ever.html

Name:


E-mail:


URL:


Comment:


Categories

/ (66)
    code/ (1)
    feed/ (1)
    friends/ (1)
    ossim/ (41)
        installer/ (3)
        plugins/ (2)
        tuning/ (3)
        tutorials/ (8)
    personal/ (20)
        campus/ (2)
        opinion/ (1)
        travel/ (1)
    rants/ (1)



Dominique Karg
(feel free to get in touch)
  • Mail (gpg key)
  • Linkedin
  • Twitter
  • Forums

Friend's blogs:
  • /blog/jaime
  • /blog/juanma
  • /blog/santiago






Certified Application Security Specialist




RSS




< June 2009 >
MoTuWeThFrSaSu
1 2 3 4 5 6 7
8 91011121314
15161718192021
22232425262728
2930     




Archives

2010-Apr
2010-Mar
2010-Feb
2009-Dec
2009-Sep
2009-Aug
2009-Jul
2009-Jun
2009-May
2009-Apr
2009-Mar
2009-Feb
2009-Jan
2008-Dec
2008-Oct
2008-Aug
2008-Jul
2008-May
2008-Mar
2008-Feb
2008-Jan
2007-Dec
2007-Nov




Tags

installer ossim tutorial untagged




Made with PyBlosxom