| By Hurricane Labs | Article Rating: |
|
| April 12, 2012 01:07 PM EDT | Reads: |
885 |
IPS Updates, Splunk, Check Point and You
How I Learned to Stop Hating the Term “Zero-Day” but Not Really
By: Bill Mathews
Zero Day attacks – you know, the ones that almost EVERY signature in your IPS claim to protect you against? Yep those guys, nasty little things. Basically, if IPS vendors are to be believed, those are the things that don’t have a patch yet and have active exploits against them. You update your IPS signatures and BOOM protection from zero day! The problem we always run into, and this is with almost every IPS vendor so I’m not just picking on Check Point here, is how do you know when an update is available? As much as most vendors would like it we are simply not logged into their console all day long so their automated “hey you have an update” thingy is not useful. This was a big problem for us because we manage a lot of firewalls so what to do, what to do. We turned to a combination of something old (RSS) something a little new (Splunk), and something really> old (email alerts.) Here was the issue and how we solved it:
ISSUE
Updates come out, an email goes to only one person (subscribing everyone is impractical), updates are scheduled as needed. The process is slow, too “people heavy”, and has a lot of built-in delay. This is no good when dealing with zero days.
SOLUTION
I took Check Point’s RSS feed that announces their IPS updates and fed it into Splunk. This allowed me to index the feed and break it apart a little so I could build a dashboard around it (dashboards in Splunk are basically a collection of searches and reports.) By itself this would allow us to search across IPS updates and figure out which ones we needed, but I wanted to dig a little deeper and make the process a bit less painful. This is where Check Point helped me out a bit (and possibly other vendors do this too but I don’t know for sure), they actually have a severity tag in their RSS feed so I know how important a given new protection is (Critical, High, Medium, Low) and I could organize my dashboard accordingly.
This dashboard gives me a neat layout of my IPS protections and how important they are. This was a great jumping off point to automate my process a bit more. Next I created a Splunk alert that allows me to alert our engineers of Critical or High protections that should be pushed with some urgency while allowing for a smaller alert for protections to be analyzed a bit more before pushing. The biggest benefit to this was unknown to me at the time, but the RSS feed is updated a full 24 hours or so before that update email is sent out so we were able to get updates out a full day faster, this is huge in this allegedly zero day world.
Some future improvements might be pushing the alerts out to SMS or via our Nagzilla system. I also have, in the back of my head, an idea for relating these things to relevant hosts via Splunk’s inventory module. All in all just one way to use technology for the betterment of all mankind or something like that.
Read the original blog entry...
Published April 12, 2012 Reads 885
Copyright © 2012 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Hurricane Labs
Christina O’Neill has been working in the information security field for 3 years. She is a board member for the Northern Ohio InfraGard Members Alliance and a committee member for the Information Security Summit, a conference held once a year for information security and physical security professionals.
- Cloud People: A Who's Who of Cloud Computing
- New Relic Q1 2013 Blazes Past Growth Targets and Reaches 40,000 Active Customer Accounts
- GDS International Confirms Unprecedented Delegation for Upcoming Next Generation Telecoms Europe Summit in May
- AWS Going into a New Line of Work
- Cloud Expo New York: Using APIs for Better Business Partnerships
- Google Compute enters the IaaS market
- Agile Solutions for Cloud, Big Data, Mobility Services
- Apple’s Key Rubber-Band Patent Found Invalid Again
- How to Re-imagine Your Business for a Mobile World
- 910Telecom to Exhibit at Cloud Expo New York
- The Cloud Delivers a New American Workforce
- Component Models in Java | Part 2
- Cloud People: A Who's Who of Cloud Computing
- New Relic Q1 2013 Blazes Past Growth Targets and Reaches 40,000 Active Customer Accounts
- North America and Asia Account for Highest Proportion of TD-LTE Network Deployments, Direct Carrier Billing Accelerates Revenue Growth for CSPs
- GDS International Confirms Unprecedented Delegation for Upcoming Next Generation Telecoms Europe Summit in May
- AWS Going into a New Line of Work
- Register for the 2013 FOSE Conference
- Cloud Expo New York: Using APIs for Better Business Partnerships
- Apple Ordered to Pay VirnetX $333K a Day
- Google Compute enters the IaaS market
- Agile Solutions for Cloud, Big Data, Mobility Services
- Nielsen to Present at Upcoming Conferences in March
- IBM Picks Mobile for Its Next Big Growth Play
- Where Are RIA Technologies Headed in 2008?
- Should RIM BlackBerries Be Rented?
- Has the Technology Bounceback Begun?
- Trump's Apprentice Runner-Up Rebecca Jarvis Has $150,000 Job Offer From SYS-CON Media
- "Mobile Web 2.0" – How Web 2.0 Impacts Mobility & Digital Convergence
- Ringback Tones
- Microsoft and Sprint Collaborate on Mobile Search
- Mobile Music Gets Boost From New W600 "Walkman Phone"
- i-Technology Blog: Zero-Cost Telephony, the 6-Ton Elephant in the Telco Room
- Java Edition of Windows Live Messenger for Mobile Launched
- Alcatel + Microsoft = Internet TV Over IP, a.k.a. "IPTV," Coming Soon To a PC or TV Near You
- Cloud People: A Who's Who of Cloud Computing



















