BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Generic Third Party Integration

Posted May 24, 2011    Morey Haber

There is an inherent value to vulnerability assessment and attack data beyond the security team. Making relevant data available to other solutions, departments, and team members can streamline the vulnerability management process and ensure the workflow is seamless between departments and management. In addition, having tight data integration makes it easier to document workflow processes required by most regulatory compliance initiatives. Take for example this simple diagram for Retina CS and a generic integration into the Windows Application Log.

Critical events can be filtered as they entered into the management console and forwarded to the Application Log. Any third party event log watcher can trigger from these events to perform addition actions or notify appropriate individuals. This simple process can be documented as follows:

  • Perform periodic vulnerability scans
  • Set a threshold for events to be replicated into the Windows Application Log
  • Have Log Management System “x” or Network Management System “y” monitor for these events
  • Perform an automated rule when these are detected. For example, open a help desk tick after correlating the data with a CMDB, send an alert to the system owner outside of the security department, or perform an automated action.
  • This type of generic integration can be used to tie virtually any system to eEye’s solutions and raise the value of the data being collected without the need for any custom code. In addition, eEye supports the following generic integration points into each of our solutions.

    Based on these, a client can do everything from custom control of the scan engine to direct access of the data warehouse and integrated alerting functions. Some custom integrations that have been performed by our clients include:

  • Extraction of data for companywide ticketing system using XML.
  • Export of results for supplemental information to an enterprise level asset inventory system.
  • Security notification of rogue devices and any other detected anomaly including new ports being opened, etc.
  • Custom web pages hosting resulting data including SharePoint
  • Allow users to initiate their own scans and view results.
  • To that end, eEye has embarked on an aggressive third party integration program (with our partners) the following out of the box integrations that go far beyond basic event log scraping.

    These solutions work seamlessly with eEye to raise the awareness of vulnerability assessment data and provide a streamlined workflow for your business requirements. For more information regarding eEye and our third party integrations, please click here.

    Additional articles

    Dark Reading

    2014: The Year of Privilege Vulnerabilities

    Posted December 18, 2014    Chris Burd

    Of the 30 critical-rated Microsoft Security Bulletins this year, 24 involved vulnerabilities where the age-old best practice of “least privilege” could limit the impact of malware and raise the bar of difficulty for attackers.

    Tags:
    , , , , ,
    dave-shackleford-headshot

    Looking back on information security in 2014

    Posted December 16, 2014    Dave Shackleford

    Dave Shackleford is a SANS Instructor and founder of Voodoo Security. Join Dave for a closer look at the year in security, and learn what you can do to prepare for 2015, with this upcoming webinar. 2014 has been one heck of an insane year for information security professionals. To start with, we’ve been forced…

    Tags:
    , ,
    patch-tuesday

    December 2014 Patch Tuesday

    Posted December 9, 2014    BeyondTrust Research Team

    This month marks the final Patch Tuesday of 2014. Most of what is being patched this month includes Internet Explorer, Exchange, Office, etc… and continues a trend of the greatest hits collection of commonly attacked Microsoft software. Probably the one thing that broke the mold this month is that for once there is not some…

    Tags:
    ,