Security Basics mailing list archives

Open Source Security Information Management (OSSIM)


From: neil () horizontheory com
Date: Tue, 26 Jun 2007 00:41:18 -0600

Does anyone have any experience using OSSIM?

I'm looking to beef up security at a school having about a thousand computers, about 800 of them laptops that students and staff take home and bring back, and a bit over a dozen servers (many of which are planned to be taken out of service). In addition, they have an open wireless connection (though connectivity to the internet is restricted via ISA). The school is rapidly growing, and while they've been lucky to have mostly benign students, I think the security is inadequate. (I'm looking at some other stuff too, like some firewalls to compartmentalize the network.)

I'm looking to OSSIM to try to help bring a much greater insight into what's travelling across the network. In particular, I like the sound of anomaly detection, a consolidated place to view all events on the network that can be filtered as needed (to isolate the behavior of a particular box, and thus a user). Of course, these are imperfect sciences, so I would love to hear how it fares for others.

Ideally, I would like to set up just one OSSIM box to have it monitor the network, but it looks like it would really need agents, particularly on the servers.

Naturaly, any other opinions, feedback, or advice would be great (even if its not about OSSIM, as long as it helps me get to my goal).

Thanks.
--
Neil.



Current thread: