Ads by TechWords

See your link here
Receive the latest technology news and information.
Data Management
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

FAA turns to ArcSight for security event management

The new tool is designed to help it sift through a torrent of security data

November 8, 2005 12:00 PM ET

Computerworld - The Federal Aviation Administration has just finished putting in place a new security event management system designed to help the agency detect and respond to external and internal threats more efficiently.
The new tool is based on a product from ArcSight Inc. called Enterprise Security Management (ESM) that allows the FAA to centrally monitor, collect and analyze information from multiple network security devices such as firewalls and intrusion-detection systems.
The tool is part of a broader FAA bid to bolster its network defenses and incident-response capabilities after the 9/11 terrorist attacks, according to Michael Brown, director of the Office of Information Systems Security at the FAA.
"We were looking for a way to manage the large volume of information coming from multiple [network] sources [and] do a lot of correlation and data reduction," he said. The goal is to help the agency better manage the large amount of information generated by security systems, Brown said.
ArcSight's ESM, like other products in its class from vendors such as netForensics Inc., NetIQ Corp., and Intellitactics Inc., is designed to help organizations quickly sift through the torrent of data generated by multiple security devices, allowing them to focus on the ones that are most important.
At the FAA, for instance, firewalls, system log files, vulnerability scanners and intrusion-detection systems together generate more than a million alerts a day -- only a very small fraction of which really merit any follow-up, Brown said.
"At the end of the day, after all the analysis has been done, we are looking at roughly 15 to 20 alerts" that really matter, he said.
Apart from transforming raw event data into actionable intelligence for security and network administrators, tools such as those from Cupertino, Calif.-based ArcSight can also be useful for forensic analysis after an attack, he said.
Like other agencies, the FAA -- which is a part of the U.S. Department of Transportation -- is also subject to audits by the Government Accountability Office and is required to implement strong incident-response capabilities under the Federal Information Security Management Act.
The new event management capability will allow the FAA to create an auditable security infrastructure to demonstrate compliance with such requirements, Brown said.

Read more about data mining in Computerworld's Data Mining Knowledge Center.



Jump to comments

Data Mining

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

White Papers & Webcasts

Data Grids & SOA
Get this paper now!  

The Workday User Experience Video
Watch Workday's Creative Director, Scott Lietzke, discuss the business-centered design philosophy at Workday.

Business Process Framework Demo
Learn about Configurable Business Processes and Calculated Fields. Watch Now!

Manager Experience Demo
Go beyond self-service solutions to perform more effectively. Watch Now.


IT Jobs

 

SAS Information Management Kit

SAS is the leader in business intelligence and analytical software and services. Only SAS offers leading data integration, storage, analytics and business intelligence applications within a comprehensive enterprise intelligence platform. SAS gives 97 of the top 100 companies in the 2007 Fortune 500 THE POWER TO KNOW®.

Webcast: The Information Management Roadmap
Imagine high-quality data, cleansed, analyzed and delivered throughout your organization. Join Computerworld, IT visionary Thornton May and a panel of experts to learn how SAS® can help you make it happen.

View this webcast 
Research Report: Information Management Initiatives at Midsize and Large Organizations
See the top-line results of this Computerworld sponsored survey to see how IT and business leaders are handling information management implementation.

Download this report 
White Paper: Information Management: Better Information for Winning Decisions.
This white paper explains how the SAS Information Evolution Model aids companies in assessing how they use this information to make strategic decisions and drive business.

Download this white paper