![]() |
![]() |
![]() |
Can OSSIM be considered a SIEM? Is it enterprise ready? Sat, 20 Jun 2009
The story starts as following. A couple of years ago Dr. Anton Chuvakin (for those who might not know him a well renowned security professional and speaker) made a prediction for 2006: that a Credible Open-Source SIM would not arrive.
Yesterday I followed a couple of quick twitter exchanges where I'd like to quote the most significant ones:
So, there it is, Andrew Hay (another renowned security expert) and Anton say that:
Well. Guess I'll have to prove them wrong ;-). And on top I'm not pissed off, so I guess I'm growing up :-)). So what do I need? I for myself have received news/feedback of pretty big OSSIM installations and have had my hands on another bunch of them. Ranging from 100 person Real Estate companies to >40000pc governmnet environments with distributed deployments and thousands of events per second (this last one using the COSS version of course). But, the point as mentioned by Anton is that we don't have our hands in it, the testimonial has to come from someone who's got a deployment running not managed by us. Both S/MB as well as large enterprise deployments are valid since there are two points to prove. I'd really like to hear from a large company which is supposedly using Splunk+OSSIM, can't say the name but that would be a good example :-). So, if any of you reading this is in that situation please let Mr. Chuvakin and Mr. Hay know about it so they hopefully can change their minds on the subject. There's contact information on their respective homepages. Otherwise I'll have to eat my words and admit that OSSIM is no Open Source SIEM (like in The Matrix, "there's no spoon"). Thanks in advance for any help :-) PS: BTW, we did a first run of the webinar yesterday, thanks everybody for assisting and apologies for the, well, mishappenings. I got quite nervous, next demo will be better. Edit 2009/06/20: Fixed a misunderstanding on who predicted what, see the comments.
posted at: 07:03 | path: /personal | permanent link to this entry | 6 comments | A small victory against abusive copyright holder practices Mon, 20 Apr 2009 I wanted to share this news entry with everybody visiting this site. This has very little to do with OSSIM or AlienVault and of course this is my own opinion, not necessarily shared by them. A week ago I had read a sad sentence convicting those who're running the Pirate Bay torrent tracking site. Now I'm pleased to see that not everybody has sold their soul to what's "supposed to be politcally correct": Telenor, the norwegian ISP hosting the pirate bay have told the copyright lawyers to shove their demands where Long John Silver couldn't see 'em even with his good eye and a very long spyglass.
My sincere admiration (both to TPB admins and Telenor), I'm pre-ordering my support t-shirt right now :-)
posted at: 18:26 | path: /personal | permanent link to this entry | 0 comments | Finally someone accepted me in their certification! Wed, 01 Apr 2009
I just became a proud Certified ASS, that is, Certified Application Security Specialist (don't think wrong). Just check the official badge on the right :-)
What are the benefits to employers?
posted at: 20:15 | path: /personal | permanent link to this entry | 4 comments | How to make good friends Fri, 27 Mar 2009 I just wanted to share a quick mail we've received tonight at AlienVault. I'm hiding the user's identity until he grants me permission to disclose it, which I doubt he'll do btw. The mail did read as following: Subject: Port scan from you guys to my server from 207.158.15.208. Cease and desist. I installed your ossim product and now you are port scanning my servers? You are scanning [insert FQDN here] servers right now and I am picking it up on my IDS coming from 207.158.15.208. Can you explain why you would be doing this? You had better have a good explanation or I guarantee your company will be written up in all the security publications I write in and I will recommend that nobody ever use your product. Amazing, ain't? No previous contact, no double checking, nothing, just going ahead, threatening, menacing and being bold. Well, here goes the answer. As said, this is my very own opinion and the company (Alienvault) has nothing to do with it. Just for the records, before replying I logged in into the above host, checked for unauthorized access, ran several tcpdumps and checked logs on his domain. Clean. Oh, and I'm going to call the user "Hugo" after a big mounth president with the same name.
Hello Hugo, have you ever heard about kindness going a long way? Well, it usually works. If you had kindly requested information about this, either on the forums (where hundreds of happy users would've been eager to answer you), on the irc, even on this contact address, I'd have answered with a nice: "Hey Hugo, no worries, the 1.0.6 iso comes with an automatic, free, nessus plugin feed which gets checked on a daily basis. Due to the huge amount of users we've got we noticed rsync starting to duplicate itself, launching multiple instances which in turn get denied, provoking some sort of false positives". I even would've offered you help on sorting it out if that weren't the cause, which I'm pretty sure is. But... here you come, threatening, menacing with bad manners. So the answer is. Hugo, I encourage you to post the above mail to all the security publications you write in. I'm sure your mail has the possibility to become one of those long lasting laughers which will be used as openings in security conferences all over the world for the next few years. Not enough with this, I offer you to also publish it on the ossim forums. I for sure will post it on my blog (no worries, unless you grant me permission to do so I'll hide your name and mail) for other fellow users to comment on it. And, on top, I offer you a free refund for OSSIM. Oh, wait, you haven't paid a single cent for it... So please, just deinstall OSSIM right now, that will solve both our problems or I guarantee your name will be written up in all the security publications I write in and I will recommend that nobody ever lets you use their product. I'd feel bad coding OSSIM and knowing that you would benefit from it. With kind regards, Dominique Karg PS: Any views or opinions presented in this email are solely those of the author, that is, me and do not represent those of the company Things like these keep opensource developers motivated. *sigh* Update 2009/03/27: the story goes on. ::read more
posted at: 08:34 | path: /personal | permanent link to this entry | 5 comments | R.I.P. Elmo Tue, 10 Mar 2009
We've got bad news. Our former CEO/CTO/CSO/COO or whatever his role was decided to quit the company in a somewhat... harsh manner.
posted at: 14:33 | path: /personal | permanent link to this entry | 4 comments | A fairy tale about bank robbery - Un atraco con final feliz Sat, 28 Feb 2009
This is a short description of what happened to my girlfriend at a bank recently. It's not about millions, it's a short sum of money, but the way the bank tried to steal it from us is outrageous. I'll write it (exceptionally) in spanish, since it's happened here in Madrid at a "Banco Santander" office. I'll write a short sum up in english at the end :-)
Lo sucedido
Esto es el relato sin adornos de como el Banco Santander intentó robar hace poco a mi novia todo lo que tenia ingresado en el banco. Como ya decía en inglés, no es una pataleta, quiero denunciar un robo pero no tengo mejor sitio donde hacerlo.
Seis meses despues y tras informarnos de tasas de transferencia internacionales resulta que no compensa en absoluto ingresarla en españa y transferirle; mejor pagar el impuesto revolucionario del pais de destino directamente. Así que decidimos cerrar la cuenta y usar esos 50 euros para comprarle ropa a su sobrino (al de mi novia) que esta pasando una fase familiar "compleja".
Aquí ahora debería venir una larga lista de amargas quejas sobre el sisteema financiero, los bancos, la politica de la cutrez y mezquindad que domina nuestra sociedad actualmente, pero dejemoslo ahi.
English synopsisLong story short. We opened an account (at the Banco Santander) six months ago, entered 50 euros, wanted to cancel it last week after not having used it because international transfer fees were way too high on thihs bank and, to our inmense surprise, not only had we lost the 50 euros but we were supposed to pay an additional 8 euros to cancel the account. They charged us 27 euros of yearly maintenance, 12 euros for a credit card we never received nor used and another 17 as cancellation fees. The story had a happy ending tho: the nice people at the bank decided on their own to give us our 50 euros back without charging us anything, nice move :-). Aaah, and as a side note, this bank had a netto benefit of 8876 million last year.
posted at: 13:47 | path: /personal | permanent link to this entry | 1 comments | Thu, 04 Dec 2008 Although I'm not a big fan of all those social network thinggies, I joined facebook in order to check on a friend's pictures. Being there I decided to create a group for ossim in order to check in on fellow OSSIM users in a more "informal" manner, as opposed to linkedin. If you're curious about other users using ossim, feel free to join: http://www.facebook.com/group.php?gid=42954697060. Cheers all :-)
posted at: 11:17 | path: /personal | permanent link to this entry | 0 comments | Holidays :-) Wed, 16 Jul 2008 At last, time for a short break. I'll be off starting tomorrow until July 27th, down to the "Costa del Sol" with my beloved girlfriend, in order to get some sun, beach and Tintos de verano. The rest will be more than needed, since the next 1/2 year will be stressing:
So, for all of you who're planning holidays too, enjoy them, for those who stay, well, enjoy it too ;-).
posted at: 08:56 | path: /personal | permanent link to this entry | 0 comments | Cheers to our guys at Campus Party Colombia :-) Thu, 10 Jul 2008
I'm writing these lines to cheer at my co-worker (@AlienVault) Santiago "Santi" Gonzalez, who went to Bogota for a couple of weeks in order to implement OSSIM as security event and information monitoring solution at Campus Party in Colombia. Back to the party. You can check out some pictures at Flickr, it's quite of a mess but I'll try to update this entry tomorrow with some interesting pictures. So, as always this is a nice place to test ossim, do some benchmarks and improve some stuff. The party in Valencia is due to the end of this month and we hope we'll be there too :-) Last but not least, a big hug to my friends in Turkiye. Another co-worker (Juanma) has been there a couple of weeks ago doing some training; he's enjoyed it alot and I hope the people undergoing the ossim training too. Edit 2008/07/10: removed links to sites that contain information about AlienVault customers.
posted at: 08:01 | path: /personal/campus | permanent link to this entry | 1 comments | Help request on a Cisco issue. Tue, 27 May 2008 I've got some tests to do with a Cisco 6513 ACE-10 card. My testing environment is very limited and I'd greatly appreciate getting some feedback from someone knowledgeable with that thing. Having someone help me setup a quick test environment with two hosts balancing http would be awesome of course, but any help is greatly appreciated. Should you have any feedback please contact me at dk@ossim.net. TYIA.
posted at: 15:53 | path: /personal | permanent link to this entry | 2 comments | |
Categories
/ (57) Dominique Karg (feel free to get in touch) Friend's blogs:
Archives
2009-Jun Tags | |||||||||||||||||||||||||||||||||||||||||||||||||
![]() |
![]() |





