<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>eIQviews &#187; asset management</title>
	<atom:link href="http://blog.eiqnetworks.com/tag/asset-management/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.eiqnetworks.com</link>
	<description>Perspectives on Security and Compliance Management from eIQnetworks</description>
	<lastBuildDate>Mon, 14 Dec 2009 13:04:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.eiqnetworks.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/9a3baa02baa3289d9a8c9a6a0eb652a5?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>eIQviews &#187; asset management</title>
		<link>http://blog.eiqnetworks.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.eiqnetworks.com/osd.xml" title="eIQviews" />
	<atom:link rel='hub' href='http://blog.eiqnetworks.com/?pushpress=hub'/>
		<item>
		<title>Ten Reasons Log Data is Not Enough: #5. Who dat installing software?</title>
		<link>http://blog.eiqnetworks.com/2009/09/21/ten-reasons-log-data-is-not-enough-5-who-dat-installing-software/</link>
		<comments>http://blog.eiqnetworks.com/2009/09/21/ten-reasons-log-data-is-not-enough-5-who-dat-installing-software/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 14:55:15 +0000</pubDate>
		<dc:creator>Mike Rothman</dc:creator>
				<category><![CDATA[Log Management Series]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[asset management]]></category>
		<category><![CDATA[log management]]></category>
		<category><![CDATA[software install]]></category>

		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=277</guid>
		<description><![CDATA[As we continue down our analysis of why log data is not enough, the next issue we discover is installed software. Most malware (at least persistent malware) will do some kind of installation of the malicious code to steal data, which could be sniffing network traffic or key strokes or account numbers. The list goes [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=277&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>As we continue down our analysis of why <a href="http://www.logdataisnotenough.com" target="_blank">log data is not enough</a>, the next issue we discover is installed software. Most malware (at least persistent malware) will do some kind of installation of the malicious code to steal data, which could be sniffing network traffic or key strokes or account numbers. The list goes on and on. Many <a href="http://www.eiqnetworks.com/solutions/log_management.shtml" target="_blank">log management</a> or <a href="http://www.eiqnetworks.com/solutions/security_information_and_event_management.shtml" target="_blank">security information and event management</a> (<a href="http://www.eiqnetworks.com/solutions/siem.shtml" target="_blank">SIEM</a>) products will look at logs to figure out if some software was installed.</p>
<p><a href="http://www.flickr.com/photos/rafaespada/2053820847/" target="_blank"><img class="alignleft" style="margin:10px;" title="ubuntu install 2450 originally uploaded by rafa_espada" src="http://farm3.static.flickr.com/2365/2053820847_adeb2f1881_m_d.jpg" alt="" width="240" height="180" /></a>So that should solve the problem, right? The host log says software was installed and then you&#8217;ll know malware has been installed, act decisively and be the hero. Well, not so much. Do you know how many times a day a typical enterprise installs software on it&#8217;s managed devices. Hundreds? Thousands? More? It&#8217;s very likely too much for human analysis to figure out. What about those fancy correlation engines that will look for bad software? Hmm. For that to work, it needs to have a list of &#8220;good&#8221; software &#8211; which is always changing. I hope you are good with coding and regular expressions, because you&#8217;ll need to build a number of custom rules to make that work in a SIEM product.</p>
<p>The key is to be able to ENFORCE POLICY. As we discussed in <a href="http://blog.eiqnetworks.com/2009/09/10/ten-reasons-log-data-is-not-enough-3-whats-the-configuration-kenneth/" target="_blank">Reason #3 about configuration data</a>, the key to reacting faster to emerging threats is to detect something different, anomalous, and not normal. By establishing a set of policies for what software is allowed and then detecting when a device violates that policy, you can reduce the noise of watching every software install.</p>
<p>All of the anti-virus companies are talking about their shiny new, white-listing widget, and justifiably so. Taking a positive security approach (only allowing authorized software to run on managed devices) will definitely reduce the likelihood of infection. So this idea of monitoring for new software installs is sort of a poor-man&#8217;s white-listing.</p>
<p>Which is really the point of this entire series. There are many defensive techniques that are required to keep pace with today&#8217;s attackers. Just relying on a log management toaster or a SIEM &#8220;in a box&#8221; is not going to get the results you are looking for. Aggregating, parsing and even correlating on log data is just not enough.</p>
<br />Posted in Log Management Series, Security Tagged: asset management, log management, software install <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/277/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/277/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/277/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/277/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/277/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/277/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/277/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/277/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/277/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/277/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=277&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2009/09/21/ten-reasons-log-data-is-not-enough-5-who-dat-installing-software/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike</media:title>
		</media:content>

		<media:content url="http://farm3.static.flickr.com/2365/2053820847_adeb2f1881_m_d.jpg" medium="image">
			<media:title type="html">ubuntu install 2450 originally uploaded by rafa_espada</media:title>
		</media:content>
	</item>
		<item>
		<title>Controlling the browser, if you can</title>
		<link>http://blog.eiqnetworks.com/2009/02/05/controlling-the-browser-if-you-can/</link>
		<comments>http://blog.eiqnetworks.com/2009/02/05/controlling-the-browser-if-you-can/#comments</comments>
		<pubDate>Thu, 05 Feb 2009 17:07:39 +0000</pubDate>
		<dc:creator>Mike Rothman</dc:creator>
				<category><![CDATA[User Issues]]></category>
		<category><![CDATA[asset management]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[configuration audit]]></category>
		<category><![CDATA[Firefox]]></category>

		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=96</guid>
		<description><![CDATA[Andreas makes a number of good points in his weekly NetworkWorld column about Firefox add-ins. His general point is that software extensibility is good, but it must be controlled lest you introduce significant new risks to your environment. I couldn&#8217;t agree more. That&#8217;s why a lot of the work we at eIQ do with configuration [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=96&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Andreas makes a number of good points in <a href="http://www.networkworld.com/columnists/2009/020309antonopoulos.html" target="_blank">his weekly NetworkWorld column about Firefox add-ins</a>. His general point is that software extensibility is good, but it must be controlled lest you introduce significant new risks to your environment. I couldn&#8217;t agree more. That&#8217;s why a lot of the work we at eIQ do with configuration auditing is such an important part of maintaining a secure environment.</p>
<p>Most security organizations don&#8217;t have the pull to really lock-down desktops. Sure they can mandate a standard build, but in most cases users can install software that they want, and sometimes that software becomes a problem. The reality is you can&#8217;t avoid these issues, but you need to figure out how to react faster and appropriately when an issue crops up.</p>
<p>The first step is to know what&#8217;s out there. A lot of organizations rely on asset management tools to assemble information on who is using what. You can also figure out what software is out of policy and decide whether to do anything about it. Sometimes it&#8217;s the better answer to turn the other cheek, in terms of getting rid of unauthorized software. But it&#8217;s not OK to not know it&#8217;s there.</p>
<p>Just as important as understanding what&#8217;s out there, you need to understand what&#8217;s changing. That&#8217;s why constantly revisiting the asset base and the device configurations are critical. And just doing one or the other isn&#8217;t enough. New software can (and usually does) change configurations and that can create security exposures.</p>
<p>To bring the point home, it&#8217;s probably unreasonable to expect that your users will allow you to totally control what software they are running. But you CAN and SHOULD know what they are running and be able to pinpoint when something changes to evaluate the security risk to your environment. That&#8217;s just good security practice.</p>
<br />Posted in User Issues Tagged: asset management, browser, configuration audit, Firefox <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/96/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=96&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2009/02/05/controlling-the-browser-if-you-can/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike</media:title>
		</media:content>
	</item>
	</channel>
</rss>