Tripwire steps into SIEM territory

Tripwire steps into SIEM territory

By Robert Westervelt | Feb 8, 2010

Tripwire Inc. has announced plans to sell security information and event management (SIEM) technology, but analysts say it's entering an already chaotic and crowded market where it is sometimes difficult for enterprises to thoroughly evaluate vendors.

The Portland, Ore.-based configuration management vendor is introducing Tripwire Log Center, selling log and event management software that can tie into many different systems.

The biggest challenge for enterprises is to get SIEM software to tap into event data from a variety of proprietary data sources, such as network firewalls and intrusion detection systems. The goal of SIEM products is to help collect and analyze all the activity data to determine the overall health of a network. In addition, SIEM systems are being deployed to give compliance auditors evidence that a company is maintaining log data and that someone within the organization is minding the network.

"All these tools were originally designed to take logs from security devices and correlate them for threat purposes," said John Kindervag, a senior analyst at Cambridge, Mass.-based Forrester Research Inc. "There was never a movement to put payment application data into some of these things and with the various payment applications out there it can be a difficult process."

With much of the interest in SIEM products driven by compliance initiatives, the market for SIEM products is jam-packed with vendors, many competing with similar products. Established names include Arcsight Inc., CA Inc., Intellitactics Inc., IBM, NetIQ Corp. and EMC's RSA Security division. Other vendors include LogLogic Inc., NetForensics Inc., Novell Inc., Sensage Inc., Symantec Corp. and TriGeo Network Security Inc.

Most vendors sell SIEM appliances and prepackaged software, though there are no advantages to choosing an appliance over a software package. Alternatively, Kindervag said small and midmarket companies may eventually choose SIEM in a Software as a Service (SaaS) package.

 
 

Add comment

Post a Comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <a> <p> <span> <div> <h1> <h2> <h3> <h4> <h5> <h6> <img> <img /> <map> <area> <hr> <br> <br /> <ul> <ol> <li> <dl> <dt> <dd> <table> <tr> <td> <em> <b> <u> <i> <strong> <font> <del> <ins> <sub> <sup> <quote> <blockquote> <pre> <address> <code> <cite> <embed> <object> <strike> <caption>
  • Lines and paragraphs break automatically.
  • Use <!--pagebreak--> to create page breaks.

More information about formatting options

 

knowledge_central_tab

 
 
Knowledge Central
Today's top security priorities
Attacks based on vulnerabilities in websites are skyrocketing, and not many solutions are available to protect organizations against them. How do you deal with this and other key security issues today?
Taking a holistic business-centric approach to security
Today’s CIOs face multiple challenges, including the need to innovate in an extremely competitive business climate, address highly dynamic regulatory and compliance challenges, speed ROI to counter shrinking IT budgets, and secure their organizations against a wide barrage of sophisticated threats.
 
 
 
UTM product offers Logansport Savings Bank superior protection
Astaro Security Gateway’s IPS was able to block attacks that other intrusion prevention systems (IPS) missed at Logansport Savings Bank.
Hong Leong Financial opts for Juniper Networks at new Malaysia head office, data center
Hong Leong Financial Group Berhad builds complete and seamless data center and office network infrastructure with Juniper switches, security devices and Junos software.