Click me
Transcribed

How Well Are You Monitoring Your 3A's?

WHITE HAT LAB REPORT nuspire BROUGHT TO YOU BY networks HOW WELL ARE YOU 3A's? MONITORING YOUR ACCESS AUTHENTICATION AUTHORIZATION ACCESS is determined by restricting access based on something other than the identity of the user AUTHENTICATION refers to the process where an entity's identity is authenticated AUTHORIZATION determines whether a particular entity is authorized to perform a given activity ---- ----- A RECENT REPORT BY NUSPIRE'S WHITE HAT LABS FOUND THAT AAA THREATS 4&5 MAKE UP LEVEL 45% OF THE OVERALL THREAT LANDSCAPE IN THE MONTH OF JUNE, NUSPIRE FOUND 33,511 21,475 FAILED ATTEMPTS AT ADMINISTRATOR LOGINS INSTANCES OF WEBSITE ADMIN ACCESS BLOCKED 3,892 ATTEMPTS AT WIRELESS ACCESS DENIED 566 FAILED ATTEMPTS AT VPN ACCESS THESE AAA INSTANCES CAN BE REDUCED BY A STANDARD MANAGED FIREWALL THE THINGS EVEN ADVANCED FIREWALLS CANNOT DO ARE CORRELATIONS EXAMPLE OF AN ACCESS/AUTHENTICATION/AUTHORIZATION CORRELATION RULE EXCESSIVE FAILED ADMIN LOGIN ATTEMPTS FOLLOWED BY A SUCCESSFUL LOGIN FOLLOWED BY USER FOLLOWED BY GIVEN HIGHER CONFIGURATION PRIVILEGE RIGHTS CHANGES 1+2+3+4=CORRELATED AAA EVENT ONCE A HACKER IS IN AS AN AUTHENTICATED USER THERE'S NO LIMIT TO THE AMOUNT OF DAMAGE THEY CAN DO IF YOU'RE NOT MONITORING YOUR 3 A's THROUGH CORRELATION AND HUMAN ANALYTICS WITH REAL-TIME RESPONSE, NUSPIRE CAN HELP O nuspire networks *Data represented in this document taken from combined global managed security services clients over a 30 day period during the month of June 2013 Source: Nuspire proprietary SIEM data www.nuspire.com

How Well Are You Monitoring Your 3A's?

shared by infographer on Jun 18
112 views
0 shares
0 comments
Infographic showing how a modern network security posture needs human analytics to create correlation rules for Security Information Event Management (SIEM) systems to be fully utilized.

Publisher

Nuspire

Designer

infographer

Category

Computers
Did you work on this visual? Claim credit!

Get a Quote

Embed Code

For hosted site:

Click the code to copy

For wordpress.com:

Click the code to copy
Customize size