fhs
Volume 11, Number 8 -- March 1, 2011

Raz-Lee Feeds IBM i Data into RSA SIEM

Updated: March 18, 2011

by Alex Woodie

RSA Security recently certified IBM i security software from Raz-Lee Security to feed log data into its enVision security information and event management (SIEM) offering. The integration gives IBM i shops a proven way to keep one of the security world's most adopted and well-respected SIEM devices in tune with events occurring on the IBM i server.

Earlier this month, Raz-Lee announced that RSA had certified iSecurity version 11.4 to translate IBM i data into the Syslog format, and feed it into the enVision SIEM, an enterprise-class security device that's been adopted by about 1,600 customers. The integration involves various components of iSecurity, including AP-Journal, Audit, Anti-Virus, Firewall, and Authority on Demand.

As a result of the integration, several security events on the IBM i server can now be detected in real time via the SIEM, including: attempts to hack into the server through network exit points; attempts to change user authority levels; the presence of viruses on the IFS; and attempts to edit or delete IBM i application objects and data files.

The integration satisfies demand from RSA customers to include the IBM i server within the scope of protection provided by the enVision SIEM device. IBM i event information can now be included in standard security and compliance reports generated by enVision. Most importantly, customers can now correlate any unusual activity detected on the IBM i server with activity detected in other computer systems and networks. This is the crux of the SIEM, and enables organizations stay on top of the latest blended threats that cyber criminals are using to pilfer corporate IT systems for data and money.

Internal networks are used to send IBM i event information from iSecurity to envision. Users can send the data via several means, including the IBM i message queue (MSGQ), short messaging service (SMS), simple network management protocol (SNMP), and even the Twitter messaging service, according to an RSA implementation guide. Raz-Lee added automatic generation of Twitter messages to its products last year at the COMMON conference in Orlando, Florida.

According to the RSA brochure, iSecurity can use Twitter to send IBM i security information at speeds of up to 1,000 lines per second. Messages can also be sent under different severity ratings, including emergency, alert, critical, error, and warning.

Raz-Lee touts one of the largest insurance companies in Israel as one of the first iSecurity customers to start sending IBM i data to enVision. According to a customer brief from Raz-Lee, the company was able to stop storing IBM i event data on the IBM i server itself after it started sending them to enVision, which saved a considerable amount of disk space, as well as I/O overhead.

The company also discovered what many other security experts have been saying for years: that the IBM i server can be somewhat chatty when it comes to logs and message queues. It was generating so much IBM i log data that it overwhelmed enVision, and the company was forced to use filters to scale back the number of events it sent over the wire.

iSecurity is not the only IBM i security tool that can feed data to enVision, which was originally developed by a company called Network Intelligence that was acquired by EMC around the same time that EMC bought RSA in 2006. Raz-Lee doesn't have formal partnerships in place with other SIEM vendors, but a company spokesman says it's easy to support other SIEMs. Raz-Lee does have a partnership with Imperva, which focuses on database security.

The integration supports Raz-Lee iSecurity version 11.4 and higher running on i5/OS V5R3 through IBM i 7.1. For more information, see the vendors' websites at www.rsa.com and www.razlee.com.


RELATED STORIES

Raz-Lee Unveils GUI for IBM i Journal Security Tool

Raz-Lee Gets the Twitter Bug

Imperva and Raz-Lee Team Up for DB2/400 Security Software

Raz-Lee Adds Object-Level Security to i OS Security Suite

RSA Cracks Down on Security Threats with enVision 4.0



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
MANAGEENGINE

iSeries Systems Monitoring
Improve Operations Productivity

Advantages of using ManageEngine Applications Manager:

· Monitor iSeries Jobs, Spools, Printer, Disk, Subsystems via an Intuitive Web Interface!
· Agentless Monitoring Solution makes maintenance easy
· Intuitive Web based console
· Root Cause Analysis helps quick troubleshooting
· Trend Analysis and Capacity Planning Reports
· Anomaly Detection to help you identify issues proactively
· Heterogenous Systems Monitoring [Linux, Windows, HP-UX, AIX, Solaris, FreeBSD, Tru64, Mac OS]
· Monitor WebSphere MQ, WebSphere, DB2, AIX and iSeries Systems
· Web Transaction and End User Monitoring Capability

For more information, visit
www.manageengine.com


Editor: Alex Woodie
Contributing Editors: Dan Burger, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

System i Developer:  Upgrade your skills at the RPG & DB2 Summit in Orlando, March 22-24
Townsend Security:  Learn how to easily and securely communicate with XML
Northeast User Groups Conference:  21th Annual Conference, April 11 - 13, Framingham, MA


 

IT Jungle Store Top Book Picks

BACK IN STOCK: Easy Steps to Internet Programming for System i: List Price, $49.95

The iSeries Express Web Implementer's Guide: List Price, $49.95
The iSeries Pocket Database Guide: List Price, $59
The iSeries Pocket SQL Guide: List Price, $59
The iSeries Pocket WebFacing Primer: List Price, $39
Migrating to WebSphere Express for iSeries: List Price, $49
Getting Started with WebSphere Express for iSeries: List Price, $49
The All-Everything Operating System: List Price, $35
The Best Joomla! Tutorial Ever!: List Price, $19.95


 
The Four Hundred
LUG Issues Call to iASP Arms for ISVs

Mainframes Put IBM Back on Top for Servers in Q4

Social Business Ushering Changes in Content Management

Mad Dog 21/21: Talking Toklas

IT Spending Better Than Expected Last Year, And 2011 Looking Up

Four Hundred Guru
Secure DB2 for i Database Server Access by IP Address

Avoid Division by Zero in Query/400

Image Catalogs: Another Timesaving Method for Upgrade or Installs

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

System i PTF Guide
September 25, 2010: Volume 12, Number 39

September 18, 2010: Volume 12, Number 38

September 11, 2010: Volume 12, Number 37

September 4, 2010: Volume 12, Number 36

August 28, 2010: Volume 12, Number 35

August 21, 2010: Volume 12, Number 34

TPM at The Register
Godson: China shuns US silicon with faux x86 superchip

Amazon automates AWS app deployment

IBM reclaims server crown from HP

Intel outs future Xeon chip porn

AMD's Bulldozer cores to push to 3.5 GHz and beyond

SGI lays off 4 per cent of workforce

Doing the math on IBM's real systems biz

HP misses Q1 sales, revises 2011 downward

Acer launches server biz in the US

Ethernet, Fibre Channel sales boom in Q4

Oracle debuts carrier-grade Sparc T3 servers

How to build your own Watson Jeopardy! supermachine

THIS ISSUE SPONSORED BY:

Maxava
Abacus Solutions
ManageEngine
Townsend Security
Twin Data Corporation


Printer Friendly Version


TABLE OF CONTENTS
BIRT Makes Open Source Waves in BI World

IBM i Vendors: It's Time to Rally

Raz-Lee Feeds IBM i Data into RSA SIEM

Sirius Claims Third Consecutive Beacon Award, Notes IBM i Trends

PowerTech Adds Innovatum's Monitoring Tool to Product Mix

News Briefs and Product Shorts:

E-Mail Storage Solution for Outlook Users from ACOM . . . MaddenCo Goes GUI with Tire Store App . . . Key to Resell UNIT4 CODA Financials . . . Friedman Nabs Viewlocity for SCM . . . Solarsoft Reports New Implementations of iVP Suite . . .

Four Hundred Stuff

BACK ISSUES




 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2011 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement