ossim user training: get improved security visibility with ossim

20
APRIL 2014 What’s New in AlienVault v4.6? OSSIM Customer Training

Upload: alienvault

Post on 15-Jan-2015

675 views

Category:

Technology


6 download

DESCRIPTION

Join us for for a free training session to review what's new in OSSIM v4.6 along with a demo of key use cases to help you get the most out of your OSSIM environment. We'll also give an overview of how you can improve threat detection and simplify incident response with the AlienVault Labs Threat Intelligence feed included in AlienVault Unified Security Management™ USM. We enjoyed hearing your feedback in last month's user training. We hope you'll join us again!

TRANSCRIPT

Page 1: OSSIM User Training: Get Improved Security Visibility with OSSIM

APRIL 2014

What’s New in AlienVault v4.6?OSSIM Customer Training

Page 2: OSSIM User Training: Get Improved Security Visibility with OSSIM

COMMUNITY GUIDELINES

Community members are not leads

We are a commercial company

OSSIM is not trialware

If you see something, say something

http://forums.alienvault.com/discussion/4/

Page 3: OSSIM User Training: Get Improved Security Visibility with OSSIM

AGENDA

v.4.6 Feature Overview

How To … Examples

Questions

Page 4: OSSIM User Training: Get Improved Security Visibility with OSSIM

New v4.6 Features

Page 5: OSSIM User Training: Get Improved Security Visibility with OSSIM

SUMMARY OF NEW FEATURE AREAS

Improved Download Experience Console Improvements

Getting Started Wizard Updates

Multi-Asset DeleteGetting Started Guide

Reduced Image Size Increased Download Reliability

Page 6: OSSIM User Training: Get Improved Security Visibility with OSSIM

IMPROVED DOWNLOAD EXPERIENCE

Feature Summary:

40% decrease in download size (2.4GB ~1.3GB)

Added new download servers + pause / resume capability

Customer Benefit:

Download the virtual appliance more quickly

Get to value more quickly

http://www.alienvault.com/free-trial

Page 7: OSSIM User Training: Get Improved Security Visibility with OSSIM

NEW GETTING STARTED GUIDE

Feature Summary:

Updated the AlienVault Quick Start Guide

New AlienVault Getting Started Guide

Customer Benefit:

Clear, detailed installation and configuration instructions to help new users get AV running quickly.

https://alienvault.bloomfire.com/posts/785625

Page 8: OSSIM User Training: Get Improved Security Visibility with OSSIM

CONSOLE IMPROVEMENTS

Feature Summary:

Improved menu structure, easier to navigate

New static configuration option on the Management Interface configuration

Prominently display the IP address of the device to ensure users are connected to the right device

Validate DNS entry to ensure that the DNS server is internal, allows internal hostname resolution

Page 9: OSSIM User Training: Get Improved Security Visibility with OSSIM

GETTING STARTED WIZARD IMPROVEMENTSFeature Summary:

New welcome screen that describes the wizard workflow

Merged the Log Management, Network monitoring paths into a single workflow

New screen to configure network interfaces

Visually show what devices have a plugin enabled

Clearly define the Management Interface within the network interface configuration screen

Automatically detect Management Interface network

Page 10: OSSIM User Training: Get Improved Security Visibility with OSSIM

MULTI-ASSET DELETE

Feature Summary:

It’s Back

Use the asset filter to select the assets

Delete them all with one click

Page 11: OSSIM User Training: Get Improved Security Visibility with OSSIM

How To …Examples

Page 12: OSSIM User Training: Get Improved Security Visibility with OSSIM

How To …Generate an email about an alarm

Page 13: OSSIM User Training: Get Improved Security Visibility with OSSIM

How To …Avoid SQL Storage for Events

Page 14: OSSIM User Training: Get Improved Security Visibility with OSSIM

How To …Find your Windows XP assets

Page 15: OSSIM User Training: Get Improved Security Visibility with OSSIM

OSSIM vs. USM

Page 16: OSSIM User Training: Get Improved Security Visibility with OSSIM

DIFFERENCE BETWEEN OSSIM AND USM

OSSIM USM

Support Community Commercial

Management - Centralized Administration and

ConfigurationThreat Intelligence Community

DevelopedAV Labs Threat

Intelligence Subscription

Reporting Community Developed

100+ Compliance and Threat Reports

Access Control - Rich RBAC with Permission Templates

Deployment Types Flat Deployments Single / Multi-Tiered Small Business to

Enterprise

Page 17: OSSIM User Training: Get Improved Security Visibility with OSSIM

http://www.alienvault.com/marketing/smb-bundles

Page 18: OSSIM User Training: Get Improved Security Visibility with OSSIM

SMALL BUSINESS BUNDLE OPTIONS

Page 19: OSSIM User Training: Get Improved Security Visibility with OSSIM

http://forums.alienvault.com

Page 20: OSSIM User Training: Get Improved Security Visibility with OSSIM