Security Log Management: Identifying Patterns in the Chaos

Hopefully, in this chapter there have been some takeaways that you can use or implement in your organization to improve the level of informed security measures are in place. Another key point in this chapter was to illustrate the effectiveness of a true defense in depth IDS architecture while at the same time having a checks-and-balances system of validation of data through use of multiple tools. One good example is the use of session logging from Argus and Lancope to validate that they both see the same thing on the same span port. Another important takeaway is to report in useful and distributable information from your security devices. One example that is used over and over is to translate the technical information into an understandable format such as graphs and charts. If the data is presented in that format, it is easily distributed to other interested parties, and then, hopefully, upper management and/or the client will have a better understanding about threats to the networks. This type of understanding can lead to management knowing the return on investments (ROI) that they have made to the security teams in such forms as firewalls, IDS, router and ACLs, just to name a few line items.