Types of log data for Helix Enterprise

Prev Next

The detection capability from various log sources can be compared with the "cost" (in terms of dollars as well as resources and effort) to form an efficiency curve.

The diagram below provides a prioritized view with the outside ring being the highest priority data to be ingested by Helix Enterprise.

data_priorities.png

Perimeter devices create a bottleneck for network traffic to the internet and are generally easy to configure for syslog. Perimeter devices such as firewalls translate outside IP addresses to outside Ops and track ports used, providing key information used to identify malware and other activities of known malicious actors. Web proxy events allow detection of beaconing activities and SQL injections.

Operating system logs, including system events and process tracking from high-value systems such as domain controller and logs from DNS, DHCP, and other anti-virus software, offer valuable context into potential malicious activity such as lateral movement.

Data logs such as file auditing, DLP, or file integrity auditing, have less value to security operations compared to other data sources and can be complex to implement effectively.

Event data generated by the following network devices, network services, security devices, and applications help detect advanced threats:

  • Web applications: IIS, Apache, Tomcat

  • Authentication sources: VPN, two factor, SSO, AD, LDAP

  • Network devices: Routers, switches

  • Network services: DNS, DHCP, NAT

  • Network sensors: Bro, Npulse, Extrahop

  • Security devices: Firewalls, IPS, DLP, NAC (Network Access Controls)

  • Applications: ERP, CRM, Web applications

  • Email: Server transaction events, filtering, security events

  • Threat Detection Systems such as Helix Enterprise

  • Internet devices: Switches, routers, and VPNs such as Cisco, Juniper

  • Web Proxy: BlueCoat, Websense

  • Endpoint security: Anti-virus, HIPS, Bit9

  • Log aggregators: Splunk, Q1, Rsyslog, ArcSight, RSA Envision, Estreamer

Note

JSON structured data file uploads should use port 515.