Blog|Login|Chinese German Japanese|Follow @imperva
June 10, 2009
 SecureSphere followed Action and OS Integration - Part I
Following Imperva's DIY syslog format posting by bmestep I decided to write in more details about SecureSphere's "content out" integration with different systems, starting with the generic interfaces first. This is the first post in the series. 

SecureSphere provides rich set of out-of-the-box policies for Data protection, yet one might need to add 3rd party integration or perform a task that is unique for his organization. SecureSphere security administrators can use built-in interfaces for syslog, email, snmp, ticketing and OS command integration to perform such tasks.

Let's start with the basics: SecureSphere provides a method to perform external activities and integrate with 3rd party applications using Action Sets: predefined action templates that are performed as a respond to a security or system event occurrence and provide a variety of detection, monitoring and management options. Action Sets are assigned to SecureSphere policies using the Followed Action parameter. Each Action Set is applied to an event according to the event type, which is also matched to the policy type. Defining different actions for each type is performed using Action Interfaces

The following screenshot illustrates the relationship between Action Sets and Action Interfaces: 
Action Set (listed on the left) serve as the policy repository for the different actions that will take place when an event occurs. The diagram below shows 6 action interface options (sends email, OS command, send syslog, create SecureSphere task and review SecureSphere task).  

action interface.png
Action Sets and Action Interfaces (click to see a larger image)

A single Action Set might have multiple interfaces. The Action Set is invoked by SecureSphere's policy using followed action.  One can add as many Action Sets and Action Interfaces as needed. 
The picture below shows how multiple rules of the SQL Profile Policy can have different actions and different Followed Action. Each Followed Action can invoke an Action Set

policies with followed actions.png

Action Sets Used In Policies (click to see a larger image)

As you can see, within a policy, different rules can have different followed actions, providing a high level of flexibility for integration with external systems as well as different business owners.  

Next, I'll discuss the OS command interface. 


Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.

« Podcast - Jeremiah Grossman of Whitehat Security Talks about Bringing Together WAF and VA | Main | Spicy Food Challenge #4 - Tokyo Japan »