20
MARCH 2014 What’s New in AlienVault USM v4.5? USM Customer Webinar

Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

Embed Size (px)

DESCRIPTION

USM v4.5 is here! With a focus on ease of use, better error control, and suggestions to make your security visibility more complete, USM v4.5 works hard to save you time. Join us for this FREE customer-only training session to learn how USM v4.5 helps you: Streamline workflows: The more intuitive, easy to use, and consistent user interface helps you accomplish daily tasks in less time Reduce blindspots: USM v4.5 alerts you of network assets that aren't sending events to USM so you can quickly add them Avoid service disruptions: USM v4.5 proactively alerts you of impending errors related to disk space utilization, IDS packet capture issues, etc. Plus, we'll dive into some of the most common USM use cases to demonstrate how the new release makes it easier than ever to get complete security visibility. And, we'll preview a new Health Check offering we'll be rolling out soon. We're excited to explore the new release with you and hear your feedback!

Citation preview

Page 1: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

MARCH 2014

What’s New in AlienVault USM v4.5?USM Customer Webinar

Page 2: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

AGENDA

Feature Overview

Examples of how to use USM

New Health Check Service Offering

Questions

Page 3: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

New v4.5 Features

Page 4: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

SUMMARY OF NEW FEATURESNew Look and Feel New Plugin

Suggestion EngineNew Errors and

Warnings Dashboard

First Time Wizard Improvement

New Status Monitors Alarm Tag Forwarding

Page 5: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

NEW LOOK AND FEEL

Feature Summary:

Color, layout, and style improvements

Common library of UI elements (buttons, tables, interaction, workflow)

Value to You:

More intuitive, consistent, and easy to use

Predictable, consistent interaction and workflow

Reduced learning curve, increased time to value – “results in day one”

Page 6: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

PLUGIN SUGGESTION ENGINE

Feature Summary:

Identify assets sending data but with no plugin enabled

Identify assets not sending data and with no plugin enabled

Offer suggestions and built-in workflow to enable the proper plugin

Value to You:

More easily identify assets with no data collection and help the user easily enable the right plugin

Increase time to value when configuring new assets.

Page 7: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

NEW WARNINGS & ERRORS DASHBOARD

Feature Summary:

Warn administrators of conditions that require attention

Provide suggestions on how to resolve the error or warning

Value to You:

Self-monitoring to prevent system failure

Proactive notification

Page 8: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

FIRST TIME WIZARD IMPROVEMENT

Feature Summary:

Separated the Log Management step into two separate pages

Provide better clarity about each asset, plugin selected, and if AlienVault is receiving data.

Value to You:

Make the log management section more intuitive and easy to use.

Provide better information to tell the user if AlienVault is collecting data or not.

Page 9: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

NEW STATUS MONITORS

Feature Summary:

Built-in monitors to assess the system for failure conditions

Monitors Available:

The Asset is not sending any log to the system Asset is sending log to the system, but there isn't a plugin enabled to parse the logs The Asset was successfully sending logs to the system, but no log received within the

last 24 hours The System is dropping packets, overloaded The System is dropping packets, malformed network packets The System Disk space is under 25% The System Disk space is under 10%

Page 10: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

ALARM TAG FORWARDING

Feature Summary:

Alarms sent from a child server in a federated environment are tagged to uniquely identify the source

Customer Value:

Better support in MSSP, federated environments

Allow users to more easily discern what child server an alarm was generated on

Page 11: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

Use USM to Answer Simple Questions

Page 12: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

Is one of your system administrators running a bittorrent in the data center?

Page 13: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

What known malicious hosts are your systems talking to?

Page 14: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

Which of my vulnerable assets are under attack?

Page 15: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

Introducing…

USM Health Check Service

Page 16: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

Let us help you tune your AlienVault USM deployment so you can maximize the value of your investment.

USM Health Check Service

Validate that USM components are performing optimally and within specificationAssess directives, policies, and alarms to get you results you are expecting

Provide guidance on how to most effectively utilize USM to get results.

Deliver a comprehensive findings report to drive correction and improvements.

$2000

Page 17: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

This Service Is For …Who have …

A single All-in-One [25A, 50A, 75A, 150A, or Standard]

A Standard USM Server, Standard Sensor and Standard Logger combination

A Standard USM Server or All-in-One with up to 5 remote sensors

Other Options Available

Existing

s

Page 18: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

A Certified AlienVault Consultant will …

Spend one day (8 hours) to evaluate your deployment Services performed remotelyEvaluate …Operating system configuration and health• Query performance and indexing response times• USM content memory utilization• Sizing, capacity, and growth metrics• Data collection and plugin health• Policies to determine false positives and optimization

optionsReport delivered at the end of the engagement to provide …• Investigation results• Any remediations done during the engagement• Recommendations

Page 19: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5

Contact [email protected]

Interested?

Page 20: Customer Training: Detect and Respond to Threats More Quickly with USM v4.5