20
Vulnerability Management using Open Source Tools Vikram Meh Sr. Manager – Information Securi MakeMyTr

Vulnerability Management using Open Source Tools v1.0

Embed Size (px)

Citation preview

Page 1: Vulnerability Management using Open Source Tools v1.0

Vulnerability Management using Open Source Tools

Vikram MehtaSr. Manager – Information Security

MakeMyTrip

Page 2: Vulnerability Management using Open Source Tools v1.0

2

Agenda

1. Operational Challenges

2. General Vulnerability Management Architecture

3. Automation Possibilities

4. Insight

5. Info sources

Page 3: Vulnerability Management using Open Source Tools v1.0

3

Agenda

1. Operational Challenges

2. General Vulnerability Management Architecture

3. Automation Possibilities

4. Insight

5. Info sources

Page 4: Vulnerability Management using Open Source Tools v1.0

Operational Challenges

1. Multiple scanning sources

2. Consolidating vulnerability information

3. Alerting / notification

4. Lack of consolidated dashboards

5. Tracking to closure

Page 5: Vulnerability Management using Open Source Tools v1.0

5

Agenda

1. Operational Challenges

2. General Vulnerability Management Architecture

3. Automation Possibilities

4. Insight

5. Info sources

Page 6: Vulnerability Management using Open Source Tools v1.0

6

General Architecture

Scanner 1

Scanner 2

Scanner 3

Manual Results

Consolidation Alerting / Analysis

Tracking

Page 7: Vulnerability Management using Open Source Tools v1.0

7

General Architecture

Nessus

AlienVault

ZAP

Manual Results

Consolidation Alerting / Analysis

Tracking

Page 8: Vulnerability Management using Open Source Tools v1.0

8

General Architecture

Nessus

AlienVault

ZAP

Manual Results

Consolidation Alerting / Analysis

Tracking

XML

mySQL

XML

XLS

Page 9: Vulnerability Management using Open Source Tools v1.0

9

Automation Possibilities

Nessus

AlienVault

ZAP

Manual Results

Consolidation Alerting / Analysis

Tracking

XML

mySQL

XML

XLS

Import JobsDB Connectors

Integration Connectors

mySQL ELSA

BugZillaOTRS

Activiti

Page 10: Vulnerability Management using Open Source Tools v1.0

10

Agenda

1. Operational Challenges

2. General Vulnerability Management Architecture

3. Automation Possibilities

4. Insight

5. Info sources

Page 11: Vulnerability Management using Open Source Tools v1.0

Insight - Consolidation

11

Simple DB Connector (ELSA)

1378383608 1936864308 NESSUS 10003 IP: X.X.X.X | Port: 80 | SVC: www | Protocol: tcp | Severity: 0 | NID: 11219 | Plugin Name: Nessus SYN scanner | Plugin Family: Port scanners | Plugin Modification Date: 2011/04/05 | Plugin Type: remote | Risk Factor: None | Synopsis: It is possible to determine which TCP ports are open. 0 80 No CVSS Base Score No CVSS Temporal Score 0 NO FIELD tcp 11219 It is possible to determine which TCP ports are open. www None

Nessus Report Parser (ELSA)

AlienVault

Page 12: Vulnerability Management using Open Source Tools v1.0

Insight - Consolidation

12

Third Party

Manual Results

XML

CSV

Import Jobs / Custom Code

Database

Page 13: Vulnerability Management using Open Source Tools v1.0

Insight – Alerting / Analysis

13

Page 14: Vulnerability Management using Open Source Tools v1.0

Insight – Alerting / Analysis

14

Page 15: Vulnerability Management using Open Source Tools v1.0

Insight – Alerting / Analysis

15

Page 16: Vulnerability Management using Open Source Tools v1.0

ELSA - Dashboards

16

Page 17: Vulnerability Management using Open Source Tools v1.0

Insight – Tracking

17

BugZilla

OTRS

API

SMTP

IntegrationDatabase ActivitiAPI

Page 18: Vulnerability Management using Open Source Tools v1.0

Insight – Tracking

18

BugZilla

OTRS

API

SMTP

IntegrationDatabase ActivitiAPI

Simple issue tracking

Work-flow, SLA andescalation management

Page 19: Vulnerability Management using Open Source Tools v1.0

Questions?

Page 20: Vulnerability Management using Open Source Tools v1.0

20

Info Sources

1. ELSA - https://code.google.com/p/enterprise-log-search-and-archive/

2. BugZilla - http://www.bugzilla.org/

3. Activiti - http://activiti.org/

4. OTRS - http://www.otrs.com/

and a lot of good work already done in this area