This event has ended!
View current events hosted by BayLISA
May General BayLISA eventThursday, May 18, 2006 from 7:00 PM to 10:00 PM (PT)Cupertino, CA |
|
Event Details
Correlating Identity Information in Open Source Applications Using Multifunction Identity & Access Management Appliances: A Hands-On Hardware Demo
System administrators use a variety of security and network monitoring systems to secure their production networks. Open source tools such as SNORT, Nessus, Clam-AV and others are widely deployed security tools providing a wealth of functionality. However, the alerts and syslog event messages generated by nearly all security and network systems, both open source and commercial, have lacked the ability to provide the user identity information.
Without identity, network and security forensics are performed through manual "back-tracking" of MAC address to IP address to hostname and then to user identity. This can add time and effort to forensic and network management processes where speed is critical, especially as data sets grow and compliance and internal controls are being pushed for adherence.
A10 Networks will present its identity & access management appliance with a thin XML client and show how it can be integrated with open source security solutions such as SNORT - allowing the rapid correlation of critical network security alerts with user identity information. With identity information as part of the alert and syslog message, enforcement of corporate security policies and computer usage policies become much easier.
Philip Kwan, A10 Networks
Phil served as an IT Director for more than 20 years, building and managing networks for companies such as Incyte Genomics, Applied Materials, and McGraw-Hill School Systems. Phil brings hands-on experience and a user perspective to his role leading product marketing for A10 Networks. Prior to A10, he was director of product management at Fortinet and a product line manager for wireless at Foundry Networks. He has served on the technical advisory boards of numerous Silicon Valley technology companies. He holds a degree in Computer Information Systems from Langara College, Canada.
Using search technology for troubleshooting within the data center
As the data center continues to become more and more complex, troubleshooting systems has become more challenging. Fixing problems is not usually the hard part, but rather finding the the location of the problem at the logical level. Thus, Splunk came up with search technology as the answer. We'll share with you why search technology for IT data is so powerful and how we designed Splunk software to meet the needs of such challenging data. Splunk uses universal event classification providing IT professionals the basis for discussing the same types of events across infrastructure contexts. Splunk Base is the service--a global wiki of IT events that utilizes the event classification--where professionals can discuss event issues. We'll show demonstrations of Splunk software for some advanced troubleshooting scenarios including using it in conjunction with Splunk Base. Also find out what's coming in Splunk's future, including distributed search, data level access controls and pattern detection.
Rob Das, Chief Splunk Architect and Co-founder
Rob is the man behind the architecture. He's a technology leader with 22 years of large-scale software architecture and engineering experience in early-stage ventures and large companies including 280, Avolent, CommerceFlow, Data Broadcasting, Lotus, Sun Microsystems and Taligent. He has in-depth product lifecycle experience, and has delivered to market several innovative enterprise software systems currently in use at many of the largest Fortune 500 companies. Rob.s technology expertise includes high performance and high availability server architecture and implementation, financial transaction interfaces, information search and retrieval and network file systems. Rob studied computer science at Indiana University and is the inventor of several U.S. patents.
When & Where
Apple Campus
10500 N De Anza Blvd
De Anza 3 Auditorium
Cupertino,
CA 95014
Thursday, May 18, 2006 from 7:00 PM to 10:00 PM (PT)
Add to my calendar
Hosted By
BayLISA
BayLISA includes system and network administrators across a range of skill levels. BayLISA meets monthly to discuss topics of interest to administrators and managers of sites supporting more than 100 users and/or computers. blw@baylisa.org to contact event coordinators.