SlideShare uma empresa Scribd logo
1 de 18
ObserveIT:
User Activity Monitoring

Mark Kreymer
mark@observeit.com
June, 2013

Copyright © 2011 ObserveIT. All rights reserved.
All trademarks, trade names, service marks and logos referenced herein belong to their respective companies. This document is for informational purposes only.

www.observeit.com
ObserveIT Software that acts like a security camera on your servers!

 Video camera: Recordings of all user activity


 Summary of key actions: Alerts for problematic activity

2
700+ Enterprise Customers
Healthcare / Pharma

Financial

Telco & Media

Manufacturing

Retail / Service

Utilities / Logistics / Energy

IT Services / Technology

Government

Gaming

3
Worldwide Presence
France
CG61
S2IH
BOUYGUES TELECOM
Societe Generale
Groupama Asset
Management (GAM)

Spain
Banco Espirito Santo S.A.
CECA (Confederación
Española de Cajas de
Ahorros)
BBVA
Caja Madrid

Canada
Bell Canada
Quebec Loto
Bellin Treasury Services Ltd.
Toronto Hydro
Transat A.T. Inc.
Atlantic Lottery Corporation
(ALC)

UK

Germany

Norway

Estonia

UK Payments Administration Ltd
Sanofi Aventis
VTS
Estonian Security
BlackRock
HSH Nordbank
Police Board
QinetiQ
Boehringer Ingelheim GmbH
Switzerland
Vocalink UK
AGRAVIS Raiffeisen AG
BCN
Friends Provident
Deutsche Telekom AG
Bank Vontobel AG
Hyperion Insurance Group
Schweizerische Bundesbahnen (SBB)
LCH.Clearnet Ltd.
Luxemburg
Swiss Federal Railway
BSkyB Sky Network Service
TELINDUS Luxmeburge
ZKB
Xtrakter Ltd
Corner Banca SA
Opal Telecom Ltd
Banca del Sempione
Talk Talk Technology (Carphone CPWN) Liechtenstein
Banca Euromobiliare Suisse
BNP Paribas Real Estate Advisory (UK) LGT FInancial Services
BancaStato
VTB Capital plc
Baillie Gifford & Co.
Italy
Heritage Group LTD
Vodafone (Italy)
ELECTRONIC'S TIME SRL
Allianz SPA
ING Lease Italia S.p.A.
UBI Banca Sistemi&Servizi
Xerox s.p.a.

Poland
Podkarpacki OddziaB
Wojewódzkiego Narodowego
Funduszu Zdrowia z siedzib w
Rzeszowie
Elektrotim S.A.
Inteligo Financial Services S.A.

Czech Republic

Hungary

Greece

GE Money Bank

Wiz
z Air

hol

Croatia

Slovenia

Cyprus

T-Mobile Croatia
OTP

Zavarovalnica Triglav d.d
Raiffeisen banka d.d.

SEM Ltd

Slovakia
Tatra Banka a.s.

South Korea
Japan
Mitsubishi Information

USA
Trend Micro Inc.
Shumway Capital Partners, LLC
Spoken Communications
University Health Systems of Eastern Carolina
Casino Arizona
CDW
Dimension Data Americas (USA)
CSX Technology
PGE - Portland General Electric
Cisco (Webex)
St. Jude Medical
UPS
Disney
IBM
Newegg
Spring Branch Independent School District
Sony
British Petrolum (BP)
SUNY Downstate
Washington University
Western Governors University
Kroll Ontrack
BNP Paribas
StrataCare, LLC.
Societe Generale (USA)
MFS Investment Management
Fort McDowell Enterprises
CHARLES SCHWAB & CO
Aastra
Cost Plus World Market (CPWM)

Samsung Networks Korea
Yonsei Hospital
GS Caltex
Defense Acquisition
Program Administration

China
Taiwan
Trinidad &
Tobago
Bolivia

Turkey

PETROTRIN

Telecel S.A. TIGO

Chile
Nexus

Argentina
Nuevo Banco del
Chaco S.A.

Angola
Banco Nacional
de Angola

Chad
MIC Chad, Ltd. TIGO

South Africa
Derivco (PTY) Ltd.
Ubank
MultiChoice Africa (Pty)
Ltd.
Clicks Group Ltd.
Truworths, South Africa

Tanzania
MIC Tanzania, Ltd. TIGO

Turkcell
ANADOLU SIGORTA
Vakifbank
Yasar Factoring
T.C. Ziraat Bankas1

Israel

Qatar

Taiwan Railways
Administration, MOTC
Taiwan Accreditation
Foundation (TAF)
Taiwan Mobile

Ministry of Education
China Construction Bank
China Mobile Group Guangdong Co.
ShinseiBank
Tesco China
China Foreign Exchange Trade System
National Interbank Funding Center
The Hong Kong Jockey Club
DMX

India
HDFC Bank Ltd.
iYogi
HCL
Wipro

Excellence Nessua
QFC Regulatory Authority
Yes
Court of the Crown Prince (CPC)
Leumi Bank
Financial Centre Authority
Harel Insurance
Hapoalim Bank
United Arab Emirates
Ayalon Insurance
First Gulf Bank
Australia
Pelephone
Metito Overseas Ltd.
Woodside Energy Ltd
Comverse
AHI Carrier Fzc
Australian Stock Exchange
Zim
NetstarLogicalis
Clal Insurance
Bezeq
Visa
Coca Cola
Orange
First International Bank
Bank Discount
Ministry of Interior

Philippines
Asian Development Bank

Singapore
BT Frontline
Siemens Medical
Singapore Post
Singapura Finance
UOB
Shimano

4
Business challenges that ObserveIT addresses

Remote Vendor
Monitoring
• Impact human behavior
• Transparent SLA and billing
• Eliminate ‘Finger pointing’

Compliance &
Security Accountability

Root Cause Analysis &
Documentation

• Reduce compliance costs for
GETTING compliant and
STAYING compliant
• Satisfy PCI, HIPAA, SOX, ISO

• Immediate root-cause answers
• Document best-practices

5
An Analogy
Bank Branch Office

Bank Computer Servers

Companies invest in access control
but once users gain access,
there is little knowledge of
who they are and what they do!
(Even though 71% of data breaches
involve privileged user credentials)
They both hold money…
…They both have Access Control…
...Here they also have security cameras…
…Here, they don’t!

6
Why?
Because system logs are built by DEVELOPERS for DEBUG!
Only 1% of data breaches are
(and not by SECURITY ADMINS for SECURITY AUDIT)
discovered by log analysis!
(Even in large orgs with established SIEM processes,
the number is still only 8%!)

“

“

“

“

I don’t have this problem.
I’ve got log analysis!

The picture isn’t quite as
rosy as you think.
7
Can you tell what
happened here?

Replay Video

Wouldn’t it be easier
with a ‘Replay Video’
button?

Video Replay shows
exactly what happened

8
And many commonly used apps don’t even have their own logs!
• DESKTOP APPS
DESKTOP APPS
•
•
•
•

Firefox / Chrome / IE
MS Excel / Word
Outlook
Skype

REMOTE & VIRTUAL
• Remote Desktop
• VMware vSphere

ADMIN TOOLS
•
•
•
•

Registry Editor
SQL Manager
Toad
Network Config

TEXT EDITORS
• vi
• Notepad

9
System Logs are like
Fingerprints
They show the results/outcome
System Logs areof what took place
like Fingerprints

User Audit Logs are like
Surveillance Recordings
They show exactly what
took place!

“

“

Both are valid…
…But the video log goes right to the point!

10
Our Solution
1: Video Capture
Video
Session
Recording

‘Admin‘
= Alex

Logs on as ‘Administrator’
X X X

IT
Alex the
Admin

2: Video Content Analysis
List of apps,
files, URLs
accessed

3: Shared-user Identification

Corporate
Server or Desktop
WHO is doing WHAT
on our network???

Cool! Now I know.

Audit Reporting DB &
SIEM Log Collector

User
Alex

Video
Play!

Text Log
App1, App2

Sam the
Security Officer

11
Demo Links:
Live hosted demo: http://demo.observeit.com

YouTube demos:
English: http://www.youtube.com/watch?v=uSki27KvDk0&hd=1

Russian: http://www.youtube.com/watch?v=fzVhLfSb2nY&hd=1

LIVE DEMO
DEPLOYMENT SCENARIO OPTIONS
Standard Agent-based Deployment
•
•
•
•

Agent installed ObserveIT audit
Administrators access on each monitored machine

• Agent becomes active only when user session starts
• ASP.NET application in IIS
•
Data Storage
Mgmt Data capture is triggered by userand reporting movement, text typing,
Server receives video replay activity (mouse
• Primary interface forsession data from Agents
etc.). No recording takes place while user is idle
ASP.NET application in IIS • Microsoft SQL Server database
• Also used for configuration and admin tasks
• Communicates with Mgmt Server via HTTP on customizable port, with
CollectsWeb console includesthe Agents file-system limiting
• all data delivered by granular policy rules for storage)
(or optonal
optional SSL encryption
Analyzes and categorizes data,Stores all config data, metadata and screenshots
access to sensitive dataand sends to DB Server
• recorded info (customizable buffer size)
• Offline mode buffers
Communicates with Agents for config updates via standard TCP port 1433
• All connections
• Watchdog mechanism prevents tampering

ObserveIT
Agents

ObserveIT
Web Console
ObserveIT
Management
Server

Remote
Users

Database
Server

Metadata Logs
& Video Capture

Local
Login

Desktop

AD

Network
Mgmt

SIEM

BI

Open API and Data Integration
• Standards-based
• Simple integration

14
Gateway Jump-Server Deployment

Corporate Servers

SSH
PuTTY

(no agent installed)
MSTSC

Gateway
Server
Corporate Desktops

Internet

(no agent installed)

ObserveIT
Agent

Remote and local users

Corporate Servers
(no agent installed)

ObserveIT
Management Server

15
Hybrid Deployment

Corporate Servers

SSH
PuTTY

(no agent installed)
MSTSC

Gateway
Server
Corporate Desktops

Internet

(no agent installed)

ObserveIT
Agent

Remote and local users

Direct login
(not via gateway)

Sensitive production servers
(agent installed)

ObserveIT
Management Server

16
Gateway Jump-Server Deployment

Customer #1 Servers

SSH
PuTTY

(no agent installed)
MSTSC

Gateway
Server
Internet
Remote and local users

Customer #2 Servers
(no agent installed)

ObserveIT
Agent

Customer #3 Servers
(no agent installed)

ObserveIT
Management Server

17
Citrix Published Apps Deployment

Published Apps

Citrix
Server

Remote
Access

ObserveIT
Agent

ObserveIT
Management Server

18

Mais conteúdo relacionado

Mais de Andris Soroka

Digitala Era 2017 - ZAB “BULLET” - Ivo Krievs - Vai uz valsti attiecināmi cit...
Digitala Era 2017 - ZAB “BULLET” - Ivo Krievs - Vai uz valsti attiecināmi cit...Digitala Era 2017 - ZAB “BULLET” - Ivo Krievs - Vai uz valsti attiecināmi cit...
Digitala Era 2017 - ZAB “BULLET” - Ivo Krievs - Vai uz valsti attiecināmi cit...Andris Soroka
 
Digitala Era 2017 - LSPDSA - Arnis Puksts - Datu aizsardzības speciālists (DPO)
Digitala Era 2017 - LSPDSA - Arnis Puksts - Datu aizsardzības speciālists (DPO)Digitala Era 2017 - LSPDSA - Arnis Puksts - Datu aizsardzības speciālists (DPO)
Digitala Era 2017 - LSPDSA - Arnis Puksts - Datu aizsardzības speciālists (DPO)Andris Soroka
 
Digitala Era 2017 - IIZI - Lauris Kļaviņš - GDPR - Kādus izdevumus un riskus ...
Digitala Era 2017 - IIZI - Lauris Kļaviņš - GDPR - Kādus izdevumus un riskus ...Digitala Era 2017 - IIZI - Lauris Kļaviņš - GDPR - Kādus izdevumus un riskus ...
Digitala Era 2017 - IIZI - Lauris Kļaviņš - GDPR - Kādus izdevumus un riskus ...Andris Soroka
 
Digitala Era 2017 - E-Risinajumi - Māris Ruķers - Vai ar vienu datu aizsardzī...
Digitala Era 2017 - E-Risinajumi - Māris Ruķers - Vai ar vienu datu aizsardzī...Digitala Era 2017 - E-Risinajumi - Māris Ruķers - Vai ar vienu datu aizsardzī...
Digitala Era 2017 - E-Risinajumi - Māris Ruķers - Vai ar vienu datu aizsardzī...Andris Soroka
 
Digitala Era 2017 - Gints Puškundzis - Personas datu apstrādes līgumi
Digitala Era 2017 - Gints Puškundzis - Personas datu apstrādes līgumi Digitala Era 2017 - Gints Puškundzis - Personas datu apstrādes līgumi
Digitala Era 2017 - Gints Puškundzis - Personas datu apstrādes līgumi Andris Soroka
 
Digitala Era 2017 - DatuAizsardziba.LV - Agnese Boboviča - Datu aizsardzības ...
Digitala Era 2017 - DatuAizsardziba.LV - Agnese Boboviča - Datu aizsardzības ...Digitala Era 2017 - DatuAizsardziba.LV - Agnese Boboviča - Datu aizsardzības ...
Digitala Era 2017 - DatuAizsardziba.LV - Agnese Boboviča - Datu aizsardzības ...Andris Soroka
 
Digitala Era 2017 - NotAKey - Janis Graubins - Mobile technologies for single...
Digitala Era 2017 - NotAKey - Janis Graubins - Mobile technologies for single...Digitala Era 2017 - NotAKey - Janis Graubins - Mobile technologies for single...
Digitala Era 2017 - NotAKey - Janis Graubins - Mobile technologies for single...Andris Soroka
 
Digitala Era 2017 - Hermitage Solutions - Gatis Kaušs - Clearswift - Komunikā...
Digitala Era 2017 - Hermitage Solutions - Gatis Kaušs - Clearswift - Komunikā...Digitala Era 2017 - Hermitage Solutions - Gatis Kaušs - Clearswift - Komunikā...
Digitala Era 2017 - Hermitage Solutions - Gatis Kaušs - Clearswift - Komunikā...Andris Soroka
 
Digitala Era 2017 - Digital Mind - Leons Mednis - eDiscovery risinājums GDPR ...
Digitala Era 2017 - Digital Mind - Leons Mednis - eDiscovery risinājums GDPR ...Digitala Era 2017 - Digital Mind - Leons Mednis - eDiscovery risinājums GDPR ...
Digitala Era 2017 - Digital Mind - Leons Mednis - eDiscovery risinājums GDPR ...Andris Soroka
 
Digitala Era 2017 - ALSO - Artjoms Krūmiņš - Personas datu regulas (EU GDPR) ...
Digitala Era 2017 - ALSO - Artjoms Krūmiņš - Personas datu regulas (EU GDPR) ...Digitala Era 2017 - ALSO - Artjoms Krūmiņš - Personas datu regulas (EU GDPR) ...
Digitala Era 2017 - ALSO - Artjoms Krūmiņš - Personas datu regulas (EU GDPR) ...Andris Soroka
 
Digitala Era 2017 - ZAB Skopiņa & Azanda - Jūlija Terjuhana - Tiesības uz dat...
Digitala Era 2017 - ZAB Skopiņa & Azanda - Jūlija Terjuhana - Tiesības uz dat...Digitala Era 2017 - ZAB Skopiņa & Azanda - Jūlija Terjuhana - Tiesības uz dat...
Digitala Era 2017 - ZAB Skopiņa & Azanda - Jūlija Terjuhana - Tiesības uz dat...Andris Soroka
 
Digitala Era 2017 - IT Centrs - Agris Krusts - Latvijas iedzīvotāju digitālo ...
Digitala Era 2017 - IT Centrs - Agris Krusts - Latvijas iedzīvotāju digitālo ...Digitala Era 2017 - IT Centrs - Agris Krusts - Latvijas iedzīvotāju digitālo ...
Digitala Era 2017 - IT Centrs - Agris Krusts - Latvijas iedzīvotāju digitālo ...Andris Soroka
 
Digitala Era 2017 - DSS.LV - Arturs Filatovs - Datu Aizsardzības Tehnoloģiskā...
Digitala Era 2017 - DSS.LV - Arturs Filatovs - Datu Aizsardzības Tehnoloģiskā...Digitala Era 2017 - DSS.LV - Arturs Filatovs - Datu Aizsardzības Tehnoloģiskā...
Digitala Era 2017 - DSS.LV - Arturs Filatovs - Datu Aizsardzības Tehnoloģiskā...Andris Soroka
 
Digitala Era 2017 - DSS.LV - Arturs Filatovs - Mobilitāte un Personas Datu Dr...
Digitala Era 2017 - DSS.LV - Arturs Filatovs - Mobilitāte un Personas Datu Dr...Digitala Era 2017 - DSS.LV - Arturs Filatovs - Mobilitāte un Personas Datu Dr...
Digitala Era 2017 - DSS.LV - Arturs Filatovs - Mobilitāte un Personas Datu Dr...Andris Soroka
 
Digitala Era 2017 - DSS.LV - Andris Soroka - Personas datu regulas tehnoloģis...
Digitala Era 2017 - DSS.LV - Andris Soroka - Personas datu regulas tehnoloģis...Digitala Era 2017 - DSS.LV - Andris Soroka - Personas datu regulas tehnoloģis...
Digitala Era 2017 - DSS.LV - Andris Soroka - Personas datu regulas tehnoloģis...Andris Soroka
 
Zane Beļavska - LR MOD - Normatīvie akti kiberdrošībā - @ LTRK + DSS.LV = Hak...
Zane Beļavska - LR MOD - Normatīvie akti kiberdrošībā - @ LTRK + DSS.LV = Hak...Zane Beļavska - LR MOD - Normatīvie akti kiberdrošībā - @ LTRK + DSS.LV = Hak...
Zane Beļavska - LR MOD - Normatīvie akti kiberdrošībā - @ LTRK + DSS.LV = Hak...Andris Soroka
 
DSS.LV @ IBM and ALSO Tech Workshop in Riga, Latvia (May, 2016)
DSS.LV @ IBM and ALSO Tech Workshop in Riga, Latvia (May, 2016)DSS.LV @ IBM and ALSO Tech Workshop in Riga, Latvia (May, 2016)
DSS.LV @ IBM and ALSO Tech Workshop in Riga, Latvia (May, 2016)Andris Soroka
 
IBM QRadar versus MK noteikumi 2016
IBM QRadar versus MK noteikumi 2016IBM QRadar versus MK noteikumi 2016
IBM QRadar versus MK noteikumi 2016Andris Soroka
 
DSS @ IBM Business Connect 2016 - OUTTHINK. - 10 baušļi mobīlajai drošībai
DSS @ IBM Business Connect 2016 - OUTTHINK. - 10 baušļi mobīlajai drošībaiDSS @ IBM Business Connect 2016 - OUTTHINK. - 10 baušļi mobīlajai drošībai
DSS @ IBM Business Connect 2016 - OUTTHINK. - 10 baušļi mobīlajai drošībaiAndris Soroka
 
DSS.LV @ Dienas Biznesa, IBM un Exigen Latvija seminārā "Biznesa datu drošība"
DSS.LV @ Dienas Biznesa, IBM un Exigen Latvija seminārā "Biznesa datu drošība"DSS.LV @ Dienas Biznesa, IBM un Exigen Latvija seminārā "Biznesa datu drošība"
DSS.LV @ Dienas Biznesa, IBM un Exigen Latvija seminārā "Biznesa datu drošība"Andris Soroka
 

Mais de Andris Soroka (20)

Digitala Era 2017 - ZAB “BULLET” - Ivo Krievs - Vai uz valsti attiecināmi cit...
Digitala Era 2017 - ZAB “BULLET” - Ivo Krievs - Vai uz valsti attiecināmi cit...Digitala Era 2017 - ZAB “BULLET” - Ivo Krievs - Vai uz valsti attiecināmi cit...
Digitala Era 2017 - ZAB “BULLET” - Ivo Krievs - Vai uz valsti attiecināmi cit...
 
Digitala Era 2017 - LSPDSA - Arnis Puksts - Datu aizsardzības speciālists (DPO)
Digitala Era 2017 - LSPDSA - Arnis Puksts - Datu aizsardzības speciālists (DPO)Digitala Era 2017 - LSPDSA - Arnis Puksts - Datu aizsardzības speciālists (DPO)
Digitala Era 2017 - LSPDSA - Arnis Puksts - Datu aizsardzības speciālists (DPO)
 
Digitala Era 2017 - IIZI - Lauris Kļaviņš - GDPR - Kādus izdevumus un riskus ...
Digitala Era 2017 - IIZI - Lauris Kļaviņš - GDPR - Kādus izdevumus un riskus ...Digitala Era 2017 - IIZI - Lauris Kļaviņš - GDPR - Kādus izdevumus un riskus ...
Digitala Era 2017 - IIZI - Lauris Kļaviņš - GDPR - Kādus izdevumus un riskus ...
 
Digitala Era 2017 - E-Risinajumi - Māris Ruķers - Vai ar vienu datu aizsardzī...
Digitala Era 2017 - E-Risinajumi - Māris Ruķers - Vai ar vienu datu aizsardzī...Digitala Era 2017 - E-Risinajumi - Māris Ruķers - Vai ar vienu datu aizsardzī...
Digitala Era 2017 - E-Risinajumi - Māris Ruķers - Vai ar vienu datu aizsardzī...
 
Digitala Era 2017 - Gints Puškundzis - Personas datu apstrādes līgumi
Digitala Era 2017 - Gints Puškundzis - Personas datu apstrādes līgumi Digitala Era 2017 - Gints Puškundzis - Personas datu apstrādes līgumi
Digitala Era 2017 - Gints Puškundzis - Personas datu apstrādes līgumi
 
Digitala Era 2017 - DatuAizsardziba.LV - Agnese Boboviča - Datu aizsardzības ...
Digitala Era 2017 - DatuAizsardziba.LV - Agnese Boboviča - Datu aizsardzības ...Digitala Era 2017 - DatuAizsardziba.LV - Agnese Boboviča - Datu aizsardzības ...
Digitala Era 2017 - DatuAizsardziba.LV - Agnese Boboviča - Datu aizsardzības ...
 
Digitala Era 2017 - NotAKey - Janis Graubins - Mobile technologies for single...
Digitala Era 2017 - NotAKey - Janis Graubins - Mobile technologies for single...Digitala Era 2017 - NotAKey - Janis Graubins - Mobile technologies for single...
Digitala Era 2017 - NotAKey - Janis Graubins - Mobile technologies for single...
 
Digitala Era 2017 - Hermitage Solutions - Gatis Kaušs - Clearswift - Komunikā...
Digitala Era 2017 - Hermitage Solutions - Gatis Kaušs - Clearswift - Komunikā...Digitala Era 2017 - Hermitage Solutions - Gatis Kaušs - Clearswift - Komunikā...
Digitala Era 2017 - Hermitage Solutions - Gatis Kaušs - Clearswift - Komunikā...
 
Digitala Era 2017 - Digital Mind - Leons Mednis - eDiscovery risinājums GDPR ...
Digitala Era 2017 - Digital Mind - Leons Mednis - eDiscovery risinājums GDPR ...Digitala Era 2017 - Digital Mind - Leons Mednis - eDiscovery risinājums GDPR ...
Digitala Era 2017 - Digital Mind - Leons Mednis - eDiscovery risinājums GDPR ...
 
Digitala Era 2017 - ALSO - Artjoms Krūmiņš - Personas datu regulas (EU GDPR) ...
Digitala Era 2017 - ALSO - Artjoms Krūmiņš - Personas datu regulas (EU GDPR) ...Digitala Era 2017 - ALSO - Artjoms Krūmiņš - Personas datu regulas (EU GDPR) ...
Digitala Era 2017 - ALSO - Artjoms Krūmiņš - Personas datu regulas (EU GDPR) ...
 
Digitala Era 2017 - ZAB Skopiņa & Azanda - Jūlija Terjuhana - Tiesības uz dat...
Digitala Era 2017 - ZAB Skopiņa & Azanda - Jūlija Terjuhana - Tiesības uz dat...Digitala Era 2017 - ZAB Skopiņa & Azanda - Jūlija Terjuhana - Tiesības uz dat...
Digitala Era 2017 - ZAB Skopiņa & Azanda - Jūlija Terjuhana - Tiesības uz dat...
 
Digitala Era 2017 - IT Centrs - Agris Krusts - Latvijas iedzīvotāju digitālo ...
Digitala Era 2017 - IT Centrs - Agris Krusts - Latvijas iedzīvotāju digitālo ...Digitala Era 2017 - IT Centrs - Agris Krusts - Latvijas iedzīvotāju digitālo ...
Digitala Era 2017 - IT Centrs - Agris Krusts - Latvijas iedzīvotāju digitālo ...
 
Digitala Era 2017 - DSS.LV - Arturs Filatovs - Datu Aizsardzības Tehnoloģiskā...
Digitala Era 2017 - DSS.LV - Arturs Filatovs - Datu Aizsardzības Tehnoloģiskā...Digitala Era 2017 - DSS.LV - Arturs Filatovs - Datu Aizsardzības Tehnoloģiskā...
Digitala Era 2017 - DSS.LV - Arturs Filatovs - Datu Aizsardzības Tehnoloģiskā...
 
Digitala Era 2017 - DSS.LV - Arturs Filatovs - Mobilitāte un Personas Datu Dr...
Digitala Era 2017 - DSS.LV - Arturs Filatovs - Mobilitāte un Personas Datu Dr...Digitala Era 2017 - DSS.LV - Arturs Filatovs - Mobilitāte un Personas Datu Dr...
Digitala Era 2017 - DSS.LV - Arturs Filatovs - Mobilitāte un Personas Datu Dr...
 
Digitala Era 2017 - DSS.LV - Andris Soroka - Personas datu regulas tehnoloģis...
Digitala Era 2017 - DSS.LV - Andris Soroka - Personas datu regulas tehnoloģis...Digitala Era 2017 - DSS.LV - Andris Soroka - Personas datu regulas tehnoloģis...
Digitala Era 2017 - DSS.LV - Andris Soroka - Personas datu regulas tehnoloģis...
 
Zane Beļavska - LR MOD - Normatīvie akti kiberdrošībā - @ LTRK + DSS.LV = Hak...
Zane Beļavska - LR MOD - Normatīvie akti kiberdrošībā - @ LTRK + DSS.LV = Hak...Zane Beļavska - LR MOD - Normatīvie akti kiberdrošībā - @ LTRK + DSS.LV = Hak...
Zane Beļavska - LR MOD - Normatīvie akti kiberdrošībā - @ LTRK + DSS.LV = Hak...
 
DSS.LV @ IBM and ALSO Tech Workshop in Riga, Latvia (May, 2016)
DSS.LV @ IBM and ALSO Tech Workshop in Riga, Latvia (May, 2016)DSS.LV @ IBM and ALSO Tech Workshop in Riga, Latvia (May, 2016)
DSS.LV @ IBM and ALSO Tech Workshop in Riga, Latvia (May, 2016)
 
IBM QRadar versus MK noteikumi 2016
IBM QRadar versus MK noteikumi 2016IBM QRadar versus MK noteikumi 2016
IBM QRadar versus MK noteikumi 2016
 
DSS @ IBM Business Connect 2016 - OUTTHINK. - 10 baušļi mobīlajai drošībai
DSS @ IBM Business Connect 2016 - OUTTHINK. - 10 baušļi mobīlajai drošībaiDSS @ IBM Business Connect 2016 - OUTTHINK. - 10 baušļi mobīlajai drošībai
DSS @ IBM Business Connect 2016 - OUTTHINK. - 10 baušļi mobīlajai drošībai
 
DSS.LV @ Dienas Biznesa, IBM un Exigen Latvija seminārā "Biznesa datu drošība"
DSS.LV @ Dienas Biznesa, IBM un Exigen Latvija seminārā "Biznesa datu drošība"DSS.LV @ Dienas Biznesa, IBM un Exigen Latvija seminārā "Biznesa datu drošība"
DSS.LV @ Dienas Biznesa, IBM un Exigen Latvija seminārā "Biznesa datu drošība"
 

Último

Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DayH2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DaySri Ambati
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfRankYa
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteDianaGray10
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 

Último (20)

Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DayH2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdf
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test Suite
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 

DSS ITSEC 2013 Conference 07.11.2013 - ObserveIT - Monitoring everyone

  • 1. ObserveIT: User Activity Monitoring Mark Kreymer mark@observeit.com June, 2013 Copyright © 2011 ObserveIT. All rights reserved. All trademarks, trade names, service marks and logos referenced herein belong to their respective companies. This document is for informational purposes only. www.observeit.com
  • 2. ObserveIT Software that acts like a security camera on your servers!  Video camera: Recordings of all user activity    Summary of key actions: Alerts for problematic activity 2
  • 3. 700+ Enterprise Customers Healthcare / Pharma Financial Telco & Media Manufacturing Retail / Service Utilities / Logistics / Energy IT Services / Technology Government Gaming 3
  • 4. Worldwide Presence France CG61 S2IH BOUYGUES TELECOM Societe Generale Groupama Asset Management (GAM) Spain Banco Espirito Santo S.A. CECA (Confederación Española de Cajas de Ahorros) BBVA Caja Madrid Canada Bell Canada Quebec Loto Bellin Treasury Services Ltd. Toronto Hydro Transat A.T. Inc. Atlantic Lottery Corporation (ALC) UK Germany Norway Estonia UK Payments Administration Ltd Sanofi Aventis VTS Estonian Security BlackRock HSH Nordbank Police Board QinetiQ Boehringer Ingelheim GmbH Switzerland Vocalink UK AGRAVIS Raiffeisen AG BCN Friends Provident Deutsche Telekom AG Bank Vontobel AG Hyperion Insurance Group Schweizerische Bundesbahnen (SBB) LCH.Clearnet Ltd. Luxemburg Swiss Federal Railway BSkyB Sky Network Service TELINDUS Luxmeburge ZKB Xtrakter Ltd Corner Banca SA Opal Telecom Ltd Banca del Sempione Talk Talk Technology (Carphone CPWN) Liechtenstein Banca Euromobiliare Suisse BNP Paribas Real Estate Advisory (UK) LGT FInancial Services BancaStato VTB Capital plc Baillie Gifford & Co. Italy Heritage Group LTD Vodafone (Italy) ELECTRONIC'S TIME SRL Allianz SPA ING Lease Italia S.p.A. UBI Banca Sistemi&Servizi Xerox s.p.a. Poland Podkarpacki OddziaB Wojewódzkiego Narodowego Funduszu Zdrowia z siedzib w Rzeszowie Elektrotim S.A. Inteligo Financial Services S.A. Czech Republic Hungary Greece GE Money Bank Wiz z Air hol Croatia Slovenia Cyprus T-Mobile Croatia OTP Zavarovalnica Triglav d.d Raiffeisen banka d.d. SEM Ltd Slovakia Tatra Banka a.s. South Korea Japan Mitsubishi Information USA Trend Micro Inc. Shumway Capital Partners, LLC Spoken Communications University Health Systems of Eastern Carolina Casino Arizona CDW Dimension Data Americas (USA) CSX Technology PGE - Portland General Electric Cisco (Webex) St. Jude Medical UPS Disney IBM Newegg Spring Branch Independent School District Sony British Petrolum (BP) SUNY Downstate Washington University Western Governors University Kroll Ontrack BNP Paribas StrataCare, LLC. Societe Generale (USA) MFS Investment Management Fort McDowell Enterprises CHARLES SCHWAB & CO Aastra Cost Plus World Market (CPWM) Samsung Networks Korea Yonsei Hospital GS Caltex Defense Acquisition Program Administration China Taiwan Trinidad & Tobago Bolivia Turkey PETROTRIN Telecel S.A. TIGO Chile Nexus Argentina Nuevo Banco del Chaco S.A. Angola Banco Nacional de Angola Chad MIC Chad, Ltd. TIGO South Africa Derivco (PTY) Ltd. Ubank MultiChoice Africa (Pty) Ltd. Clicks Group Ltd. Truworths, South Africa Tanzania MIC Tanzania, Ltd. TIGO Turkcell ANADOLU SIGORTA Vakifbank Yasar Factoring T.C. Ziraat Bankas1 Israel Qatar Taiwan Railways Administration, MOTC Taiwan Accreditation Foundation (TAF) Taiwan Mobile Ministry of Education China Construction Bank China Mobile Group Guangdong Co. ShinseiBank Tesco China China Foreign Exchange Trade System National Interbank Funding Center The Hong Kong Jockey Club DMX India HDFC Bank Ltd. iYogi HCL Wipro Excellence Nessua QFC Regulatory Authority Yes Court of the Crown Prince (CPC) Leumi Bank Financial Centre Authority Harel Insurance Hapoalim Bank United Arab Emirates Ayalon Insurance First Gulf Bank Australia Pelephone Metito Overseas Ltd. Woodside Energy Ltd Comverse AHI Carrier Fzc Australian Stock Exchange Zim NetstarLogicalis Clal Insurance Bezeq Visa Coca Cola Orange First International Bank Bank Discount Ministry of Interior Philippines Asian Development Bank Singapore BT Frontline Siemens Medical Singapore Post Singapura Finance UOB Shimano 4
  • 5. Business challenges that ObserveIT addresses Remote Vendor Monitoring • Impact human behavior • Transparent SLA and billing • Eliminate ‘Finger pointing’ Compliance & Security Accountability Root Cause Analysis & Documentation • Reduce compliance costs for GETTING compliant and STAYING compliant • Satisfy PCI, HIPAA, SOX, ISO • Immediate root-cause answers • Document best-practices 5
  • 6. An Analogy Bank Branch Office Bank Computer Servers Companies invest in access control but once users gain access, there is little knowledge of who they are and what they do! (Even though 71% of data breaches involve privileged user credentials) They both hold money… …They both have Access Control… ...Here they also have security cameras… …Here, they don’t! 6
  • 7. Why? Because system logs are built by DEVELOPERS for DEBUG! Only 1% of data breaches are (and not by SECURITY ADMINS for SECURITY AUDIT) discovered by log analysis! (Even in large orgs with established SIEM processes, the number is still only 8%!) “ “ “ “ I don’t have this problem. I’ve got log analysis! The picture isn’t quite as rosy as you think. 7
  • 8. Can you tell what happened here? Replay Video Wouldn’t it be easier with a ‘Replay Video’ button? Video Replay shows exactly what happened 8
  • 9. And many commonly used apps don’t even have their own logs! • DESKTOP APPS DESKTOP APPS • • • • Firefox / Chrome / IE MS Excel / Word Outlook Skype REMOTE & VIRTUAL • Remote Desktop • VMware vSphere ADMIN TOOLS • • • • Registry Editor SQL Manager Toad Network Config TEXT EDITORS • vi • Notepad 9
  • 10. System Logs are like Fingerprints They show the results/outcome System Logs areof what took place like Fingerprints User Audit Logs are like Surveillance Recordings They show exactly what took place! “ “ Both are valid… …But the video log goes right to the point! 10
  • 11. Our Solution 1: Video Capture Video Session Recording ‘Admin‘ = Alex Logs on as ‘Administrator’ X X X IT Alex the Admin 2: Video Content Analysis List of apps, files, URLs accessed 3: Shared-user Identification Corporate Server or Desktop WHO is doing WHAT on our network??? Cool! Now I know. Audit Reporting DB & SIEM Log Collector User Alex Video Play! Text Log App1, App2 Sam the Security Officer 11
  • 12. Demo Links: Live hosted demo: http://demo.observeit.com YouTube demos: English: http://www.youtube.com/watch?v=uSki27KvDk0&hd=1 Russian: http://www.youtube.com/watch?v=fzVhLfSb2nY&hd=1 LIVE DEMO
  • 14. Standard Agent-based Deployment • • • • Agent installed ObserveIT audit Administrators access on each monitored machine • Agent becomes active only when user session starts • ASP.NET application in IIS • Data Storage Mgmt Data capture is triggered by userand reporting movement, text typing, Server receives video replay activity (mouse • Primary interface forsession data from Agents etc.). No recording takes place while user is idle ASP.NET application in IIS • Microsoft SQL Server database • Also used for configuration and admin tasks • Communicates with Mgmt Server via HTTP on customizable port, with CollectsWeb console includesthe Agents file-system limiting • all data delivered by granular policy rules for storage) (or optonal optional SSL encryption Analyzes and categorizes data,Stores all config data, metadata and screenshots access to sensitive dataand sends to DB Server • recorded info (customizable buffer size) • Offline mode buffers Communicates with Agents for config updates via standard TCP port 1433 • All connections • Watchdog mechanism prevents tampering ObserveIT Agents ObserveIT Web Console ObserveIT Management Server Remote Users Database Server Metadata Logs & Video Capture Local Login Desktop AD Network Mgmt SIEM BI Open API and Data Integration • Standards-based • Simple integration 14
  • 15. Gateway Jump-Server Deployment Corporate Servers SSH PuTTY (no agent installed) MSTSC Gateway Server Corporate Desktops Internet (no agent installed) ObserveIT Agent Remote and local users Corporate Servers (no agent installed) ObserveIT Management Server 15
  • 16. Hybrid Deployment Corporate Servers SSH PuTTY (no agent installed) MSTSC Gateway Server Corporate Desktops Internet (no agent installed) ObserveIT Agent Remote and local users Direct login (not via gateway) Sensitive production servers (agent installed) ObserveIT Management Server 16
  • 17. Gateway Jump-Server Deployment Customer #1 Servers SSH PuTTY (no agent installed) MSTSC Gateway Server Internet Remote and local users Customer #2 Servers (no agent installed) ObserveIT Agent Customer #3 Servers (no agent installed) ObserveIT Management Server 17
  • 18. Citrix Published Apps Deployment Published Apps Citrix Server Remote Access ObserveIT Agent ObserveIT Management Server 18