Logging and Monitoring

Recent resources tagged with Logging and Monitoring.

Minimize Exposure Panel: Correlating Identities Across the Enterprise

Added by the EDUCAUSE Librarian
Title:Minimize Exposure Panel: Correlating Identities Across the Enterprise (ID: CAMP08103)
Author(s):Thomas J. Barton (University of Chicago), Michael Conlon (University of Florida), Jens Haeusser (The University of British Columbia), and Mark Berman (Williams College)
Origin:Contributed by EDUCAUSE Grant Programs (CAMP) (02/13/2008)
Type:Presentations/Speeches
Abstract:

What are the benefits and issues with correlating identities across the enterprise? What are the issues relating to cross walking and characteristics of identifiers? What strategies are there for getting the most out of logging? It’s important to know if an identifier has been reassigned, for instance, when using it for access to restricted spaces. Are there new institutional processes we should consider, such as logging in to register your IP address and binding an IP with a user? This session will explore these questions and offer a set of common requirements.

View this resource:

Architecture for 24 x 7 Application Delivery: Clustering, Failing Over, Logging, and Beyond

Added by the EDUCAUSE Librarian
Title:Architecture for 24 x 7 Application Delivery: Clustering, Failing Over, Logging, and Beyond (ID: EDU07132)
Author(s):Katya Sadovsky (University of California, Irvine), Marina Arseniev (University of California, Irvine), and Jason Lin (University of California, Irvine)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

Designing and implementing a network, server, and application architecture for 24 x 7 Web application delivery is a must in today's demanding business environment. This presentation will cover the planning, complexities to address, and necessary steps to achieve reliable delivery of campus-wide financial, human resources, and student applications.

View this resource:

Are universities protecting students from the RIAA?

Added by the EDUCAUSE Librarian
Title:Are universities protecting students from the RIAA? (ID: CSD5200)
Author(s):Declan McCullagh (CNET News.com)
Origin:Contributed by Organizations or Campuses (10/18/2007)
Type:Articles, Papers, and Reports
Abstract:

The author suggests that schools may be purposely not retaining IP logging data on students to protect them from copyright infringement lawsuits.

View this resource:

Intrusion Detection

Added by the EDUCAUSE Librarian
Title:Intrusion Detection (ID: EPS170)
Author(s):Timothy Wright (University of Notre Dame)
Origin:Contributed by Organizations or Campuses (2003)
Type:Effective Practices
Abstract:

Intrusion detection was a high priority for the Notre Dame Information Security Department when it was created about a year and a half ago. The university's Responsible Use Policy contains a clause that codifies the university's right to "inspect and examine any Notre Dame owned or operated communications system, computing resource, and/or files or information contained therein at any time," enabling us to implement an intrusion detection system (IDS) with no resistance.

We evaluated the top commercial and open source network intrusion detection system (NIDS) products, including Snort. Ultimately, we found that the best fit was multiple Snort sensors managed using SnortCenter, with MySQL for data storage and ACID for display and reporting.

View this resource:

Monitoring and Network Forensics at the University of Chicago

Added by the EDUCAUSE Librarian
Title:Monitoring and Network Forensics at the University of Chicago (ID: EPS175)
Author(s):E. Larry Lidz (University of Chicago)
Origin:Contributed by Organizations or Campuses (2003)
Type:Effective Practices
Abstract:

Overview of the University Network The University of Chicago's network has approximately 15,000 network devices on it, spanning across about a thousand switches. The network infrastructure is a 100 MB per second switched infrastructure with a gigabit backbone. For off campus connectivity, we currently have 155 MB/sec Internet2 connectivity, and two 40 MB/sec commodity links. We have a handful of T1 and T3 connections which connect into our campus backbone for affiliated organizations or sites away from the main campus network. Evolution of Network Forensics at the University We have been running various network forensic tools since around 1995. We started with TAMU NetLogger logging traffic on the subnet on which we had our main e-mail, Web, and other important servers. NetLogger relied on a non-switched network for logging. As the University's network swapped over to a switched network we stopped using NetLogger. Around 1998, as the university started the Network Security Center, we started searching for a way to have similar network audit logs, except to monitor traffic across the university's gateway instead of or in addition to monitoring the main servers.

View this resource:

Security Log Analysis for Windows NT/2000/XP/2003

Added by the EDUCAUSE Librarian
Title:Security Log Analysis for Windows NT/2000/XP/2003 (ID: EPS176)
Author(s):Kenneth J. Hoover (Yale University)
Origin:Contributed by Organizations or Campuses (2003)
Type:Effective Practices
Abstract:

Windows NT-derived systems are able to record many kinds of information on user authentication. The logs generated are very detailed but difficult to analyze with the tools provided, which cannot summarize or report on the information that the log contains (other than a primitive filtering function). I wrote a Perl script, called logger.pl, that can read the security log from one or more Windows machines and summarize the information it contains to produce a report of what it finds, detailing the types of authentications that occurred, which usernames and client machines were involved, and the result. The output can be e-mailed to a given user (with PGP encryption available if PGP is installed on the host system), written to a file, or simply displayed on the screen. This script is very useful for many purposes, ranging from finding what systems a particular user has "touched" to summarizing authentication activity over a large number of systems. A recently added function generates a CSV file when multiple systems are scanned that can be imported and analyzed to produce, for example, a 3D graph of authentication activity on a user-to-machine basis.

View this resource:

Open Source Security Tools at Maricopa Community Colleges

Added by the EDUCAUSE Librarian
Title:Open Source Security Tools at Maricopa Community Colleges (ID: EPS193)
Author(s):Carol Myers (Paradise Valley Community College)
Origin:Contributed by Organizations or Campuses (2004)
Type:Effective Practices
Abstract:

The Maricopa Community Colleges consist of 10 colleges, two skill centers, and many college satellite centers, including classes being held at the Arizona state prison. More than 200,000 students are enrolled, supported by approximately 11,000 employees. This translates to roughly 25,000 network hosts. Maricopa has a decentralized administration, with each college having a president and a full complement of deans. The district office administration handles core, centralized, administrative operations such as human resources and financials. The colleges have diverse missions, from purely occupational to largely academic colleges. One college is solely distance learning.

View this resource:

Network Monitoring with Nagios

Added by the EDUCAUSE Librarian
Title:Network Monitoring with Nagios (ID: SEC07094)
Author(s):Matthew Gracie (Canisius College)
Origin:Presented at Security Professionals Conference (04/11/2007)
Type:Presentations/Speeches
Abstract:Nagios is a freely available open source network and host monitoring tool. This presentation will discuss using Nagios in an academic environment to monitor servers, detect network problems, and alert administrators to problems before the user population is affected.
View this resource:

Border Patrol: Access Denied!

Added by the EDUCAUSE Librarian
Title:Border Patrol: Access Denied! (ID: MWR07088)
Author(s):Dan Rousseve (University of Notre Dame), Robert M. Winding (University of Notre Dame), and Robert Riley (University of Notre Dame)
Origin:Presented at Midwest Regional Conferences (03/14/2007)
Type:Presentations/Speeches
Abstract:The University of Notre Dame has recently changed its network border policy to deny most unsolicited network traffic from the Internet. A small set of services like the Web, secure shell, VPN, and so forth are allowed in, but all others are denied by default.
View this resource:

Centralizing and Analyzing Security Events: Deploying Security Information Management Systems

Added by the EDUCAUSE Librarian
Title:Centralizing and Analyzing Security Events: Deploying Security Information Management Systems (ID: MAC07041)
Author(s):Lynn Ray (Towson University)
Origin:Presented at Mid-Atlantic Regional Conferences (01/18/2007)
Type:Presentations/Speeches
Abstract:Attacks on computer resources are more complex. It is increasingly difficult to quickly and effectively collect, analyze, and respond to security events. This presentation will demonstrate the use of security information management systems and offer an improved means to identify and respond to security threats.
View this resource: