Oklahoma City using SIEM to crack down on hackers - and wayward employees

Oklahoma City is using technology that not only watches for signs of any hacker activity on its municipal government network, but monitors employee online behavior to assure no one's going out of bounds.

"We wanted to be able to respond to intrusions," says Tom Barnum, security engineer for Oklahoma City, about the main reason the city deployed the Prism Microsystems security information and event management (SIEM) product EventTracker about two years ago. But the city government is also finding it to be a way to follow what employees, including IT staff, do via their computers online and have city managers step in when need be.

BEST PRACTICES: SIEM deployment

The Prism SIEM client software "keeps track of all the events on the machine, log-in and log-out times, and it has the ability to track programs," Barnum says. SIEM has become a tool for gauging "employee malfeasance," that might mean anything from trying to access something they shouldn't or wasting time with unauthorized applications.

Oklahoma City has established procedures, some via automated alerts, where city managers can be immediately informed electronically about misbehavior. This spares the IT department from having to directly play the policing role.

SIEM can also keep track of whether certain records are changed. And on the IT administrative side, where only certain workers have access to machines like police computers, if someone gets dropped or added, an alert is sent out right away.

While the Prism SIEM can make many determinations on its own, the IT security staff still has to plow through raw data at times to interpret what's going on, Barnum says. For instance, new activity on the municipal network, such as when the city started a migration to Windows 7, will send up the "noise level" and require another round of SIEM "tuning".

Although it's a powerful security tool, there are some limitations with Prism's SIEM offering, according to Barnum. For one thing, it faces challenges monitoring over wireless networks due to bandwidth constraints. Also, "EventTracker is not geared toward high-speed searching," Barnum says. Some intensive searches into stored log and event data "can take a week" and although the latest version is an improvement, "it's still not a system getting rolling-fast searches."

Read more about wide area network in Network World's Wide Area Network section.

Join the PC World newsletter!

Error: Please check your email address.

Tags securityWindowsWindows 7softwareoperating systemsSIEM

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Ellen Messmer

Network World
Show Comments

Essentials

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

GGG Evaluation Team

Michael Hargreaves

Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Steph Mundell

LIFEBOOK UH574

The Fujitsu LifeBook UH574 allowed for great mobility without being obnoxiously heavy or clunky. Its twelve hours of battery life did not disappoint.

Andrew Mitsi

STYLISTIC Q702

The screen was particularly good. It is bright and visible from most angles, however heat is an issue, particularly around the Windows button on the front, and on the back where the battery housing is located.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?