Oklahoma City using SIEM to crack down on hackers - and wayward employees

Oklahoma City is using technology that not only watches for signs of any hacker activity on its municipal government network, but monitors employee online behavior to assure no one's going out of bounds.

"We wanted to be able to respond to intrusions," says Tom Barnum, security engineer for Oklahoma City, about the main reason the city deployed the Prism Microsystems security information and event management (SIEM) product EventTracker about two years ago. But the city government is also finding it to be a way to follow what employees, including IT staff, do via their computers online and have city managers step in when need be.

BEST PRACTICES: SIEM deployment

The Prism SIEM client software "keeps track of all the events on the machine, log-in and log-out times, and it has the ability to track programs," Barnum says. SIEM has become a tool for gauging "employee malfeasance," that might mean anything from trying to access something they shouldn't or wasting time with unauthorized applications.

Oklahoma City has established procedures, some via automated alerts, where city managers can be immediately informed electronically about misbehavior. This spares the IT department from having to directly play the policing role.

SIEM can also keep track of whether certain records are changed. And on the IT administrative side, where only certain workers have access to machines like police computers, if someone gets dropped or added, an alert is sent out right away.

While the Prism SIEM can make many determinations on its own, the IT security staff still has to plow through raw data at times to interpret what's going on, Barnum says. For instance, new activity on the municipal network, such as when the city started a migration to Windows 7, will send up the "noise level" and require another round of SIEM "tuning".

Although it's a powerful security tool, there are some limitations with Prism's SIEM offering, according to Barnum. For one thing, it faces challenges monitoring over wireless networks due to bandwidth constraints. Also, "EventTracker is not geared toward high-speed searching," Barnum says. Some intensive searches into stored log and event data "can take a week" and although the latest version is an improvement, "it's still not a system getting rolling-fast searches."

Read more about wide area network in Network World's Wide Area Network section.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags SIEMoperating systemssoftwareWindowsWindows 7

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Ellen Messmer

Network World
Show Comments

Cool Tech

Toys for Boys

Family Friendly

Stocking Stuffer

SmartLens - Clip on Phone Camera Lens Set of 3

Learn more >

Christmas Gift Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Cathy Giles

Brother MFC-L8900CDW

The Brother MFC-L8900CDW is an absolute stand out. I struggle to fault it.

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?