Difference between revisions of "Hardening Monitoring & Analysis"

From khika
Jump to navigation Jump to search
Line 23: Line 23:
  
 
[[File:Hard1.jpg|700px]]
 
[[File:Hard1.jpg|700px]]
 +
 +
 +
 +
[[Data Enrichment in KHIKA|Previous]]
 +
 +
The next section is about data age in KHIKA, online and offline storage and [[Data Archival in KHIKA|Data Archival]]

Revision as of 06:09, 12 June 2019

Introduction

Default configuration of most devices (viz. operation systems, databases, routers, switches, etc.) is not designed with security as primary focus which leaves them vulnerable to security threats. Hardening is the process of enhancing device security through a variety of means which results in a much more secure server operating environment. KHIKA provides hardening compliance reports which are precisely serve this purpose, to check devices for compliance against hardening policies.

KHIKA collects hardening compliance data from devices on a daily basis which is then evaluated against pre-defined policies.

The best defense against security attacks is to ensure server hardening policies are implemented and up to date, to minimize these loopholes. The resultant reports depict the hardening posture for the respective device wherein each policy along with its compliance status is rendered on KHIKA dashboards.

Business Process flow for Linux Hardening

Following sequence explains the data flow and business process for Hardening analysis and monitoring using KHIKA :

  1. Hardening related data, values are collected into KHIKA using commands/scripts which run on servers via the Ossec Agent to get the hardening data into KHIKA.
  2. For Windows, Linux, Network devices and Oracle DB the polling interval is once every 24 hours.
  3. KHIKA processes this data and generates report dashboards which mention policy-wise which servers are non compliant and what is their current state vis a vis the desired.
  4. This data is captured once in every 24 hours and dashboards are refreshed with current results.


Hardening Dashboard

Required Hardening Dashboard can be selected from the Dashboard list like other Dashboards


Hard1.jpg


Previous

The next section is about data age in KHIKA, online and offline storage and Data Archival