{"id":15638,"date":"2020-07-20T12:43:28","date_gmt":"2020-07-20T08:13:28","guid":{"rendered":"http:\/\/payampardaz.com\/en\/?p=15638"},"modified":"2020-07-25T14:26:47","modified_gmt":"2020-07-25T09:56:47","slug":"ravin","status":"publish","type":"post","link":"https:\/\/payampardaz.com\/en\/ravin\/","title":{"rendered":"Ravin SIEM"},"content":{"rendered":"<h3><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full wp-image-15556\" src=\"http:\/\/payampardaz.com\/wp-content\/uploads\/2018\/11\/info-Ravin.0.0.png\" alt=\"\" width=\"426\" height=\"413\" \/><\/h3>\n<h2>Introduction to Ravin<\/h2>\n<p><strong>Ravin<\/strong><\/p>\n<p>Today, in any organization millions of events and alerts are generated by software, hardware, network and security devices daily. \u00a0Big amount of data, variety, different format and languages used in these events, makes it hard and costive to be identified, assessed and analyzed by human and may cause faults and mistakes or even be impossible in some situations.<\/p>\n<p>Ravin Incident and Event Management Service, makes it possible to monitor all events and alerts in organization\u2019s network continuously. All the alerts and events are collected and beside maintenance and long-term recovery, it has the ability to be monitored and analyzed continuously and immediately in order to detect the main cause of security events and response systematically.<\/p>\n<p>One of the most important option in Ravin SIEM is its usage in organization\u2019s security operation center (SOC). SOC shows up the state of network security and current flows with continuous monitoring (365*24).<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Options and features<\/strong><\/p>\n<ul>\n<li>Using in organization\u2019s security operation center (SOC)<\/li>\n<li>Reduce the cost of collecting, identifying and analyzing alerts and events in different part of the organization network<\/li>\n<li>Detect cyber-attacks and malwares and suspicious behaviors<\/li>\n<li>Immediate security incident detection and network behavioral analyzes<\/li>\n<li>Reduce the incident response time.<\/li>\n<li>Generate statistical reports from security events, categories and priorities<\/li>\n<li>Represents dashboard from immediate events and security incidents monitoring<\/li>\n<li>Analyze and monitoring events and security incidents at any time<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>Ravin SIEM components<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"222\"><img decoding=\"async\" class=\" wp-image-15786 aligncenter\" src=\"http:\/\/payampardaz.com\/en\/wp-content\/uploads\/sites\/2\/2020\/07\/sim.png\" alt=\"\" width=\"168\" height=\"105\" \/><\/td>\n<td width=\"379\"><strong>Ravin SIEM<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>Ravin is presented in different models for different hardwires according to event rate (EPS) and alert saving volume<\/p>\n<p><strong>\u00a0<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"222\"><strong> <img decoding=\"async\" class=\" wp-image-15783 aligncenter\" src=\"http:\/\/payampardaz.com\/en\/wp-content\/uploads\/sites\/2\/2020\/07\/ntlm.png\" alt=\"\" width=\"183\" height=\"107\" \/><\/strong><\/p>\n<p><strong>\u00a0<\/strong><\/td>\n<td width=\"379\"><strong>Ravin<\/strong> <strong>NTLM<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>This type is commonly deployed out of line in organization network. Different flows are exported and analyzed and security alerts are sent to managers. The analyze result can also be sent to Ravin SIEM.on the other hand this service is a sensor for Ravin SIEM<\/p>\n<p><strong>\u00a0<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"222\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-15784 aligncenter\" src=\"http:\/\/payampardaz.com\/en\/wp-content\/uploads\/sites\/2\/2020\/07\/ngids-150x150-1.png\" alt=\"\" width=\"104\" height=\"104\" \/><\/td>\n<td width=\"379\"><strong>Ravin<\/strong> <strong>NGIDS<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>This type is commonly deployed out of line in organization network. traffic contents are assessed and analyzed with the purpose of detecting security and destructive events and the result is sent to Ravin SIEM. This service is categorized as Ravin SIEM network layer sensor<\/p>\n<p><strong>\u00a0<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"222\"><strong> <img loading=\"lazy\" decoding=\"async\" class=\"wp-image-15785 aligncenter\" src=\"http:\/\/payampardaz.com\/en\/wp-content\/uploads\/sites\/2\/2020\/07\/edr.png\" alt=\"\" width=\"115\" height=\"106\" \/><\/strong><\/td>\n<td width=\"379\"><strong>Ravin EDR<\/strong><\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p>This type is installed as a software agent in network hosts. Agents export risky security behaviors from hosts and sends to central Ravin service to be analyzed and correlated with other network events. This service is categorized as Ravin host layer sensor<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>\u00a0<\/strong><\/p>\n<h2>Properties and Features<\/h2>\n<div align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\" colspan=\"2\"><strong>Network Intrusion Detection System<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"729\"><strong>Description<\/strong><\/td>\n<td style=\"text-align: center;\" width=\"187\">Features<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"729\">Up to 10Gbe<\/td>\n<td style=\"text-align: center;\" width=\"187\"><span dir=\"RTL\">Throughput <\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"729\">Up to 5 million concurrent sessions without packet loss<\/td>\n<td style=\"text-align: center;\" width=\"187\"><span dir=\"LTR\">Concurrent sessions<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"729\"><span dir=\"LTR\">Detects new and unknown attacks using anomaly detection methods based on learning<\/span><\/td>\n<td style=\"text-align: center;\" width=\"187\"><span dir=\"LTR\">Behavioral anomaly detection<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"729\"><span dir=\"LTR\">It has more than 18000 predefined attack signatures that can be updated continuously. This set contains different types of attacks such as scan, gain access, data manipulation, propagation, activity of malwares and denial of services.<\/span><\/td>\n<td style=\"text-align: center;\" width=\"187\"><span dir=\"LTR\">comprehensive set of attack signatures<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"729\">Web based graphical user interface<\/td>\n<td style=\"text-align: center;\" width=\"187\">GUI<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"text-align: center;\" align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td colspan=\"2\"><strong>Network traffic analysis sensor<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"735\"><strong>Description<\/strong><\/td>\n<td width=\"181\">Features<\/td>\n<\/tr>\n<tr>\n<td width=\"735\"><span dir=\"LTR\">application-layer detecting of more than 170 protocols, regardless of the port being used. This means that it is possible to both detect known protocols on non-standard ports (e.g. detect http on ports other than 80), and also the opposite (e.g. detect Skype traffic on port 80). This is because nowadays the concept of port=application no longer holds.<\/span><\/td>\n<td width=\"181\"><span dir=\"LTR\">Auto detect application-layer protocols <\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"735\"><span dir=\"LTR\">defines charts of packet rate, flow rate and volume usage in various time periods for different application layer protocols and add them to dashboards.<\/span><\/td>\n<td width=\"181\"><span dir=\"LTR\">Network traffic monitoring<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"735\"><span dir=\"LTR\">Receives and processes netflow reports<\/span><\/td>\n<td width=\"181\"><span dir=\"LTR\">Support netflow<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"735\"><span dir=\"LTR\">analyzes the traffic flow information and extracts new attack evidences. It learn behavior of services and users and detect abnormal manners.<\/span><\/td>\n<td width=\"181\"><span dir=\"LTR\">Traffic flow analysis<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"735\">Up to 10Gbe<\/td>\n<td width=\"181\"><span dir=\"LTR\">Throughput<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"735\"><span dir=\"LTR\">Detect malicious behaviors of attackers and automative malwares by comply network traffic flow with security policies. Administrators cloud define arbitrary rules per each security policy.<\/span><\/td>\n<td width=\"181\"><span dir=\"LTR\">Compliance Checking<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"735\"><span dir=\"LTR\">Signature based sensors problem is the lack of predefined signatures existance for detecting Zero-day attacks and malwares. Most of this attacks could cause effect on the network traffic flows.Analyzing these effects as the evidences of malicious activities, helps detecting zero-day attacks.<\/span><\/td>\n<td width=\"181\"><span dir=\"LTR\">Detect Zero-day attacks<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"text-align: center;\" align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td colspan=\"2\"><strong>Log collector<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"729\">Description<\/td>\n<td width=\"187\">Features<\/td>\n<\/tr>\n<tr>\n<td width=\"729\"><span dir=\"LTR\">Supports adding new organization\u2019s applications to receive their logs.<\/span><\/td>\n<td width=\"187\"><span dir=\"LTR\">Customizable for supporting various sensors.<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"729\"><span dir=\"LTR\">To be able to process Up to 20 thousands event per second on one appliance and scalable for higher rates.<\/span><\/td>\n<td width=\"187\"><span dir=\"LTR\">Throuput<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"729\"><span dir=\"LTR\">Unlimited sensor numbers<\/span><\/td>\n<td width=\"187\"><span dir=\"LTR\">Number of supported Sensors<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"729\"><span dir=\"LTR\">it is possible to define arbitrary filters for eliminating unusable logs or preventing entrance of some logs according to organization security policies.<\/span><\/td>\n<td width=\"187\"><span dir=\"LTR\">Event filters<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"729\"><span dir=\"LTR\">For reducing required bandwidth for transmitting logs through network from log collector to log manager, the log is compressed by 10:1 rate.<\/span><\/td>\n<td width=\"187\"><span dir=\"LTR\">Compression rate<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"729\"><span dir=\"LTR\">The security of the data is fulfiled by providing confidentiality and integrity of connections between modules.<\/span><\/td>\n<td width=\"187\"><span dir=\"LTR\">Secure transmit<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"729\">useing a cache for retaining received logs temporarily to prevent data loss in network disconnection.<\/td>\n<td width=\"187\"><span dir=\"LTR\">Reliable transmit <\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"text-align: center;\" align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td colspan=\"2\"><strong>Log management and Archive<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"711\"><strong>Description<\/strong><\/td>\n<td width=\"205\"><strong>Feature<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"711\"><span dir=\"LTR\">Receive and store up to 50,000 EPS<\/span><\/td>\n<td width=\"205\"><span dir=\"LTR\">Event Per Second <\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"711\"><span dir=\"LTR\">Depends on storage resource volume, retention of logs is possible for three, six and 12 months.<\/span><\/td>\n<td width=\"205\"><span dir=\"LTR\">Long Retention period<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"711\"><span dir=\"LTR\">Encrypts stored data in archive to prevent unauthorized access to data.<\/span><\/td>\n<td width=\"205\"><span dir=\"LTR\">Data encryption<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"711\"><span dir=\"LTR\">Compress raw and normalized logs by at least 10:1 rate.<\/span><\/td>\n<td width=\"205\"><span dir=\"LTR\">Compression<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"711\"><span dir=\"LTR\">IDMEF and IODEF formats are used to exchange message of events and incidents between security operation center components.<\/span><\/td>\n<td width=\"205\"><span dir=\"LTR\">Message Exchange Format<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"711\"><span dir=\"LTR\">For analysts of security operations center, facilities has been provided for searching and real-time retrieval of archived data based on various parameters.<\/span><\/td>\n<td width=\"205\"><span dir=\"LTR\">Realtime Data Retrieval<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"711\"><span dir=\"LTR\">Supports the storing of data for long term archive on a external storage such as SAN and NAS.<\/span><\/td>\n<td width=\"205\"><span dir=\"LTR\">External Storage<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"text-align: center;\" align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td colspan=\"2\"><strong>Correlation &amp; Response Engine<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><strong>Description<\/strong><\/td>\n<td width=\"211\">Feature<\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">Upon completion of the attacks symptoms, the incident will be reported to stop the progress of the attack.<\/span><\/td>\n<td width=\"211\">Realtime Analysis<\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">Some attacks create the necessary conditions for achieving desired goal over long periods of time. For proactiving detection of their stages, different stages of the attack is related and as a result, the final goal of the attacker will be understood. <\/span><\/td>\n<td width=\"211\">Multisage correlation<\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">In order to complete symptoms of the reported incidents and reduce false positive alarms, logs of network services and devices is analyzed and correlated with alerts of security softwares and devices.<\/span><\/td>\n<td width=\"211\">Cross-Device Correlation<\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">Detect and eliminate false positive alerts if corresponding vulnerabilities is not exist in attack targets.<\/span><\/td>\n<td width=\"211\">verification based on assets vulnerabilities<\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">the correlation engine does not miss attacks while reduces very high percent of reported events.<\/span><\/td>\n<td width=\"211\"><span dir=\"LTR\">Efficient correlation engine<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">Generalized correlation rules is selected and existed in the system. These predefined rules can be customized for organization situations. In addition, analysts of security operation center can inject special purpose correlation rules to the correlation engine.<\/span><\/td>\n<td width=\"211\"><span dir=\"LTR\">Predefined and customizable correlation rules<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">Detect abnormal events by statistical analysis of log producted by profiles of assets.<\/span><\/td>\n<td width=\"211\"><span dir=\"LTR\">behavioral abnormal analysis<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"705\">Unlimited<\/td>\n<td valign=\"top\" width=\"211\"><span dir=\"LTR\">The number of supported rules<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">Up to 5000 EPS for an appliance and more throughputs can also be achieved by replicating multiple of them.<\/span><\/td>\n<td width=\"211\"><span dir=\"LTR\">Event per second throughput<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">At the end of event analysis, attack graph will be displayed for better visually understanding of incident.<\/span><\/td>\n<td width=\"211\"><span dir=\"LTR\">Visual attack graph<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">uses central knowledge management engine to handle processes of creating and updating of knowledge and guarantees integrity of knowledge. knowledge base contains information about security policies and priorities of organization, vulnerabilities of assets and etc.<\/span><\/td>\n<td width=\"211\"><span dir=\"LTR\">Integrated knowledge base<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">In addition to integrated ticketing system for task tracking, neccessary automatic instruments are implemented based on a standard incident handling process. This feature is not presented in common SIEM products.<\/span><\/td>\n<td width=\"211\"><span dir=\"LTR\">Incident handling process<\/span><\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"705\"><span dir=\"LTR\">supports interaction with CERT, NOS and forensics teams <\/span><\/td>\n<td valign=\"top\" width=\"211\"><span dir=\"LTR\">interaction with organization teams<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">For every detected incident, a useful guideline is proposed. This guideline describes how to response to incidents and also presents operational instructions for denying a malicious traffic or removing a malware and etc and the SOC analysts could modify response guidelines or add new special cases to them. This feature is not presented in common SIEM products.<\/span><\/td>\n<td width=\"211\"><span dir=\"LTR\">incident handling guidelines<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"text-align: center;\" align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td colspan=\"2\"><strong>Correlation &amp; Response Engine<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><strong>Description<\/strong><\/td>\n<td width=\"211\">Feature<\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">Upon completion of the attacks symptoms, the incident will be reported to stop the progress of the attack.<\/span><\/td>\n<td width=\"211\">Realtime Analysis<\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">Some attacks create the necessary conditions for achieving desired goal over long periods of time. For proactiving detection of their stages, different stages of the attack is related and as a result, the final goal of the attacker will be understood. <\/span><\/td>\n<td width=\"211\">Multisage correlation<\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">In order to complete symptoms of the reported incidents and reduce false positive alarms, logs of network services and devices is analyzed and correlated with alerts of security softwares and devices.<\/span><\/td>\n<td width=\"211\">Cross-Device Correlation<\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">Detect and eliminate false positive alerts if corresponding vulnerabilities is not exist in attack targets.<\/span><\/td>\n<td width=\"211\">verification based on assets vulnerabilities<\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">the correlation engine does not miss attacks while reduces very high percent of reported events.<\/span><\/td>\n<td width=\"211\"><span dir=\"LTR\">Efficient correlation engine<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">Generalized correlation rules is selected and existed in the system. These predefined rules can be customized for organization situations. In addition, analysts of security operation center can inject special purpose correlation rules to the correlation engine.<\/span><\/td>\n<td width=\"211\"><span dir=\"LTR\">Predefined and customizable correlation rules<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">Detect abnormal events by statistical analysis of log producted by profiles of assets.<\/span><\/td>\n<td width=\"211\"><span dir=\"LTR\">behavioral abnormal analysis<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"705\">Unlimited<\/td>\n<td valign=\"top\" width=\"211\"><span dir=\"LTR\">The number of supported rules<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">Up to 5000 EPS for an appliance and more throughputs can also be achieved by replicating multiple of them.<\/span><\/td>\n<td width=\"211\"><span dir=\"LTR\">Event per second throughput<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">At the end of event analysis, attack graph will be displayed for better visually understanding of incident.<\/span><\/td>\n<td width=\"211\"><span dir=\"LTR\">Visual attack graph<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">uses central knowledge management engine to handle processes of creating and updating of knowledge and guarantees integrity of knowledge. knowledge base contains information about security policies and priorities of organization, vulnerabilities of assets and etc.<\/span><\/td>\n<td width=\"211\"><span dir=\"LTR\">Integrated knowledge base<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">In addition to integrated ticketing system for task tracking, neccessary automatic instruments are implemented based on a standard incident handling process. This feature is not presented in common SIEM products.<\/span><\/td>\n<td width=\"211\"><span dir=\"LTR\">Incident handling process<\/span><\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"705\"><span dir=\"LTR\">supports interaction with CERT, NOS and forensics teams <\/span><\/td>\n<td valign=\"top\" width=\"211\"><span dir=\"LTR\">interaction with organization teams<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"705\"><span dir=\"LTR\">For every detected incident, a useful guideline is proposed. This guideline describes how to response to incidents and also presents operational instructions for denying a malicious traffic or removing a malware and etc and the SOC analysts could modify response guidelines or add new special cases to them. This feature is not presented in common SIEM products.<\/span><\/td>\n<td width=\"211\"><span dir=\"LTR\">incident handling guidelines<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"text-align: center;\" align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td colspan=\"2\"><strong>GUI<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"741\"><strong>Description<\/strong><\/td>\n<td width=\"175\">Feature<\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"741\">Every users can define customized dashboards designed by arbitrary charts of various security events and reports.<\/td>\n<td width=\"175\"><span dir=\"LTR\">Security dashboards<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"741\"><span dir=\"LTR\">Web-based graphical user interface features is provided to manage, configure, search and follow-up process for identifing, analying and handling the incidents.<\/span><\/td>\n<td width=\"175\">GUI<\/td>\n<\/tr>\n<tr>\n<td width=\"741\">GUI shows activity status of the registered sensors.<\/td>\n<td width=\"175\">Sensor monitor<\/td>\n<\/tr>\n<tr>\n<td width=\"741\"><span dir=\"LTR\">The system has many predefined useful reports. Each user can define arbitrary reports. The defined reports are generated at scheduled times in pdf, html and exel formats.<\/span><\/td>\n<td width=\"175\">Various reports<\/td>\n<\/tr>\n<tr>\n<td width=\"741\"><span dir=\"LTR\">Each user in SOC teams is possible to manage accessibility of various product components such as configuring, monitoring and incident handling.<\/span><\/td>\n<td width=\"175\"><span dir=\"LTR\">User management<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"741\"><span dir=\"LTR\">Once a task is assigned to a user, he will be notified via email.<\/span><\/td>\n<td width=\"175\"><span dir=\"LTR\">Email Notification<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"741\"><span dir=\"LTR\">The system contains asset discovery and vulnerability assessment tools, for discovering assets and theirs vulnerabilities automatically and adding assets information to knowledge base. In addition it can connect to an external asset discovery and vulnerability assessment tool if exists any in the organization.<\/span><\/td>\n<td width=\"175\"><span dir=\"LTR\">Asset discovery and vulnerability assessment<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"text-align: center;\" align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td colspan=\"2\"><strong>Device Management<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"741\"><strong>Description<\/strong><\/td>\n<td width=\"175\">Feature<\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"741\"><span dir=\"LTR\">Send command to active network devices to prevent from attacks by block malicious traffic, disable users and kill processes and etc.<\/span><\/td>\n<td width=\"175\"><span dir=\"LTR\">Automatic commander<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"741\"><span dir=\"LTR\">Administrators could define arbitrary actions by create a manual script and use it for reponse to attacks.<\/span><\/td>\n<td width=\"175\">Custom script<\/td>\n<\/tr>\n<tr>\n<td width=\"741\"><span dir=\"LTR\">It support different devices and protocols to send commands:<\/span><\/p>\n<ul>\n<li>Network devices operating systems<\/li>\n<li>Unified threat managemtn systems<\/li>\n<li>Network layer and application firewalls<\/li>\n<li>SFTP<\/li>\n<li>Printers<\/li>\n<li>Alarm notification systems<\/li>\n<li>Operating systems windows, linux, ..<\/li>\n<li>SSH, Telnet<\/li>\n<\/ul>\n<\/td>\n<td width=\"175\">Supported Devices<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td colspan=\"2\"><strong>Support Services<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"765\"><strong>Description<\/strong><\/td>\n<td style=\"text-align: center;\" width=\"151\"><strong>Feature<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"765\">support (24*7) relevant to SLA<\/td>\n<td style=\"text-align: center;\" width=\"151\">support 24*7<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"765\">Ticketing system for following-up customers requests.<\/td>\n<td style=\"text-align: center;\" width=\"151\">Ticketing system<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"765\"><span dir=\"LTR\">User guide for the system outputs such as detailed information of attacks and security incidents is given to people working in Security Operations Center enabling to effectively analysis events.<\/span><\/td>\n<td style=\"text-align: center;\" width=\"151\">User manual<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" valign=\"top\" width=\"765\"><span dir=\"LTR\">Training for personnel of security operations center will be achieved. Therefore, The trained staff can work with the system autonomously.<\/span><\/td>\n<td style=\"text-align: center;\" width=\"151\">Training<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"765\"><span dir=\"LTR\">Updating the knowledge of detecting attacks is fully supported. In addition, special-purpose correlation rules to suit the requirements and policies of the organization in accordance relevant to SLA is also supported.<\/span><\/td>\n<td style=\"text-align: center;\" width=\"151\">Support of knowledge<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h2>Models<\/h2>\n<p><strong>Ravin SIEM Models<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-15793 size-full\" src=\"http:\/\/payampardaz.com\/en\/wp-content\/uploads\/sites\/2\/2020\/07\/ravin-siem-models1.png\" alt=\"\" width=\"595\" height=\"181\" srcset=\"https:\/\/payampardaz.com\/en\/wp-content\/uploads\/sites\/2\/2020\/07\/ravin-siem-models1.png 595w, https:\/\/payampardaz.com\/en\/wp-content\/uploads\/sites\/2\/2020\/07\/ravin-siem-models1-300x91.png 300w\" sizes=\"(max-width: 595px) 100vw, 595px\" \/><\/p>\n<p><strong>Log<\/strong> <strong>Collector<\/strong> <strong>Models<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-15794 size-full\" src=\"http:\/\/payampardaz.com\/en\/wp-content\/uploads\/sites\/2\/2020\/07\/ravin-siem-models2.png\" alt=\"\" width=\"586\" height=\"127\" srcset=\"https:\/\/payampardaz.com\/en\/wp-content\/uploads\/sites\/2\/2020\/07\/ravin-siem-models2.png 586w, https:\/\/payampardaz.com\/en\/wp-content\/uploads\/sites\/2\/2020\/07\/ravin-siem-models2-300x65.png 300w\" sizes=\"(max-width: 586px) 100vw, 586px\" \/><\/p>\n<p><strong>Log Management Models<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-15795 size-full\" src=\"http:\/\/payampardaz.com\/en\/wp-content\/uploads\/sites\/2\/2020\/07\/ravin-siem-models3.png\" alt=\"\" width=\"592\" height=\"131\" srcset=\"https:\/\/payampardaz.com\/en\/wp-content\/uploads\/sites\/2\/2020\/07\/ravin-siem-models3.png 592w, https:\/\/payampardaz.com\/en\/wp-content\/uploads\/sites\/2\/2020\/07\/ravin-siem-models3-300x66.png 300w\" sizes=\"(max-width: 592px) 100vw, 592px\" \/><\/p>\n<p><strong>Correlation Response Engine Models<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-15796 size-full\" src=\"http:\/\/payampardaz.com\/en\/wp-content\/uploads\/sites\/2\/2020\/07\/ravin-siem-models4.png\" alt=\"\" width=\"618\" height=\"106\" srcset=\"https:\/\/payampardaz.com\/en\/wp-content\/uploads\/sites\/2\/2020\/07\/ravin-siem-models4.png 618w, https:\/\/payampardaz.com\/en\/wp-content\/uploads\/sites\/2\/2020\/07\/ravin-siem-models4-300x51.png 300w\" sizes=\"(max-width: 618px) 100vw, 618px\" \/><\/p>\n<h2>Deployment scheduling<\/h2>\n<p dir=\"LTR\" style=\"text-align: justify;\">The following list describes the steps to deploy the Security Operations Center in a middle sized network.<\/p>\n<h4 style=\"text-align: justify;\">1) Requirements Engineering<\/h4>\n<ul style=\"text-align: justify;\">\n<li>Identify the network &amp; select the sensors<\/li>\n<li>Planning the setup<\/li>\n<li>Determine the staff<\/li>\n<\/ul>\n<h4 dir=\"LTR\" style=\"text-align: justify;\">2) Setup and Customization<\/h4>\n<ul style=\"text-align: justify;\">\n<li>Setup the infrastructures<\/li>\n<li>Configure sensors to send their logs<\/li>\n<li>Add necessary security sensors to the network<\/li>\n<li>Add required plugins to cover all of the selected sensors<\/li>\n<li>Define new required reports<\/li>\n<li>Customize knowledge base entries regarding to the operational environment situations &amp; organization security policies<\/li>\n<\/ul>\n<h4 style=\"text-align: justify;\">3) Configure and Tune the system<\/h4>\n<ul style=\"text-align: justify;\">\n<li>Verify initial outputs of the system according to network facts<\/li>\n<li>Determine the threshold values of correlation rules according to the initial feedbacks of the system.<\/li>\n<li>Determine the verification filters for reducing false positives incidents<\/li>\n<\/ul>\n<h4 dir=\"LTR\" style=\"text-align: justify;\">4) Training and Delivery<\/h4>\n<ul>\n<li>train the security operation center staffs<\/li>\n<li>deliver the system &amp; its management to SOC staffs<\/li>\n<\/ul>\n<h2>Supported applications and devices<\/h2>\n<div align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\" colspan=\"2\" width=\"573\"><strong>Network Security Devices<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Tarigh UTM<\/td>\n<td style=\"text-align: center;\" rowspan=\"30\" width=\"181\">Firewall\/UTM\/ WAF\/VPN<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Tarigh FV<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Tarigh WAF<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">ModeSecurity<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Keyhan VPN Server<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">IPTables<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Cisco-PIX<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Cisco-ASA<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Cisco-FWSM<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Juniper-Netscreen<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">IPFW<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Cisco-VPN<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Fortigate<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Juniper-VPN<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">TippingPoint<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">FortiGuard<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Sonicwall<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">ISA-Server<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Checkpoint<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Astaro<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Netasq Alarm<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Netasq Connection<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Netasq Filter<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Symantec Gateway Security<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Sonicwall<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Cisco ACS Csv<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Cisco ACS Syslog<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Cisco ACS Csv<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Radius<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Safeguard<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"text-align: center;\" align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"573\"><strong>Network Devices<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Cisco Switch<\/td>\n<td rowspan=\"8\" width=\"181\">Router\/Switch<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Cisco Router<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Huawei switch<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Huawei Router<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Cisco CSS<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Nortel Switch<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Foundry<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Juniper Router<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"text-align: center;\" align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"573\"><strong>Security monitoring Sensors<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"392\">RealSecure wgm<\/td>\n<td rowspan=\"22\" width=\"181\">HIDS\/NIDS\/ Honeypot<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">OSSec<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Osirix<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Juniper IDP<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Snort<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Suricata<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Stongate<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">SourceFire<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Bro IDS<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Cisco IPS(SDEE)<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Cisco CSA v45<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Cisco CSA v60<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Cisco CSA v52<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Tipping Point<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Samhain<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">TripeWire<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Symantec Network Security<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">McAfee Intercept<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">McAfee Intrushield<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Enterasys Dragon<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Amun<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">HoneyD<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"text-align: center;\" align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"573\"><strong>Operating Systems<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"459\">2003 Workstation &amp; Server, XP,Vista,Win7,Win8, Win2008workstation &amp; Server<\/td>\n<td width=\"114\">Windows<\/td>\n<\/tr>\n<tr>\n<td width=\"459\">Pam_unix,sudo,dhcp,usbdev<\/td>\n<td width=\"114\">Linux<\/td>\n<\/tr>\n<tr>\n<td width=\"459\">FreeBSD,NetBSD,OpenBSD<\/td>\n<td width=\"114\">BSD<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"text-align: center;\" align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"573\"><strong>Servers<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"315\">PureFTP<\/td>\n<td rowspan=\"16\" width=\"258\">Application servers\/Web Proxies<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">ProFTPD<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">WuFTP<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">SSHD<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">NFS<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">Apache<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">IIS<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">Bind<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">VSFTP<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">Squid<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">Squid Guard<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">WebShield<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">WebSense<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">OpenNMS<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">DHCP<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">OpenLdap<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"text-align: center;\" align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"573\"><strong>Mail Server<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"315\">Postfix<\/td>\n<td rowspan=\"6\" width=\"258\">Mail Server<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">Exchange<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">Courier<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">Dovecot<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">Axigen<\/td>\n<\/tr>\n<tr>\n<td width=\"315\">Send Mail<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"text-align: center;\" align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"585\"><strong>Antimalware<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Kaspersky<\/td>\n<td rowspan=\"11\" width=\"193\">Antivirus\/AntiSpam<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Bitdefender<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Avast<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Clamav<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Sophos<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Podvish<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Symantec End Point Protection<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Norton Antivirus<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Spamassasin<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Mcafee-Antivirus<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Mcafee-Antispam<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"text-align: center;\" align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"585\"><strong>Database<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"392\">MySQL<\/td>\n<td rowspan=\"4\" width=\"193\">Data Base<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Oracle<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">PostgreSQL<\/td>\n<\/tr>\n<tr>\n<td width=\"392\">Sybase<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div align=\"left\">\n<table class=\"MediumShading1-Accent51\" dir=\"rtl\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\" colspan=\"2\" width=\"585\"><strong>Scanners<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">NMap<\/td>\n<td style=\"text-align: center;\" rowspan=\"5\" width=\"193\">Asset Discovery\/ Vulnerability Scanner<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Nessus<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">NTop<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Oval<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\" width=\"392\">Mcafee FoundStone<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Introduction to Ravin Ravin Today, in any organization millions of events and alerts are generated by software, hardware, network and security devices daily. \u00a0Big amount of data, variety, different format and languages used in these events, makes it hard and costive to be identified, assessed and analyzed by human and may cause faults and mistakes [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":15640,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":["post-15638","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-network-monitoring"],"_links":{"self":[{"href":"https:\/\/payampardaz.com\/en\/wp-json\/wp\/v2\/posts\/15638","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/payampardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/payampardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/payampardaz.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/payampardaz.com\/en\/wp-json\/wp\/v2\/comments?post=15638"}],"version-history":[{"count":0,"href":"https:\/\/payampardaz.com\/en\/wp-json\/wp\/v2\/posts\/15638\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/payampardaz.com\/en\/wp-json\/wp\/v2\/media\/15640"}],"wp:attachment":[{"href":"https:\/\/payampardaz.com\/en\/wp-json\/wp\/v2\/media?parent=15638"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/payampardaz.com\/en\/wp-json\/wp\/v2\/categories?post=15638"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/payampardaz.com\/en\/wp-json\/wp\/v2\/tags?post=15638"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}