Security Monitoring
Enterprises face the threat of intrusion from multiple sources on a regular basis. Monitoring threats in an adhoc manner places an organization at considerable risk. Intrusion attempts can be captured through consolidated analysis of logs from Operating Systems, Databases, network and security devices. Analyzing logs in real time will enable organizations to detect and prevent security incidents arising from threats. Paladion has a fully established Security Operations Center (SOC) for continuous management of internal & external threats. Our security event monitoring service offers real time detection & response to intrusion attempts on a 24X7X365 basis. The primary goal of our security monitoring and attack detection services is to help identify suspicious events on a network that may indicate malicious activity or procedural errors.
Features
- 24X7X365 service
- Real time detection, alert & response
- Attack correlation for logs from multiple sources
- Multiple alert mechanisms
- Multi vendor and platform support
- Support for large number of devices, more than 140+
- Smart bandwidth utilization
- Intelligent event capture
- Incident Management
- Historic Forensic Analysis Capabilities
- Risk based prioritization
- Security Dashboard for online reports
- 250+ predefined report templates
- Rich visualization
How do we do it?
Paladion's network security monitoring combines a team of disciplined security experts, a rigorous process for incident detection and response, and best-of-breed technologies to provide information-driven organizations immediate feedback regarding the threats to a network's security -- in real time, as it changes in the face of new attacks, new threats, software updates, and reconfigurations. Our security monitoring architecture is designed to collect, normalize, aggregate and filter millions of events from thousands of assets across customer networks into a manageable stream prioritized according to risk. These prioritized events can then be correlated, investigated, analyzed, and remediated using tools at our SOC. We have a multi-tier architecture with agents loaded on centralized log servers in customer premise reporting to our central Security Information Management (SIM) server at SOC. Customer logs are segregated in to individual streams and strict access controls are managed between customer event data