Prelude SIEM (Intrusion Detection System) explained

Prelude SIEM
Author:Yoann Vandoorselaere
Released:1998
Latest Release Version:5.2.0
Latest Release Date:[1]
Programming Language:Python, C
Operating System:Linux, *NIX
Language:French, English, German, Spanish, Italian, Polish, Portuguese, Russian
Genre:SIEM
License:Proprietary software and GPLv2
Website:
Standard:RFC4765

Prelude SIEM is a Security information and event management (SIEM).

Prelude SIEM is a tool for driving IT security that collects and centralizes information about the company's IT security to offer a single point of view to manage it. It can create alerts about intrusions and security threats in the network in real-time using logs and flow analyzers. Prelude SIEM provides multiple tools to do forensic reporting on Big Data and Smart Data to identify weak signals and Advanced Persistent Threats (APT). Prelude SIEM also embeds all tools for the exploitation phase to make work easier for operators and help them with risk management.

While a malicious user (or software) may be able to evade the detection of a single intrusion detection system, it becomes exponentially more difficult to get around defenses when there are multiple protection mechanisms. Prelude SIEM comes with a large set of sensors, each of them monitoring different event types. Prelude SIEM permits alert collection to the WAN scale, whether its scope covers a city, a country, a continent or the world.

Prelude SIEM is a SIEM system capable of inter-operating with all the systems available on the market.[2] It implements natively with the Intrusion Detection Message Exchange Format (IDMEF, RFC 4765) format. In this way, it is natively IDMEF compatible with OpenSource IDS: AuditD, Nepenthes, NuFW, OSSEC, Pam, Samhain, Sancp, Snort, Suricata, Kismet, etc. but anyone can write their own IDS or use any of the third party sensors available, given Prelude SIEM's open APIs and libraries.

Since 2016, with the "Prelude IDMEF Partner Program", Prelude SIEM is now also IDMEF compatible with many commercial IDS.

Prelude SIEM provides all SIEM functions through three modules: ALERT (SEM), ANALYZE and ARCHIVE (SIM) and is so the only one true SIEM alternative on the market. Plus, Prelude SIEM promotes the use of IETF security standards through the SECEF[3] project and the "Prelude IDMEF Partner Program".

History

Functions

Prelude SIEM collects, normalizes, sorts, aggregates, correlates and displays all security events regardless of the types of surveillance equipment. Beyond its capacity for processing of all types of event logs (system logs, syslog, flat files, etc.), it's also natively compatible with many IDS.

Prelude SIEM's main characteristics are the following:

Prelude SIEM Community version

Prelude SIEM OSS has been designed in a scalable way to simply adapt to any environment. it is a free, public and open-source version (GPLV2) for small IT Infrastructures, tests and educational purposes.

The open-source version is composed of the following main modules:

These modules are the base of the ALERT module in the commercial version. The commercial version also adds many functionalities to these modules and scale up the performances and architecture possibilities.

Prelude SIEM and Prelude SOC

Prelude SIEM (commercial version) is a scalable, professionally usable and high-performance version of Prelude, for real-world environments. Prelude SOC is fully scaled version, mainly for SOC (Security Operations Center) usage.

The commercial versions are organized as follows:

External links

Notes and References

  1. Web site: Files - PRELUDE SIEM - UNITY 360 . prelude-siem.org . 2021-04-24.
  2. Web site: PreludeLml - PRELUDE SIEM. www.prelude-siem.org. en. 2017-11-12.
  3. Web site: SECEF. SECEF. fr-FR. 2017-11-12.