Nueva versión de AlienVault OSSIM 5.2.4 (18/05/2016)

Saludos nuevamente.

El pasado día 18 de mayo de 2016 se publicó una nueva versión de la rama 5.x de AlienVault OSSIM, la 5.2.4. Dicha versión viene con actualizaciones de características y plugins. He aquí la noticia enviada por parte del equipo de realización:

New Update: AlienVault 5.2.4 has been released

2016-05-18 20:00:00

As of Thursday, May 19, 2016, AlienVault USM and OSSIM v5.2.4 are now generally available for all existing and new customers.

Users can update their system(s) through the console or web UI (see upgrade instructions for more information).

Please take a few minutes to carefully read these release notes before upgrading.

Additional Upgrade Info for All Users on v5.1.1 and Earlier

Documentation Updates
Improvements Added – USM and OSSIM
  • Improved alarm filtering – Filter alarms by risk level in the alarm list view
  • Syslog via TCP – AlienVault can now collect logs from devices that send syslog via TCP
  • Improved Windows file integrity monitoring – AlienVault HIDS now includes new rules to better monitor activities occurring on Windows machines
Improvements Added – USM only
  • AlienVault Logger performance improvements – Improved indexing and compression for long-term storage and more efficient searching
  • New compliance reports – 16 new reports available for NERC CIP and Gramm-Leach Bliley Act (GLBA) regulations
Defects Fixed
  • ENG-100641 – Web UI displays alarms still be correlated despite them reaching last correlation level – Alarms that have finished correlating appear properly in UI.
  • ENG-101664 – Agent auto-deployment/download is blocked for OS mis-detection with no easy fix – Added new messaging in the web UI to provide users with instructions on how to deploy agents.
  • ENG-101864 – Advanced search options not working properly in SIEM events – Advanced search works as expected.
  • ENG-102183 – No warning when user reaches plugin limit – Warnings added in UI and Message Center.
  • ENG-102512 – Template permission not working in alarm details action menu – Delete alarms option is only available when permission is given.
  • ENG-102704 – Ticket opened from alarm has no back reference to alarm – Tickets now include link to alarm.
  • ENG-102705 – SIEM events do not have unique URLs – Each event now contains a unique URL.
  • ENG-102857 – Initial setup search domain configured by ossim-setup is broken – Search domain is configured properly.
  • ENG-102923 – Some accounts have unnecessary access – The users list, irc, gnats, uucp, news, and IP were removed.
  • ENG-102934 – Database schema is inconsistent – Improved vulnerability database.
  • ENG-103175 – Squid events are being discarded by server – Updated plugin SID so that logs are processed properly.
  • ENG-103221 – The top 5 alarms dashboard shows open and closed alarms – Dashboard now shows only open alarms.
  • ENG-103240 – User permissions not properly segregating information – User permissions using contexts now work as expected.
  • ENG-103262 – Whois monitor plugin failing since 5.2 – Re-installed whois binary so that plugin works as expected.
  • ENG-103284 – Adjust rsyslog config for Bluecoat logging – Updated rsyslog to split Bluecoat logs into multiple lines.
  • ENG-103291 – Large events generate overflow which affects sensors – Improved sensor handling of large events.
  • ENG-103302 – Binary data is indexed in the Logger leading to large indices – Binary data is no longer indexed.
  • ENG-103339 – Alarm link in ticket is broken after alarm correlation – All opened tickets point to the alarm that they were generated from.- ENG-103364 – alienvault_dumpindex does not work with compressed indices – Users are able to dump indexes, even when the mindex.inx file is compressed.
  • ENG-103434 – Alienvault-forward does not reconnect when it loses connection – Added new reconnect method and additional debug messages when this issue occurs.
Security Advisories
  • ENG-103348, Vulnerable Hardware Configuration – RAKP (CVE-2013-4786) – AlienVault 5.2.4 is not vulnerable.
  • ENG-103348, Vulnerable Package – samba (multiple) – Added new version of package to repository – AlienVault 5.2.4 is not vulnerable.
  • ENG-103378, Vulnerable Package – openssh (CVE-2015-8325) – Added new version of package to repository – AlienVault 5.2.4 is not vulnerable.
  • ENG-103396, Vulnerable Package – libgd2 (CVE-2016-3074) – Added new version of package to repository – AlienVault 5.2.4 is not vulnerable.
  • ENG-103416, Vulnerable Configuration (ZDI-CAN-3704) – AlienVault 5.2.4 is not vulnerable.
  • ENG-103417, Vulnerable Configuration (ZDI-CAN-3704) – AlienVault 5.2.4 is not vulnerable.
  • ENG-103419, Vulnerable Package – openssl (multiple) – Added new version of package to repository – AlienVault 5.2.4 is not vulnerable.
  • ENG-103436, Vulnerable Package – libtasn1-6 (CVE-2016-4008) – Added new version of package to repository – AlienVault 5.2.4 is not vulnerable.
  • ENG-103449, Vulnerable Configuration (ZDI-CAN-3752) – AlienVault 5.2.4 is not vulnerable.
  • ENG-103452, Vulnerable Package – php5 (multiple) – Added new version of package to repository – AlienVault 5.2.4 is not vulnerable.

See the Security Advisory for USM and OSSIM v5.2.4 for more information.

Acerca de Hector Suarez Planas

Es Licenciado en Ciencia de la Computación (3 de julio de 2002). Ha sido Administrador de Red en varias organizaciones, Programador y Analista de Sistemas. Actualmente se desempeña como Administrador de Red del Telecentro Tele Turquino de Santiago de Cuba. Tiene experiencia con sistemas Windows y GNU/Linux, Infraestructura de Redes (Cisco, AlliedTelesis, Netgear y HP ProCurve, Vyatta/VyOS), Servidores tanto físicos como virtuales (plataformas VMWare, Proxmox VE y Xen), Sistemas de Seguridad Informática (Snort/Suricata IDS, appliances AlienVault OSSIM), programador (Delphi, C++ Builder, Perl [poco], Python [algo]), entre otras cosas. Actualmente estoy incursionando en todo lo que tiene relación con Cloud Computing (OpenStack) y Centros de Datos. :-)
Esta entrada fue publicada en Actualizaciones, AlienVault OSSIM. Guarda el enlace permanente.

2 respuestas a Nueva versión de AlienVault OSSIM 5.2.4 (18/05/2016)

  1. odiseo dijo:

    Héctor, tengo la versión de OSSIM (AlienVault_OSSIM_64bits_5.1.1_2), la tengo montada en una VM en proxmox, pero no he logrado avanzar en su implementación por falta de documentación para esta versión, ¿podrías tirarme al privado lo que puedas sobre este tema?, no tengo salida al mar, aún.

    Saludos.

    • Hector Suarez Planas dijo:

      Saludos, Odiseo.

      Primero que todo, pienso que debería usar una versión más reciente. 🙂 Y sí, sin problemas puede contar conmigo. Le escribiré un correo.

      🙂

Deja un comentario

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *