The AT&T product comes with a lot of correlation rules and orchestration rules. But when we install the system for a particular client, we have been looking at their business objectives and then trying to customize the system to meet their unique business requirements.
For example, some of the clients would like to see what is happening on the perimeter and the traffic entering the network. This might be the case when they are concerned with any attacks always coming in a particular way or if there is any probing going on from outside parties. In other cases, the clients may be mostly trying to monitor what is going on inside their infrastructure and the focus is more internal to the network.
AlienVault provides you these capabilities. AT&T Management Security Services provides you not only with these SIEM (Security Information and Event Management) part of security, but also other areas like behavioral analytics. They are all built into one single package. This is the advantage: you have everything in one package.
Pros
Cons
What is our primary use case?
What is most valuable?
What we do is offer SOC as a service in Sri Lanka. We have a physical SOC based on this product. We find the SIEM is, of course, the main focus of any client. The incident reporting, the logging, and then the alarms or alerts being reported come in as the number one purpose for adopting the product.
Next will come things like asset discovery where sometimes the client does not have the resources to put into the ultimate solution or their network. Then things like the summarization of events and incidents are important. Most clients like to have weekly reports from us which tell them where the areas are that they need to look at. With the AT&T MSSP (Managed Security Services Provider) product that we are using, it is very easy to customize the reports. Then the correlation of our drilling down to diagnose the incidents also becomes very easy. The features related to the SIEM are really easy to handle and once you get to know the dashboards and the features, they make it very easy to drill down to the issues.