<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns="http://purl.org/rss/1.0/">
<channel rdf:about="http://www.nessus.org/">
<title>Tenable LCE Updates</title>
<link>http://www.nessus.org/</link>
<description>Log Correlation Engine Content Updates</description>
<items>
<rdf:Seq>
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=155" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=150" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=146" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=142" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=140" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=134" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=128" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=127" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=120" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=116" />
</rdf:Seq>
</items>
</channel>
<image rdf:about="http://www.nessus.org/images/RssLogo.jpg">
<title>Nessus News</title>
<url>http://www.nessus.org/images/RssLogo.jpg</url>
<link>http://www.nessus.org/</link>
</image>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=155">
<title>ISA Firewall and MailScanner Policy Files</title>
<description><![CDATA[Tenable's research group has released two new PRM policy files for ISA firewall logs delivered via Snare as well as anti-spam MailScanner logs. <br />
<br />
Links for these policies, as well as an updated event name map are below: <br />
<br />
<ul><br />
<li><a href="http://www.nessus.org/firewall_isa_snare.prm">firewall_isa_snare.prm</a></li><br />
<li><a href="http://www.nessus.org/spam_mailscanner.prm">mail_scanner.prm</a></li><br />
<li><a href="http://www.nessus.org/prm_map.prm">prm_map.prm</a></li><br />
</ul><br />
<br />
Performing a plugin update will automatically place these files in your ~/daemons/plugins directory. Otherwise, these files can be manually downloaded and placed there. After they are in place, restarting your thunderd process will make these files live. <br />
<br />
Below is a link to the official Mail Scanner web site:<br />
<br><a href="http://www.mailscanner.info/">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=155</link>
<dc:date>2008-09-07T09:33:00-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=150">
<title>Support for TopLayer IPS Logs</title>
<description><![CDATA[Tenable has released a normalization library for syslog events from TopLayer IPS devices. The new library and the updated PRM map library can be found at: <br />
<br />
<ul><br />
<li><a href="http://www.nessus.org/nids_toplayer.prm">nids_toplayer.prm</a></li><br />
<li><a href="http://www.nessus.org/prm_map.prm">prm_map.prm</a></ul><br />
</ul><br />
<br />
Both of these files should be manually placed in your <i>plugins</i> directory on your LCE. Also, if you perform a full plugin update, the new library will be automatically added as well. Be sure to restart the <i>thunderd</i> process after the new files are loaded. <br />
<br />
<br><a href="http://www.nessus.org/nids_toplayer.prm">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=150</link>
<dc:date>2008-09-07T09:33:00-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=146">
<title>Support for F5 Big IP Application Firewall Logs</title>
<description><![CDATA[A new PRM library to process firewall events from F5 Big IP Application Firewall devices is now available. If you perform a full plugin update, this new library will be automatically installed. If you wish to perform a manual update, below are links for the new PRM library and the updated plugin index library:<br />
<br />
<ul><br />
<li><a href="http://www.nessus.org/firewall_f5bigip.prm">firewall_f5bigip.prm</a></li><br />
<li><a href="http://www.nessus.org/prm_map.prm">prm_map.prm</a></li><br />
</ul><br />
<br />
Make sure to restart your thunderd process after installing these new libraries. <br />
<br />
<br><a href="http://www.nessus.org/firewall_f5bigip.prm">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=146</link>
<dc:date>2008-09-07T13:33:00-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=142">
<title>Support for Cisco ACS Log Files</title>
<description><![CDATA[A new library for the Log Correlation Engine to process logs from Cisco ACS devices is now available here: <a href="http://www.nessus.org/auth_cisco_acs.prm">auth_cisco_acs.prm</a>.<br />
<br />
This new PRM file should be downloaded to your <i>/usr/thunder/daemons/plugins</i> directory and your thunderd process restarted. In addition, if you are making use of any TASL scripts, the <a href="http://www.nessus.org/prm_map.prm">prm_map.prm</a> file should also be updated prior to restarting the thunderd process. <br />
<br />
 <br><a href="https://plugins-customers.nessus.org/support-center/index.php?x=">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=142</link>
<dc:date>2008-09-07T13:33:00-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=140">
<title>F5 Local Traffic Manager Log support</title>
<description><![CDATA[Tenable has added support to process session information logs from F5 Local Traffic Manager devices. <br />
<br />
This new PRM file can be downloaded from <a href="http://www.nessus.org/web_f5_ltm.prm">here</a> and then placed in your <i>/usr/thunder/daemons/plugins</i> directory. An updated <a href="http://www.nessus.org/prm_map.prm">prm_map.prm </a> file is also available. Performing a full plugin update will also add this new rule to your Log Correlation Engine. The <i>thunderd</i> process must also be restarted after the plugin update. <br />
<br />
Directions and references on how to configure the F5 LTM are included in the comments of the new PRM file.<br />
<br />
<br><a href="http://www.nessus.org/web_f5_ltm.prm">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=140</link>
<dc:date>2008-09-07T17:33:00-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=134">
<title>New and Updated PRM Libraries</title>
<description><![CDATA[Tenable's research group has released several new libraries and updates for parsing new log events. These include support for logs from the Cisco Security Agent and the Amavis SPAM filter. There were also performance updates to the Postfix, Snort, PVS, Tripwire Server, Sonicwall, Windows events, Sidewinder and Netgear PRM libraries. <br />
<br />
Performing an automated plugin update with the <i>thunder-update-plugins.sh</i> script located in the <i>/usr/thunder/daemons</i> directory will add these new libraries to your Log Correlation Engine. Once updated, the <i>thunderd</i> process must be restarted.<br />
<br />
To see a list of all normalized LCE events, click on the below link:<br><a href="http://www.nessus.org/prm_map.prm">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=134</link>
<dc:date>2008-09-07T21:33:00-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=128">
<title>Discrete Anomaly Event Types</title>
<description><![CDATA[The normalization rules for logs from the <i>stats</i> daemon have recently been modified to provide more fidelity when analyzing statistical anomalies.<br />
<br />
Previously, the normalization process categorized all anomalies into generic types of "Large Anomaly", "Medium Anomaly" or just an "Anomaly". <br />
<br />
This new rule set creates events based on the "type"  of event that created the anomaly. For example, here are some example new event names:<br />
<ul><br />
<li>Statistics-User_Activity_Anomaly</li><br />
<li>Statistics-Login_Failure_Anomaly</li><br />
<li>Statistics-Network_Large_Anomaly</li><br />
</ul><br />
There are more than 100 new rules to support minor, regular, medium and large anomaly levels for all unique LCE event types. Having rules with this type of fidelity makes it much easier to focus on event types (such as logins) in which a minor statistical anomaly could be rather important. <br />
<br />
To update your LCE, please use the following links: <br />
<ul><br />
<li>Updated <a href="http://www.nessus.org/tenable_stats.prm">tenable_stats.prm</a> file</li><br />
<li>Updated <a href="http://www.nessus.org/prm_map.prm">prm_map.prm</a> file</li><br />
<li>The <a href="http://cgi.tenablesecurity.com/tasl/ids_event_followed_by_change.tasl">ids event followed by change</a> TASL script was modified to look for Large and Medium statistical anomalies in the connection rates of profiled hosts.</li><br />
<li>The <a href="http://cgi.tenablesecurity.com/tasl/standard_deviation_long_term.tasl">standard deviation long term</a> TASL script was modified to look for Large and Medium events from the new PRM library.</li><br />
</ul><br />
<br />
Follow the link below to learn more about how the LCE's <i>stats</i> engine profiles all of the logs from each host to look for anomalies:<br><a href="http://blog.tenablesecurity.com/2006/10/example_network.html">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=128</link>
<dc:date>2008-09-07T20:33:00-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=127">
<title>Support for Emerging Threats Project Content</title>
<description><![CDATA[Tenable is now offering support and interoperability to work with data from the Emerging Threats project.  The project produces a variety of updated Snort rules as well as a variety of lists of suspicious and compromised IP addresses. <br />
<ul><br />
<li>A new PRM library named <a href="http://www.nessus.org/nids_snort_emergingthreats.prm">nids_snort_emergingthreats.prm</a> is now available that can normalize Snort logs running the Emerging Threats rule base.</li><br />
<li>Version 2.4.3 of the Blacklist perl script is now available from the customer support portal and includes support for IP address correlation with known botnets, the Russian Business Network and known compromised hosts. The <a href="http://www.nessus.org/lce_tasl.prm">lce_tasl.prm</a> library has also been updated to parse these new types of blacklist correlation rules.</li><br />
<li>The existing <a href="http://www.nessus.org/nids_snort.prm">nids_snort.prm</a> library has had support for the previous Bleeding Threats signature database removed.</li> <br />
</ul><br />
If you are using any TASL scripts, then also be sure to update the <a href="http://www.nessus.org/prm_map.prm">prm_map.prm</a>  file. This file is referenced by many TASL scripts as an index of all normalized log event names.<br />
<br />
<br><a href="http://www.emergingthreats.net/">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=127</link>
<dc:date>2008-09-07T20:33:00-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=120">
<title>Updated Cyberguard PRM File</title>
<description><![CDATA[The <i>firewall_cyberguard.prm</i> library has been updated with support for logs from Cyberguard TSP1250 appliances. <br />
<br />
To update your Log Correlation Engine, either run a plugins update, or manually download the updated file with the link below, place it in your <i>/usr/thunder/daemons/plugins</i> directory and restart the <i>thunderd</i> process.<br><a href="http://www.nessus.org/firewall_cyberguard.prm">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=120</link>
<dc:date>2008-09-07T15:33:00-05:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=116">
<title>Cisco FSWM Library Update</title>
<description><![CDATA[The firewall_cisco_pix_alt.prm library has been updated with many new log types. All blocked network connections are now labeled as a 'firewall' rule type and allowed connections are logged as a 'connection' type.  <br />
<br />
To obtain this updated PRM library, follow the link below and place this library into your plugins directory in <i>/usr/thunder/daemons/plugins</i> and then restart the <i>thunderd</i> process. If you are using TASL correlation scripts, also download the latest <a href="http://www.nessus.org/prm_map.prm">prm_map.prm </a> file and replace it in the same plugins directory before restarting. <br><a href="http://www.nessus.org/firewall_cisco_pix_alt.prm">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=116</link>
<dc:date>2008-09-07T17:33:00-05:00</dc:date>
</item>
</rdf:RDF>
