Analytics
6/14/2013
11:31 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

EiQ Networks Announces ThreatVue

New solution combines SIEM data with other critical security data

Acton, Mass., June 12, 2013 – EiQ Networks, a pioneer in simplified security, risk and compliance solutions, today announced ThreatVue&trade, the first out-of-the-box security monitoring solution that automates the implementation, analysis and remediation guidance of essential security controls as recommended by the Center for Strategic and International Studies (CSIS) and The SANS Institute for effective cyber defenses.

ThreatVue takes an innovative approach to critical security controls implementation and security monitoring by proactively detecting critical security control failures and providing actionable guidance and answers to improve an organization's cyber defenses and overall security posture. The new solution combines traditional Security Information and Event Monitoring (SIEM) data with other critical security data (i.e. network awareness; asset and configuration data). ThreatVue's new closed-box design provides behind-the-scenes automation enabling organizations to proactively detect and remediate potential security problems.

"ThreatVue enables customers to easily answers questions such as what nodes, users and network activities are not aligned with security best practices, and what should they do to fix potential problem areas," said Vijay Basani, CEO of EiQ Networks. "ThreatVue addresses deployment and operational complexities, costs and other headaches associated with SIEM and security monitoring products on the market today."

"SANS Critical Security Controls is an extremely focused, metrics-based strategy for addressing the most common security vulnerabilities," said Jon Oltsik, senior principal analyst at Enterprise Strategy Group. "Reliance on manual assessment, response, and mitigation has contributed to the poor state of cybersecurity. With the incidents of cybercrimes on the rise, organizations should use guidelines like the SANS Critical Security Controls to help them automate processes and address IT risk."

To learn more about EiQ Networks and its offerings, please visit: www.eiqnetworks.com

About EiQ Networks:

EiQ Networks, a pioneer in simplified security and compliance solutions, is transforming how organizations identify threats, mitigate risks and enable compliance. Our solution, SecureVue®, is a unified situational awareness platform that proactively detects incidents, minimizes "false positives" and delivers timely and actionable intelligence by simplifying often-complex interactions between security, risk and compliance. Through a single console, SecureVue provides a unified view of your entire IT infrastructure for proactive security and risk analysis, continuous monitoring, configuration auditing, compliance automation and context relevant search. For more information, visit: http://www.eiqnetworks.com.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Threat Intel Today
Threat Intel Today
The 397 respondents to our new survey buy into using intel to stay ahead of attackers: 85% say threat intelligence plays some role in their IT security strategies, and many of them subscribe to two or more third-party feeds; 10% leverage five or more.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8142
Published: 2014-12-20
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys w...

CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.