Beginner’s guide: OSSIM Part 2

Image
Hope all of you are keeping well. Thank you all for the overwhelming support you people are giving me. So today we’ll deal with everything from basic OSSIM configuration to integrating different types of assets. Before we jump in to all of that I hope all of you are ready with installation. If not please visit my previous post, which is actually the first part. Beginner’s guide: OSSIM (Open Source Security Information Management) part 1 Make sure you have an active internet connection for your OSSIM. As you all know the Alienvault platform has five modules in it, which are the Asset discovery, vulnerability assessment, threat detection, behavioural monitoring and security intelligence. In simple words we add assets first, and then we’ll configure all those assets under each and every module of Alienvault respectively. If you're ready with everything mentioned in part 1, we can now move forward with the configurations. Here we’re just considering only OSSIM not USM.

TCP/IP Suite



 
I hope all of you have already read my blog on OSI layers.


Today we are going to discuss the TCP/IP suite. When compared with the OSI layer, we can see that few layers have been merged together in TCP/IP suite. Just like the OSI layers, TCP/IP suite is also made up of hierarchical protocols which are interactive and are not necessarily interdependent. OSI layer specifically defines functions of each layer in the model, whereas in TCP/IP suite, these independent protocols can be mixed and matched depending upon the need of the system. Just like the OSI model, upper level layers are supported by one or more lower level protocols in TCP/IP suite also.

Network Layer

Here none of other layer specifies any protocols. Instead it supports all standard and proproetay protocols. It simply can the physical connection between two end devices.

Internet Layer

It is an unreliable connection less protocol. It is used as a transmission mechanism by TCP/IP protocols. The transport layer support the internet layer, in turn the IP uses around four supporting protocols like ARP, RARP, ICMP, IGMP.

Transport Layer

The transport layer is always represented by two protocols ‘TCP/IP’. IP is host-host protocol, but since it is in internet layer the reliability is low. So the transport layer support the internet layer for reliable delivery of the data transmitted. UDP and TCP are the two protocols in the transport layer.

Application Layer

It is the combined form of application, presentation and session layer in OSI. It allows access to the network resources by translating, encrypting and compressing data if necessary.It also helps in session management.

Comments

Post a Comment

Popular posts from this blog

Beginner’s guide: OSSIM (Open Source Security Information Management) part 1

Beginner’s guide: OSSIM Part 2

Beginner’s guide: How to setup a SOC (Security Operations Center)