MozDef: The Mozilla Defense Platform
github.com
github.com
Is it webapp which informs me about new vuln. for my websites (parsing my logfiles)?
From my limited understanding MozDef is more targeted at ticketing/following through from intelligence gleaned from a SIEM as most times, people then just stick it in Remedy or Jira.
[1] http://public.dhe.ibm.com/common/ssi/ecm/en/wgd03021usen/WGD...
MozDef seems to be trying to make a relevant/niche ticketing system to run over the top of a SIEM (Security Information and Event Manager) which in turn runs over the top of IDS/IPS/AV/FW etc etc this allows single view and correlation between events i.e remote login from contracter over VPN using chinese IP address, escalating privileges on a unix box, new admin account on DB, increase in data flow outbound from DB, none of these events is individually significant but together its pretty obvious something might be wrong, thats why you pay good money for a SIEM.
The issue most companies face is they have awesome security intelligence platforms or SIEMS but then have to translate it into awful business process ticketing systems (like Remedy or Jira) not designed to handle such critical and quick moving issues.
Joke aside, I like the initiative, security is still something that seems to me not taken seriously enough by day to day sysadmins and developers.
From what I understand, its main use it to report it when attacks were attempted. Does it also check for what is probably the biggest security concern on the wild, aka outdated softwares that have updates available (better safe than sorry)?
OTOH, maybe it's not public facing :)
I read this as: attackers are usually one step ahead at least, and "defenders" (sic: developers (?) ) do not like pentesting? These tools are available to anyone..
MozDef is about incident handling. You still need to do this, even if you do pentesting.
Defenders are usually companies or a consultancies ERT (emergency repsonse team) or in their SOC (Security Operations Center) to monitor real time security threats to their business and Triage, mitigate, investigate, block etc.
Some of the enterprise tools (QRadar, Arcsight, EnVision) for these are really advanced but run into the 100's of thousands cost, so I think MozDef is an open sources initiative for smaller teams who don't have the resources for the above.
And in any case, the architecture put in place is interesting. I'm eager to see how they made use of Meteor.