Type80's SMA_RT: integrate your z/OS security events in real-time to Security Information and Event Management (SIEM) solutions
Type80 Security Software’s SMA_RT product brings mainframe security into the modern era.
By analyzing data from both WTO messages along with SMF data, Type80 gathers detailed information about security events on the mainframe. This data is then encapsulated in standard TCP/IP Syslog format and delivered in real-time to those responsible for enterprise security.
This gives an organization an enterprise-wide view of all the events they need to capture to stay abreast of attacks against their infrastructure.
The SMA_RT STC collects input from two separate real-time data streams.
The Type80 Operating System Interface (message processor)
The Type80 TSO Interface
The SMA_RT software has a TSO Interface. The TSO Interface is a series of TSO panels that allows the Security Administrator to define what they would like to monitor and to tie the monitored resources into a Type80 rule set. The resultant rules are stored in VSAM files on the mainframe, with each LPAR having its set of VSAM files and rule sets. Type80 tracks by RACF USERID, IP address, SNA device address, by file names or by message Id’s.
The Type80 SIM/SEM/Log Consolidation Interface
All outbound event alerts from SMA_RT and SYSLOG to Threat Management Systems/SIM/SEM and Log Consolidation products are in the same industry standard "TCPIP,RFC 3164,SYSLOG" format. This allows these products to collect data from Type80 as if the mainframe were a UNIX box attached to the network. One parser algorithm will handle events being delivered from both of the Type80 products. Alerts are sent using a random port on the mainframe. The port and IP address of the recipient SIM/SEM product is defined in the Type80 configuration file.
Assembler written application that resides within an LPAR on the mainframe.
Each LPAR requires an instance of SMA_RT to be active to achieve complete enterprise monitoring.
SMA_RT is a started task (STC) process that can be started at IPL time.
SMA_RT is a Type80 Security Software product.