total integrated security solution - accueil - eb-qual sa · pdf file ·...

35
| Total Integrated Security Solution Fabien Broillet Technical Director [email protected] IT Security Intelligence with QRadar

Upload: vuthuy

Post on 19-Mar-2018

215 views

Category:

Documents


3 download

TRANSCRIPT

Page 1: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

|

Total Integrated Security Solution Fabien Broillet – Technical Director [email protected]

IT Security Intelligence with QRadar

Page 2: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

What is Security Intelligence?

3

Security Intelligence provides actionable and comprehensive insight for

managing risks and threats from protection and detection through remediation

Page 3: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

Security Intelligence like Business Intelligence

4

Page 4: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

IBM Security Intelligence

Total Integrated Security Solution

5

Page 5: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

Solution for the full Security Intelligence

6

Page 6: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

IBM QRadar

Total Integrated Security Solution

7

Page 7: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

Built upon common foundation of QRadar SIOS

8

Page 8: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

Taking in data from wide spectrum of feeds

9

Page 9: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

And continually adding context for increased

accuracy

10

Page 10: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

Two deployment models: All-in-One & Distributed

11

Page 11: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

Deployed upon scalable appliance architecture

13

Page 12: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

Using fully integrated architecture and interface

14

Page 13: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

QRadar SIEM

Total Integrated Security Solution

15

Page 14: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

QRadar SIEM

Command Console for Security Intelligence

16

Page 15: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

QRadar SIEM

Flows - Context for true network intelligence

17

Page 16: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

QRadar Vulnerability Manager

Total Integrated Security Solution

18

Page 17: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

QRadar Vulnerability Manager

Strengthened by integrated vulnerability insights

19

Page 18: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

The Proof by example

Total Integrated Security Solution

21

Page 19: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

QRadar Customer Concrete Case …

Offenses overview

22

Page 20: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

QRadar Customer Concrete Case …

23

Page 21: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

QRadar Customer Concrete Case …

24

Page 22: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

QRadar Customer Concrete Case …

Let's go into the details

25

Page 23: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

QRadar Customer Concrete Case …

Web servers only as targeted IP’s !

26

Page 24: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

QRadar Customer Concrete Case …

Let’s have a look on a specific targeted Web server …

27

Page 25: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

QRadar Customer Concrete Case …

Concerned Firewall Logs

28

Page 26: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

QRadar Customer Concrete Case …

Concerned IPS Logs

29

Page 27: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

QRadar Customer Concrete Case …

Correlation Rule matched

30

Page 28: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

Remote Web Scanner Detected When an event matches any of these CategoryDefinition:

Recon Events

Suspicious Events

With the same source IP more than 5 times, across more than 59 dest. IP within 10 minutes

When the context is:

Remote to Local

Remote to Remote

When a flow or an event matches any of the following PortDefinition:

Web Ports

Reports a remote host attempting reconnaissance or suspicious connections on common local

web server ports to more than 60 hosts in 10 minutes.

QRadar Customer Concrete Case …

31

Page 29: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

QRadar Customer Concrete Case …

Correlation Rules matched

32

Page 30: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

Exploit/Malware Event Across Multiple Destinations NOT when an event matches any of the following Exploit:

Destination Vulnerable to Detected Exploit on a Different Port

When an event matches any of these CategoryDefinition:

Exploits Backdoors

Trojans

With the same source IP more than 5 times, across more than 5 destination IP within 5 minutes

Reports a source IP address generating multiple (at least 5) exploits or malicious software

(malware) events in the last 5 minutes. These events are not targeting hosts that are

vulnerable and may indicate false positives generating from a device.

QRadar Customer Concrete Case …

33

Page 31: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

Exploit Attempt Proceeded by Recon When all of these ReconDetected:

All Recon Rules

When all of these CategoryDefinition

Exploits Backdoors

Trojans

From the same source IP to the same destination port, over 1 hours

Reports reconnaissance followed by an exploit from the same source IP address to the same

destination port within 1 hour.

QRadar Customer Concrete Case …

34

Page 32: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

Main Challenge completed !

35

Many heterogeneous & unstructured data …

Page 33: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

Main Challenge completed !

36

Keeping ressources & effort on key elements

Page 34: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

In Conclusion

QRadar leverages our logs to detect major incidents, but…

QRadar leverages open services to be even more accurate What to do if we have no idea about Services present in an Offense raised by the system ?

Consider collecting network flows through QFlow collector !

QRadar leverages present vulnerabilities to be even more accurate What to do if we have no idea about the vulnerabilities present in an Offense raised by the

system ?

Consider collecting vulnerabilities posture through QRadar Vulnerability Manager

QRadar leverages Geo location & IP reputation to be more useful Consider having powerful services like IBM Security Intelligence Feeds

37

Page 35: Total Integrated Security Solution - Accueil - eb-Qual SA · PDF file · 2014-09-04Total Integrated Security Solution ... What is Security Intelligence? 3 ... Concerned Firewall Logs

[email protected] www.eb-qual.ch

Fabien Broillet

Technical Director

eb-Qual AG

Oberfeldstrasse 20

8302 Kloten

THANK YOU

Tel. 043 211 47 20

Fax 043 211 47 29