ibm qradar siem · ibm qradar siem augustin anić, system security engineer. agenda • siem leader...

22

Upload: others

Post on 07-Jul-2020

33 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons
Page 2: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons

IBM QRadar SIEM

Augustin Anić, System Security Engineer

Page 3: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons

Agenda

• SIEM leader• Effective Threat Detection• QRadar in action

– Dashboard– Search– Security incidents– Reports– User behaviour analysis

Page 4: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons

Gartner Magic Quadrant for SIEM

Page 5: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons

Open Platform

with hundreds of free integrations and content packs available via IBM Security App Exchange

See Everything

Automate Intelligence

Be Proactive

Page 6: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons

Effective Threat Detection

Page 7: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons

See EverythingGain comprehensive visibility into enterprise-wide data from behind a single pane of glass

BUSINESS CONTEXT

USERSCLOUD

APPLICATIONS

ENDPOINT

NETWORK

THREAT INTELLIGENCE

Page 8: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons

Automate IntelligenceAutomatically track threats as they progress, prioritize critical events and investigate potential incidents

Detect

Known and unknown threats

Connect

Related activity in multi-stage attacks

Prioritize

Business critical events

Investigate

Potential incidents with AI to find root

cause faster

Page 9: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons

Become Proactive

Hunt threats, respond faster and continuously improve based on lessons learned

Hunt ThreatsWith quick and advanced search

Respond Faster With automated containment and/orIR integration

Continuously ImproveWith closed-loop feedback based on lessons learned to improve automated detection processes

Page 10: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons

How it works?

Page 11: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons

QRadar dashboard

Page 12: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons
Page 13: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons
Page 14: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons

QRadar Search

Page 15: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons

QRadar offense/rules

Page 16: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons
Page 17: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons

QRadar reports

Page 18: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons
Page 19: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons
Page 20: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons

QRadar User behavior analysis

Page 21: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons

Summary

Trenutne prijetnje zahtijevaju konstantno nadziranje i analitiku

Potreba za centralnim sustavom obrade evenata u lokalnoj mreži

Potreba za automatizacijom detekcija sigurnosnih prijetnji i njihove prioritizacije

Proaktivnost i detekrianje prijetnji u ranijoj fazi njihove aktivnosti

Page 22: IBM QRadar SIEM · IBM QRadar SIEM Augustin Anić, System Security Engineer. Agenda • SIEM leader ... CLOUD APPLICATIONS ENDPOINT NETWORK THREAT INTELLIGENCE. ... based on lessons

Hvala na pažnji!