• No results found

IBM Security QRadar Risk Manager

N/A
N/A
Protected

Academic year: 2021

Share "IBM Security QRadar Risk Manager"

Copied!
6
0
0

Loading.... (view fulltext now)

Full text

(1)

IBM Security QRadar Risk

Manager

Proactively manage vulnerabilities and network device

configuration to reduce risk, improve compliance

Highlights

●● ● ●Collect network security device

configuration data to assess vulnerabilities and facilitate analysis and reporting

●● ● ●Discover configuration errors and help

remove ineffective rules to improve firewall performance

●● ● ●Depict network topology views and help

visualize current and alternative network traffic patterns

●● ● ●Identify active attack paths and high-risk

assets to help reduce risk and prioritize remediation activities

●● ● ●Support policy compliance for network

traffic, topology and vulnerability exposures

●● ● ●Improve forensics to determine offense

root cause

Log management and security information and event management (SIEM) have become trusted solutions for network and security opera-tors, enabling them to quickly detect and isolate security incidents and meet specific compliance requirements, as well as a growing number of regulatory mandates. And while the information provided by SIEM is critical for network and compliance security management efforts, it pri-marily detects exploits as they occur, rather than prioritizing what actions can be taken to prevent them from happening in the first place.

IBM® Security QRadar® Risk Manager is an integral component of a complete security intelligence solution that serves to proactively help security professionals get and stay ahead of advanced threats. The ability to correlate security device activity with IBM Security QRadar SIEM event and flow analysis yields valuable insights revealing, for example, which firewall rules are firing, which are not, and those which could be removed to improve firewall performance and security. Adding correla-tion of known asset vulnerabilities and device configuracorrela-tions—for routers, switches and intrusion detection and prevention systems—completes the risk perspective, leading to improved operational efficiencies and simpli-fied compliance reporting.

(2)

2

Automated risk management for greater

control over risk

Government regulations, industry guidelines and corporate policies all define which specific network traffic and firewall policies an organization must deploy, monitor, audit and enforce. At a high level, the security objectives are normally pretty clear. These plans exist to achieve the desired security state, but the devil is—as usual—in the details.

Many network attacks succeed simply due to inconsistent net-work and security configuration practices, highlighting the need for automated network configuration monitoring and alerts for policy breaches. Using traditional log management and SIEM solutions, where data typically exists in separate silos, organiza-tions often lack the ability to easily assess when a network configuration allows traffic that is “out of policy.”

QRadar Risk Manager offers an integrated approach to greatly improve organizations’ abilities to assess information security risk through a single console shared with QRadar SIEM. QRadar Risk Manager leverages the broadest range of risk indi-cators, including network and security configuration data, network activity data, network and security events, and vulnera-bility scan results. It also provides other key capabilities that include:

Network security configuration

●● ●Detailed configuration audit: Helps improve consistency of firewall rules, including detection of shadowed rules and other configuration errors

●● ●Security-focused network topology model: Enables auto-mated monitoring of configuration rules

●● ●Configuration change comparison and auditing: Alerts users to risky or out-of-compliance configurations

(3)

Network activity monitoring

●● ●Advanced monitoring and analysis of network activity: Quickly flags out-of-policy traffic

●● ●Fast and efficient search of network activity: Greatly reduces forensics efforts

●● ●Intuitive visualization tool: Provides interactive analysis of current and historical network activity

Network security event and configuration correlation

●● ●Analyses of firewall accept and deny events: Assesses rule effectiveness

●● ●Scheduled or on-demand collection of device

configura-tion data: Ensures timely, historical record of configuraconfigura-tion

●● ●Advanced asset database correlation: Leverages informa-tion from a wide variety of network and security events and configuration sources, improving accuracy of results

Vulnerability scan results

●● ●Correlation of known vulnerabilities with network

topol-ogy: Helps deliver a prioritized list of vulnerabilities to better

assess which systems are most vulnerable to attack and should be remediated first

●● ●Advanced threat modeling, simulation and visualization: Provides before, during and after assessment of network risks

Vulnerabilities represent the various types

of weaknesses that can be exploited by a

threat. While an analysis of information

system vulnerabilities reveals a variety

of potential causes, many vulnerabilities

can be traced to software flaws and

misconfigurations of information system

components.

1

Policy monitoring to improve compliance

QRadar Risk Manager features an automated policy engine that simplifies the assessment of a wide spectrum of information security and compliance policies. With an intuitive question-based interface, the policy engine integrates previously separate indicators of risk through regular monitoring of network assets for defined conditions. For example, the solution enables the correlation of communications that have occurred with possible communications based on firewall and router rules, and actual firewall rule device tests.

(4)

4

The Policy Monitor feature allows active evaluation of multiple security policies. QRadar Risk Manager provides out-of-the-box policy templates to assist with identifying risk across regula-tory mandates and information security best practices. These templates are easily extended to align with an organization’s internal information security policies, and as exceptions are discovered, QRadar Risk Manager can send email, display noti-fications, generate a syslog event or create an offense within QRadar SIEM. In addition, compliance reports include both policy exceptions and successes.

Device configuration management to

detect changes and profile future risks

QRadar Risk Manager provides automated collection, monitor-ing and auditmonitor-ing of device configurations across an organiza-tion’s switches, routers, firewalls and intrusion detection system (IDS)/intrusion prevention system (IPS) devices. Through an ability to normalize cross-vendor device configuration data, QRadar Risk Manager provides detailed comparisons across security devices—including firewall rules and policies—to quickly identify when network traffic is inconsistent with a reg-ulation, corporate mandate or industry best practice.

QRadar Risk Manager maintains a history of configuration changes and enables users to audit this history across a multi-vendor network. This powerful capability allows users to com-pare normalized or raw device configurations, over time, from a single device or from different devices through a single user interface.

The collection of device configuration data is also instrumental in building an enterprise-wide representation of a network’s topology. Topology mapping can help an organization under-stand allowed and denied activity across the entire network, resulting in improved consistency of device configuration.

Modeling and simulation of attacks to

prioritize remediation efforts

With modeling and simulation, QRadar Risk Manager helps organizations identify and prioritize their most significant risk areas. Simulation can help organizations quickly understand the risk impact of proposed changes to a network’s configuration before the changes are implemented. For example, vulnerability results reported from any leading vulnerability scanning solu-tion can be combined with network topology maps to provide a prioritized list of the most vulnerable systems by determining which are at the highest risk of exploit.

This prioritized list identifies vulnerable assets at highest risk due to active network attack paths, resulting in improved opera-tional efficiency and reduced security risk.

(5)

Advanced tools to investigate network

topologies, traffic and forensics

QRadar Risk Manager offers two network visualization security tools that provide unique, risk-focused, graphical representa-tions of the network. The end result of both of these visualiza-tions offers network and security teams a revolutionary investigative capacity by providing vulnerability information before, during and after an exploit. The first visualization tool, called the Topology Viewer, delivers detailed views into the net-work configuration from a routing and firewall configuration perspective. This insight comes from a unique combination of data sources, including device configuration, network activity data and security events.

The second visualization tool, called the Connection Monitor, quickly and efficiently analyzes historical network activity by automatically summarizing all network event and flow data on

searches, including the ability to search on connections between hosts and networks using specific protocols and applications, as well as analyzing traffic to and from specific countries or geo-graphical regions.

Security intelligence to minimize risk

QRadar Risk Manager provides organizations with a compre-hensive network security solution that not only enables them to access forensics during and after an attack, but also enables them to proactively detect, prioritize and remediate areas of high risk before they can be exploited.

The powerful security analytics, simulation and visualization of QRadar Risk Manager provide a unique opportunity for organi-zations to move away from day-to-day security “firefighting” and to adopt a proactive, risk-based methodology that greatly strengthens network and security offenses while minimizing exploit risk.

Log management and SIEM are necessary for a good network defense. By adding QRadar Risk Manager, organizations gain additional security intelligence enabling them to go on the offensive against those who wish to harm their networks.

Why IBM?

IBM operates the world’s broadest security research, develop-ment and delivery organization. This comprises 10 security operations centers, nine IBM Research centers, 11 software security development labs and an Institute for Advanced Security with chapters in the United States, Europe and Asia Pacific. IBM solutions empower organizations to reduce their security vulnerabilities and focus more on the success of their strategic initiatives. These products build on the threat intelli-gence expertise of the IBM X-Force® research and develop-ment team to provide a preemptive approach to security. As a trusted partner in security, IBM delivers the solutions to keep the entire enterprise infrastructure, including the cloud, protected from the latest security risks.

(6)

Additionally, IBM Global Financing can help you acquire the software capabilities that your business needs in the most cost-effective and strategic way possible. We’ll partner with credit-qualified clients to customize a financing solution to suit your business and development goals, enable effective cash management, and improve your total cost of ownership. Fund your critical IT investment and propel your business forward with IBM Global Financing. For more information, visit:

ibm.com/financing © Copyright IBM Corporation 2013 IBM Corporation Software Group Route 100 Somers, NY 10589

Produced in the United States of America January 2013

IBM, the IBM logo, ibm.com, QRadar, and X-Force are trademarks of International Business Machines Corp., registered in many jurisdictions worldwide. Other product and service names might be trademarks of IBM or other companies. A current list of IBM trademarks is available on the web at “Copyright and trademark information” at

ibm.com/legal/copytrade.shtml

This document is current as of the initial date of publication and may be changed by IBM at any time. Not all offerings are available in every country in which IBM operates.

THE INFORMATION IN THIS DOCUMENT IS PROVIDED “AS IS” WITHOUT ANY WARRANTY, EXPRESS OR IMPLIED, INCLUDING WITHOUT ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND ANY WARRANTY OR CONDITION OF NON-INFRINGEMENT. IBM products are warranted according to the terms and conditions of the agreements under which they are provided. The client is responsible for ensuring compliance with laws and regulations

applicable to it. IBM does not provide legal advice or represent or warrant that its services or products will ensure that the client is in compliance with any law or regulation.

IT system security involves protecting systems and information through prevention, detection and response to improper access from within and outside your enterprise. Improper access can result in information being altered, destroyed or misappropriated or can result in damage to or misuse of your systems, including to attack others. No IT system or product should be considered completely secure and no single product or security measure can be completely effective in preventing improper access. IBM systems and products are designed to be part of a comprehensive security approach, which will necessarily involve additional operational procedures, and may require other systems, products or services to be most effective. IBM does not warrant that systems and products are immune from the malicious or illegal conduct of any party.

1NIST Special Publication 800-128: Guide for Security-Focused

Configuration Management of Information Systems Please Recycle

References

Related documents