ibm qradar - atea · 2020. 3. 5. · qradar use case example a problem: healthcare data breaches...

34
IBM QRadar SIEM BENEFITS FOR COMPANY NETWORK VISIBILITY AND ANALYTICS

Upload: others

Post on 05-Mar-2021

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

IBM QRadarSIEM BENEFITS FOR COMPANY NETWORK VISIBILITY AND ANALYTICS

Page 2: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

Which picture scares you more?

Page 3: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

Do you remember this?

Page 4: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

Time to identify and contain a breach

279 daysPonemon, 2019

Page 5: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

Fear not! We have Qradar!

Security Information and Event Management

It is a system that uses EVENTS to find this…

Page 6: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

IT world vs. OT world

Page 7: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

How big a problem is OT?

There will be 75 000 000 000 inteligent devices in 2025

Page 8: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

Coffee break

Page 9: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

Are your printers secure?

Page 10: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

Are your phones secure?

Page 11: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

How about air-condition?

In 2013, hackers managed to get the credit card details of 41 million shoppers by targeting the air

conditioning system of the retail giant Target.

Page 12: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

And your coffee machines?

Professional Security Magazine Online, 2019

Page 13: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

In which industry data breach costs most?

6.45 million

in healthcarePonemon, 2019

Why?

Page 14: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

QRadar use case example

A problem:

Healthcare data breaches

Root cause of a problem:

DICOM

Fix it:

With Qradar IT IS SIMPLE

ProPublica, 2019

Page 15: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

DICOM

Digital Imaging and Communications in Medicine

Developed in 1985

“With MedTouch, a one-stop solution

provides you with a smarter way to

control the ultrasound device, access

patient data and inbuilt tutorial software

via your android operated smart device.”

Mindray Offical Website

https://morphuslabs.com/how-i-got-into-hacking-ultrasound-machines-part-01-432fce2e3ca7

Page 16: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

DICOM problem 1

Do we know all the devices?

Page 17: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

What is SIEM

It is a system that uses events and FLOWS to find this…

Page 18: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

DICOM problem 2

Data exfiltration

Page 19: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

DICOM problem 3

Credentials sharing

Page 20: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

DICOM problem 4

Password eavesdropping

Page 21: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

Ransomware against healthcare

Ready to use rules packages for QRadar

Page 22: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

What is SIEM

It is a system that uses events, flows and THREAT INTELLIGENCE to find this…

Page 23: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

Threat Intelligence

Log

sourcesLogs QRadar

Flow

sourcesFlows

X-Force

Feeds

Page 24: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

What is SIEM

It is a system that uses events, flows, threat intelligence and VULNERABILITIES to find this…

Page 25: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

QRadar Vulnerability Manager + QRadar Risk Manager

Page 26: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

Why QRadar?

Fast start!

More than 350 OOTB rules

(to use and to learn)

All you need to do is to configure event acquisition

Automatic log source creation

Page 27: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

How many integrations QRadar has?

Page 28: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

What is my application is not supported?

You can create your own parser

In DSM Editor

Page 29: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

Of course, we may be biased…

Page 30: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

Do not believe me! Try it!

Fully functional SIEM – QRadar Community Edition

50 EPS

5000 FPM

Page 31: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

Do I really need SIEM?

Page 32: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

Do I really need SIEM?

Maybe my SOC team will be enough?

1 offense per 9 000 000 events

And this is what I call…

Page 33: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019

Do I really need SIEM?

Page 34: IBM QRadar - ATEA · 2020. 3. 5. · QRadar use case example A problem: Healthcare data breaches Root cause of a problem: DICOM Fix it: With Qradar IT IS SIMPLE ProPublica, 2019