What is QRadar?

version check

IBM Security QRadar SIEM (Security Information and Event Management) is a network security management platform that provides situational awareness and compliance support.

The system uses a combination of flow-based network monitoring and compliance. QRadar also correlates security events and performs asset-based susceptibility assessments. The SIEM device alerts about suspicious activities and enables security analysts to investigate them. Importantly, while QRadar SIEM alerts designated people about suspicious activities, it does not respond automatically. It expects human input and investigation before taking any action. Thus, this prevents many false-positive alerts. For example, QRadar SIEM can detect services and confirm they are an attack target, but it does not change the configuration or shut down those services. Such automatic changes could cause unwanted system outages. Therefore, a better approach is for an administrator to create a rule that responds in an expected way to the issue. QRadar SIEM helps organizations detect attacks and policy breaches.

QRadar SIEM capabilities

The key capabilities of this top SIEM product (according to Gartner) are:

  • Scalable architecture to support the largest deployments.
  • Ability to process security data from a lot of sources, such as Firewalls, identity directories, Proxies, Applications, and routers
  • Collection, normalization, and correlation. It can also securely store raw events, network flows, or assets.
  • Layer 7 payload captures up to a configurable number of bytes from unencrypted traffic. By default, QFlow captures the first 64 bytes of unencrypted layer 7 payloads. The user interface exhibits these bytes without further decoding. Payloads from encrypted traffic are not captured.
  • Comprehensive search capabilities
  • Monitor host and network changes that could identify the attacker or show the policy breach. For example, off-hours use or employer policy-breaking use of an application. Other examples include network activity patterns that don’t match historical profiles. The SIEM can also detect suspected attacks and other policy breaches.
  • Notification by email, SNMP, and others
  • Many generic reporting templates included
  • Scalable architecture to fortify astronomically immense deployments
  • Single interface
  • Provides reliable, tamper-proof log storage for forensic investigations. QRadar SIEM keeps evidence and reduces the time gap between a security incident and its detection.
  • Provides reporting templates to meet working and compliance requirements
  • Puts security-relevant data from many sources  and in context with each other
  • Alerts of suspicious activities and policy breaches in the IT environment
  • Provides deep visibility into network and application activity
  • Identifying suspected attacks and policy breaches

QRadar SIEM usage

  • Where should the investigation be focused?
  • How is the assailant penetrating the system?
  • Is the suspected attack or policy breach authentic or a false alarm?
  • Who is attacking?
  • What is being attacked?
  • What is the security impact?
  • When are the attacks taking place?

To help SOC analysts, QRadar SIEM correlates information like:

  • The point of issue
  • Offending users
  • Origins
  • Targets
  • Vulnerabilities
  • Asset information
  • Known threats