Risk
9/27/2010
09:25 PM
Connect Directly
RSS
E-Mail
50%
50%

Q1 Labs Releases SIEM For Social Media

QRadar 7.0 uses deep packet inspection technology for real-time monitoring of web-based malware and extends Security Information and Event Management to social media usage.

Strategic Security Survey: Global Threat, Local Pain
Strategic Security Survey: Global Threat, Local Pain
(click image for larger view and for full photo gallery)
Q1 Labs on Monday announced the release of its latest security information and event management (SIEM) product, QRadar 7.0, which now has the ability to monitor social media networks and online communication tools, including Facebook, Gmail, LinkedIn, Skype and Twitter, in real time.

QRadar uses deep packet inspection technology to watch, in real time, for the presence of web-based malware or known vulnerabilities being introduced to the network, monitor for behavior that's outside the norm, as well as to scan for data loss prevention, among other capabilities.

Q1 Labs said that the new QRadar will also be part of its Security Intelligence Operating System -- "a unified architecture for collecting, storing, analyzing and querying log, threat, vulnerability and risk related data" -- and that QRadar is due out by the end of the year.

"Companies today face the increasing challenge of keeping their networks safe from hackers that have evolved, and that are taking advantage of new avenues of attack -- such as social networking sites and applications utilized by partners, outsourcers and employees," said Sandy Bird, CTO of Q1 Labs, in a statement. "They are also faced with keeping productivity up, due to the 'always connected' mentality of employees that want to be constantly connected to their social networks."

Accordingly, the new version of QRadar extends SIEM to social networks, adding the ability to identify which users access which social networks, chart volume and patterns of usage, and inspect any content being transmitted via such services. In addition, the software can be set to automatically alert security managers when application activity, transmitted data or user behavior violates corporate policies or typical usage patterns, which may indicate that an attacker has breached the network.

Other new features in QRadar 7.0 include inventorying applications on enterprise PCs to determine whether they contain known vulnerabilities. In addition, the software can benchmark how users and applications normally behave, to detect anomalies, for example if a worker logs in at unusual times, or suddenly begins downloading excessive amounts of data from a cloud-based application, either of which could be the only indication that an account has been compromised.

Indeed, according to Gartner Group analyst Mark Nicolett, "application activity monitoring is important because application weaknesses are frequently exploited in targeted attacks, and because abnormal application activity may be the only signal of a successful breach or of fraudulent activity."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2363
Published: 2014-07-26
Morpho Itemiser 3 8.17 has hardcoded administrative credentials, which makes it easier for remote attackers to obtain access via a login request.

CVE-2014-3071
Published: 2014-07-26
Cross-site scripting (XSS) vulnerability in the Data Quality Console in IBM InfoSphere Information Server 11.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL for adding a project connection.

CVE-2014-3301
Published: 2014-07-26
The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned messages, aka Bug ID CSCuj81700.

CVE-2014-3305
Published: 2014-07-26
Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCuj81735.

CVE-2014-3324
Published: 2014-07-26
Multiple cross-site scripting (XSS) vulnerabilities in the login page in the administrative web interface in Cisco TelePresence Server Software 4.0(2.8) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCup90060.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Sara Peters hosts a conversation on Botnets and those who fight them.