Risk
9/27/2010
09:25 PM
Connect Directly
RSS
E-Mail
50%
50%

Q1 Labs Releases SIEM For Social Media

QRadar 7.0 uses deep packet inspection technology for real-time monitoring of web-based malware and extends Security Information and Event Management to social media usage.

Strategic Security Survey: Global Threat, Local Pain
Strategic Security Survey: Global Threat, Local Pain
(click image for larger view and for full photo gallery)
Q1 Labs on Monday announced the release of its latest security information and event management (SIEM) product, QRadar 7.0, which now has the ability to monitor social media networks and online communication tools, including Facebook, Gmail, LinkedIn, Skype and Twitter, in real time.

QRadar uses deep packet inspection technology to watch, in real time, for the presence of web-based malware or known vulnerabilities being introduced to the network, monitor for behavior that's outside the norm, as well as to scan for data loss prevention, among other capabilities.

Q1 Labs said that the new QRadar will also be part of its Security Intelligence Operating System -- "a unified architecture for collecting, storing, analyzing and querying log, threat, vulnerability and risk related data" -- and that QRadar is due out by the end of the year.

"Companies today face the increasing challenge of keeping their networks safe from hackers that have evolved, and that are taking advantage of new avenues of attack -- such as social networking sites and applications utilized by partners, outsourcers and employees," said Sandy Bird, CTO of Q1 Labs, in a statement. "They are also faced with keeping productivity up, due to the 'always connected' mentality of employees that want to be constantly connected to their social networks."

Accordingly, the new version of QRadar extends SIEM to social networks, adding the ability to identify which users access which social networks, chart volume and patterns of usage, and inspect any content being transmitted via such services. In addition, the software can be set to automatically alert security managers when application activity, transmitted data or user behavior violates corporate policies or typical usage patterns, which may indicate that an attacker has breached the network.

Other new features in QRadar 7.0 include inventorying applications on enterprise PCs to determine whether they contain known vulnerabilities. In addition, the software can benchmark how users and applications normally behave, to detect anomalies, for example if a worker logs in at unusual times, or suddenly begins downloading excessive amounts of data from a cloud-based application, either of which could be the only indication that an account has been compromised.

Indeed, according to Gartner Group analyst Mark Nicolett, "application activity monitoring is important because application weaknesses are frequently exploited in targeted attacks, and because abnormal application activity may be the only signal of a successful breach or of fraudulent activity."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2006-1318
Published: 2014-09-19
Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, which allows remote attackers to execute arbitrary code via a malformed control in an Office document, aka "Microsoft Office Control Vulnerability."

CVE-2012-2588
Published: 2014-09-19
Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, or (3) Subject header or (4) body in an SMTP e-mail message.

CVE-2012-6659
Published: 2014-09-19
Cross-site scripting (XSS) vulnerability in the admin interface in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-1391
Published: 2014-09-19
QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding.

CVE-2014-3614
Published: 2014-09-19
Unspecified vulnerability in PowerDNS Recursor (aka pdns_recursor) 3.6.x before 3.6.1 allows remote attackers to cause a denial of service (crash) via an unknown sequence of malformed packets.

Best of the Web
Dark Reading Radio