Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

Q1 Labs Releases SIEM For Social Media

QRadar 7.0 uses deep packet inspection technology for real-time monitoring of web-based malware and extends Security Information and Event Management to social media usage.

Strategic Security Survey: Global Threat, Local Pain
Strategic Security Survey: Global Threat, Local Pain
(click image for larger view and for full photo gallery)
Q1 Labs on Monday announced the release of its latest security information and event management (SIEM) product, QRadar 7.0, which now has the ability to monitor social media networks and online communication tools, including Facebook, Gmail, LinkedIn, Skype and Twitter, in real time.

QRadar uses deep packet inspection technology to watch, in real time, for the presence of web-based malware or known vulnerabilities being introduced to the network, monitor for behavior that's outside the norm, as well as to scan for data loss prevention, among other capabilities.

Q1 Labs said that the new QRadar will also be part of its Security Intelligence Operating System -- "a unified architecture for collecting, storing, analyzing and querying log, threat, vulnerability and risk related data" -- and that QRadar is due out by the end of the year.

"Companies today face the increasing challenge of keeping their networks safe from hackers that have evolved, and that are taking advantage of new avenues of attack -- such as social networking sites and applications utilized by partners, outsourcers and employees," said Sandy Bird, CTO of Q1 Labs, in a statement. "They are also faced with keeping productivity up, due to the 'always connected' mentality of employees that want to be constantly connected to their social networks."

Accordingly, the new version of QRadar extends SIEM to social networks, adding the ability to identify which users access which social networks, chart volume and patterns of usage, and inspect any content being transmitted via such services. In addition, the software can be set to automatically alert security managers when application activity, transmitted data or user behavior violates corporate policies or typical usage patterns, which may indicate that an attacker has breached the network.

Other new features in QRadar 7.0 include inventorying applications on enterprise PCs to determine whether they contain known vulnerabilities. In addition, the software can benchmark how users and applications normally behave, to detect anomalies, for example if a worker logs in at unusual times, or suddenly begins downloading excessive amounts of data from a cloud-based application, either of which could be the only indication that an account has been compromised.

Indeed, according to Gartner Group analyst Mark Nicolett, "application activity monitoring is important because application weaknesses are frequently exploited in targeted attacks, and because abnormal application activity may be the only signal of a successful breach or of fraudulent activity."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3493
PUBLISHED: 2021-04-17
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivile...
CVE-2021-3492
PUBLISHED: 2021-04-17
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (ker...
CVE-2020-2509
PUBLISHED: 2021-04-17
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later Q...
CVE-2020-36195
PUBLISHED: 2021-04-17
An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia C...
CVE-2021-29445
PUBLISHED: 2021-04-16
jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDe...