IBM Security QRadar SIEM Implementation for a Telecom Provider

IBM Security QRadar SIEM Implementation for a Telecom Provider

Industry
Telecommunications
Technologies
QRadar

Summary

A national telecommunications provider — holding a large database of sensitive subscriber data and therefore a top target for fraud and cybercrime — decided to implement a top-notch security information system. Working through a Gulf-region IT group, the provider commissioned INNERLUXES to deploy IBM Security QRadar SIEM (hereinafter QRadar) across 6 data centers and perform high-level tuning of the solution.

About the Customer

The Customer is part of a major Information Technology group in the Gulf region, an authorized partner of major technology vendors that uses the latest, most innovative technologies in the marketplace. The end customer is a national telecommunications provider offering local and international telephone services, internet, and data communications, with a large workforce.

The Challenge

As a well-known telecommunications company with a large mobile subscriber base and a sizable workforce, the Customer possesses a large database of sensitive data and is therefore a top target for fraudulent activities (both internal fraud and cybercrime). Moreover, as a national telecommunications provider, the Customer must pay great attention to the stability of its services.

To meet these challenges, the Customer decided to implement a top-notch security information system and commissioned INNERLUXES to deploy IBM Security QRadar SIEM and perform high-level tuning of the solution. QRadar needed to be installed for 6 data centers across two cities.

The Solution

INNERLUXES's team of 2 SIEM specialists started work on the project. First, the initial installation of QRadar appliances for each data center was performed (Event Processor, Flow Processor and QFlow Collector, combined Event/Flow Processors, etc.). During the deployment stage, recent QRadar patches were downloaded, QRadar software was installed for the main-office appliances, basic system configuration was performed and documented, and the network hierarchy was created.

The team developed a set of correlation and offense rules for 12 of the Customer's platforms. In addition, threat cases were developed and implemented (for MySQL, Apache HTTP Server, etc.). These works ensured automatic, real-time analysis of the collected security events and timely detection of suspicious activities. Thanks to the adjusted event correlation, the installed solution separates true threats from false alarms (false positives).

During the QRadar integration stage, 19 network devices were connected. The team created 10 custom Log Source Extensions (LSX) to integrate the Customer's applications (e.g., Apache for Windows, FreeRADIUS, SIEBEL Audit Trail, MySQL).

The Results

  • The active stage of the project lasted three months (both onsite and offsite work).
  • All the Customer's appliances and applications were connected to QRadar using both out-of-the-box templates and customer-specific ones developed by INNERLUXES.
  • The Customer can now strengthen information security and investigate incidents in the shortest time possible.
  • The project is now in the support phase — when new security threats appear or a new system needs connecting, the system is enriched with further scenarios or new LSXs, and INNERLUXES consults on security information management.

Technologies and Tools

IBM Security QRadar SIEM 7.2.4; Python, Regex, Linux Shell.