IBM Security QRadar SIEM Implementation for an Asian Bank
Summary
Facing a rise in cyber-attacks, an Asian bank decided to deploy a SIEM platform to give its information-security team a single, real-time view of the bank's network. INNERLUXES won the contract and, in one month, installed and customized an IBM Security QRadar SIEM at 2,500 events per second — integrating the bank's log sources, building custom parsers and correlation rules, adding malware and botnet protection, and delivering PCI compliance reporting with resilient three-month data retention.
About the Client
The Client is an Asian bank with more than 3 million customers and over 1.7 billion US dollars in assets.
Rising Cyber-Attacks Called for a Bird's-Eye View of the Bank's Network
Acknowledging a considerable rise in cyber-attacks, the Client decided to install a SIEM system — IBM Security QRadar SIEM — to give its information-security administrators a bird's-eye view of the bank's network. To raise overall network security, the Client defined a set of functional subsystems to add to QRadar: data collection, processing, storage, analysis, reporting, search, self-diagnostics, and visual display. The bank put the QRadar deployment and configuration work out to contract, and INNERLUXES won it.
A Customized QRadar Deployment Integrating the Bank's Full Estate
In line with the scope of work, a senior INNERLUXES SIEM consultant delivered the following:
- Installed an out-of-the-box IBM Security QRadar SIEM at 2,500 EPS (events per second) and fine-tuned it to the Client's network environment.
- Integrated the bank's log sources, including Microsoft Windows Active Directory, IIS, Exchange and Terminal Services, Linux RHEL servers, DNS/DHCP, antivirus, database, and proxy servers, firewalls, switches, ESX, and SWIFT, with out-of-the-box parsers configured for them.
- Developed 3 custom Device Support Modules (DSMs) to parse events from an HP core switch, a 3Com VPN, and Tipping Point SMS.
- Connected the IBM X-Force reputational feed for malware and botnet protection, enabling QRadar to identify communications with known malicious hosts.
- Implemented 30 custom-tailored correlation rules.
- Delivered on-site custom training for the bank's security team.
A 24/7 SIEM With Malware Protection, PCI Reporting, and Resilient Retention
The month-long deployment ended with a series of quality-assurance tests, after which the customized QRadar solution went into operation. The Client received a robust SIEM with enhanced malware and botnet protection and the ability to produce a PCI compliance report. Running 24/7 in real time, the solution gives the bank's information-security team three months of data storage; in the event of an emergency outage, all information is retained and can be restored once the system is back online. INNERLUXES also provided an operational instruction for the SIEM system and will render maintenance support on request.
Technologies and Tools
IBM Security QRadar SIEM v7.2.8, Python, SQL, AQL, Regex, Linux Shell, Windows.