Download presentation
Presentation is loading. Please wait.
Published byFelicity Walker Modified over 9 years ago
1
© 2012 IBM Corporation IBM Security Systems 1 © 2014 IBM Corporation IBM Security Network Protection (XGS) Integration Framework: QRadar 7.2 MR1
2
© 2014 IBM Corporation IBM Security Systems 2 QRadar There are four supported cases: – Compromise: If the source IP is "right clicked" this IP address is sent to the XGS. This might be used in the case when the host has been infected with malware. – Reputation: If the destination IP is “right-clicked” this IP address is sent to the XGS. This represents a malicious server such as a C&C server or one hosting Malware. – Intrusion: If a source port is “right-clicked” this IP address and port combination is sent to the XGS. This can result from that client system attacking a server. – Exposure: If the destination port is "right clicked" this IP address and port combination is sent to the XGS. This might be used in the case where the service has a vulnerability.
3
© 2014 IBM Corporation IBM Security Systems 3 QRadar “right click” Integration (source address) “on the glass” integration
4
© 2014 IBM Corporation IBM Security Systems 4 QRadar “right click” Integration (source address)
5
© 2014 IBM Corporation IBM Security Systems 5 QRadar Advanced Threat Events
6
© 2014 IBM Corporation IBM Security Systems 6 QRadar 'right click' Integration (destination port) “on the glass” integration
7
© 2014 IBM Corporation IBM Security Systems 7 QRadar 'right click' Integration (destination port)
8
© 2014 IBM Corporation IBM Security Systems 8 QRadar Advanced Threat Events
9
© 2014 IBM Corporation IBM Security Systems 9 ibm.com/security
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.