Q1 Labs Enhances Security Monitoring System - InformationWeek
IoT
IoT
News
News
11/2/2004
04:38 PM
50%
50%
RELATED EVENTS
Moving UEBA Beyond the Ground Floor
Sep 20, 2017
This webinar will provide the details you need about UEBA so you can make the decisions on how bes ...Read More>>

Q1 Labs Enhances Security Monitoring System

New software helps security managers monitor IT network usage and defend against external attacks.

The security threats against business-technology systems continue to multiply. Not only do malicious worms and viruses such as Blaster and Bagle continue to wreak havoc, but security pros also must continuously monitor employee network usage for potential policy violations as well as enforce regulations such as the Health Insurance Portability and Accountability Act.

This week security vendor Q1 Labs Inc. enhanced its QRadar application, which monitors users, systems, and applications to spot abnormal and potentially malicious activity. The company also unveiled its QRadar-ICX module, which works with QRadar to stop worms, denial-of-service attacks, and other threats.

Robert Brown, director of information security, privacy, and HIPAA compliance for Borgess Health Alliance Inc., which operates more than 140 patient-care sites and 65 satellite clinics in southern Michigan, says such attacks are increasingly threatening and getting faster. "The time from when a vulnerability is announced to an attack is getting faster, and viruses beat antivirus software updates. We check for new updates every half-hour and we can still be vulnerable," he says.

Borgess has been using QRadar for about eight months, and Brown says he welcomes the QRadar-ICX enhancements. "Anything that can help you make faster decisions" is welcome, he says.

Some of the defensive enhancements QRadar-ICX provides are the ability to isolate and contain infected systems, preventing them from infecting other systems connected to the network. The module can also shut down specific user and application sessions that are being used as part of an attack or that violate a company's security policy. QRadar-ICX can also direct routers and firewalls to help shut down attacks coming from the Internet.

"We're currently evaluating these capabilities," Brown says. "It will be awhile before we feel comfortable using some of the automated response capabilities," he adds, fearing that legitimate applications or users could be accidentally blocked by the application.

But Brown is certain that as the speed and efficiency of attacks increase, security technologies will have to keep pace and get increasingly faster as well. "We're at the point were you can no longer rely on human responses to threats," he says.

QRadar 4.0 and QRadar-ICX are both available now. QRadar 4.0 is priced starting at $59,900, and pricing for QRadar-ICX starts at $19,900.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
How Enterprises Are Attacking the IT Security Enterprise
How Enterprises Are Attacking the IT Security Enterprise
To learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Register for InformationWeek Newsletters
White Papers
Current Issue
IT Strategies to Conquer the Cloud
Chances are your organization is adopting cloud computing in one way or another -- or in multiple ways. Understanding the skills you need and how cloud affects IT operations and networking will help you adapt.
Video
Slideshows
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll