New software helps security managers monitor IT network usage and defend against external attacks.
The security threats against business-technology systems continue to multiply. Not only do malicious worms and viruses such as Blaster and Bagle continue to wreak havoc, but security pros also must continuously monitor employee network usage for potential policy violations as well as enforce regulations such as the Health Insurance Portability and Accountability Act.
This week security vendor Q1 Labs Inc. enhanced its QRadar application, which monitors users, systems, and applications to spot abnormal and potentially malicious activity. The company also unveiled its QRadar-ICX module, which works with QRadar to stop worms, denial-of-service attacks, and other threats.
Robert Brown, director of information security, privacy, and HIPAA compliance for Borgess Health Alliance Inc., which operates more than 140 patient-care sites and 65 satellite clinics in southern Michigan, says such attacks are increasingly threatening and getting faster. "The time from when a vulnerability is announced to an attack is getting faster, and viruses beat antivirus software updates. We check for new updates every half-hour and we can still be vulnerable," he says.
Borgess has been using QRadar for about eight months, and Brown says he welcomes the QRadar-ICX enhancements. "Anything that can help you make faster decisions" is welcome, he says.
Some of the defensive enhancements QRadar-ICX provides are the ability to isolate and contain infected systems, preventing them from infecting other systems connected to the network. The module can also shut down specific user and application sessions that are being used as part of an attack or that violate a company's security policy. QRadar-ICX can also direct routers and firewalls to help shut down attacks coming from the Internet.
"We're currently evaluating these capabilities," Brown says. "It will be awhile before we feel comfortable using some of the automated response capabilities," he adds, fearing that legitimate applications or users could be accidentally blocked by the application.
But Brown is certain that as the speed and efficiency of attacks increase, security technologies will have to keep pace and get increasingly faster as well. "We're at the point were you can no longer rely on human responses to threats," he says.
QRadar 4.0 and QRadar-ICX are both available now. QRadar 4.0 is priced starting at $59,900, and pricing for QRadar-ICX starts at $19,900.
How Enterprises Are Attacking the IT Security EnterpriseTo learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Infographic: The State of DevOps in 2017Is DevOps helping organizations reduce costs and time-to-market for software releases? What's getting in the way of DevOps adoption? Find out in this InformationWeek and Interop ITX infographic on the state of DevOps in 2017.
Digital Transformation Myths & TruthsTransformation is on every IT organization's to-do list, but effectively transforming IT means a major shift in technology as well as business models and culture. In this IT Trend Report, we examine some of the misconceptions of digital transformation and look at steps you can take to succeed technically and culturally.