Cyber Resilient Infrastructure: Detect, Protect, and Mitigate Threats Against Brocade SAN FOS with IBM QRadar Cyber Resilient Infrastructure: Detect, Protect, and Mitigate Threats Against Brocade SAN FOS with IBM QRadar

Cyber Resilient Infrastructure: Detect, Protect, and Mitigate Threats Against Brocade SAN FOS with IBM QRadar

وصف الناشر

Enterprise networks are large and rely on numerous connected endpoints to ensure smooth operational efficiency. However, they also present a challenge from a security perspective.

The focus of this Blueprint is to demonstrate an early threat detection against the network fabric that is powered by Brocade that uses IBM® QRadar®. It also protects the same if a cyberattack or an internal threat by rouge user within the organization occurs.

The publication also describes how to configure the syslog that is forwarding on Brocade SAN FOS. Finally, it explains how the forwarded audit events are used for detecting the threat and runs the custom action to mitigate the threat.

The focus of this publication is to proactively start a cyber resilience workflow from IBM QRadar to block an IP address when multiple failed logins on Brocade switch are detected.

As part of early threat detection, a sample rule that us used by IBM QRadar is shown. A Python script that also is used as a response to block the user's IP address in the switch is provided.

Customers are encouraged to create control path or data path use cases, customized IBM QRadar rules, and custom response scripts that are best-suited to their environment.

The use cases, QRadar rules, and Python script that are presented here are templates only and cannot be used as-is in an environment.

النوع
كمبيوتر وإنترنت
تاريخ النشر
٢٠٢٢
٢ مارس
اللغة
EN
الإنجليزية
عدد الصفحات
٢٠
الناشر
IBM Redbooks
البائع
International Business Machines Corp
الحجم
٧٢٧٫٢
ك.ب.
Enhanced Cyber Resilience Threat Detection with IBM FlashSystem Safeguarded Copy and IBM QRadar Enhanced Cyber Resilience Threat Detection with IBM FlashSystem Safeguarded Copy and IBM QRadar
٢٠٢١
Cyber Resiliency with IBM QRadar and IBM Spectrum Virtualize for Public Cloud on Azure with IBM Copy Services Manager for Safeguarded Copy Cyber Resiliency with IBM QRadar and IBM Spectrum Virtualize for Public Cloud on Azure with IBM Copy Services Manager for Safeguarded Copy
٢٠٢٢
Securing Data on Threat Detection by Using IBM Spectrum Scale and IBM QRadar: An Enhanced Cyber Resiliency Solution Securing Data on Threat Detection by Using IBM Spectrum Scale and IBM QRadar: An Enhanced Cyber Resiliency Solution
٢٠٢١
Enhanced Cyber Resilience Solution by Threat Detection using IBM Cloud Object Storage System and IBM QRadar SIEM Enhanced Cyber Resilience Solution by Threat Detection using IBM Cloud Object Storage System and IBM QRadar SIEM
٢٠٢١
Proactive Early Threat Detection and Securing SQL Database With IBM QRadar and IBM Spectrum Copy Data Management Using IBM FlashSystem Safeguarded Copy Proactive Early Threat Detection and Securing SQL Database With IBM QRadar and IBM Spectrum Copy Data Management Using IBM FlashSystem Safeguarded Copy
٢٠٢٢
Early Threat Detection and Safeguarding Data with IBM QRadar and IBM Copy Services Manager on IBM DS8000 Early Threat Detection and Safeguarding Data with IBM QRadar and IBM Copy Services Manager on IBM DS8000
٢٠٢٢
Enhanced Cyber Resilience Solution by Threat Detection using IBM Cloud Object Storage System and IBM QRadar SIEM Enhanced Cyber Resilience Solution by Threat Detection using IBM Cloud Object Storage System and IBM QRadar SIEM
٢٠٢١
A Hybrid Cloud Cyber Security Solution using IBM Spectrum Virtualize for Public Cloud on Azure and IBM Spectrum Virtualize Safeguarded Copy A Hybrid Cloud Cyber Security Solution using IBM Spectrum Virtualize for Public Cloud on Azure and IBM Spectrum Virtualize Safeguarded Copy
٢٠٢٢
IBM Storage Solutions for IBM Cloud Private Blueprint IBM Storage Solutions for IBM Cloud Private Blueprint
٢٠١٩
Business Continuity Orchestration for IBM FlashSystem Hybrid Cloud with Red Hat Ansible V1R2 Business Continuity Orchestration for IBM FlashSystem Hybrid Cloud with Red Hat Ansible V1R2
٢٠٢١
Enhanced Cyber Resilience Threat Detection with IBM FlashSystem Safeguarded Copy and IBM QRadar Enhanced Cyber Resilience Threat Detection with IBM FlashSystem Safeguarded Copy and IBM QRadar
٢٠٢١
C.A.I.T.: Cyber Automated Intergrated Technology C.A.I.T.: Cyber Automated Intergrated Technology
٢٠١٨
Challenges in Cybersecurity and Privacy - the European Research Landscape Challenges in Cybersecurity and Privacy - the European Research Landscape
٢٠٢٢
Taxmann's Cyber Crimes & Laws -  4th Edition Taxmann's Cyber Crimes & Laws -  4th Edition
٢٠٢١
Rational Cybersecurity for Business Rational Cybersecurity for Business
٢٠٢٠
Cyber Security Cyber Security
٢٠٢٢
Cyber-Terrorism Cyber-Terrorism
٢٠١٤