IBM Security QRadar SIEM Implementation for a Bank in the Gulf Cooperation Council
Summary
An international Gulf bank had deployed IBM Security QRadar SIEM with its own IT team and wanted independent specialists to verify and properly tune the installation. INNERLUXES reviewed the deployment, fixed its weaknesses, applied security patches, built a 97-object network hierarchy, created custom log source extensions for the bank's specific applications, and added proprietary health-check monitoring — then continued remotely to finalize tuning, documentation, and support, ensuring solid protection across the bank's network and the safety of its clients' data.
About the Customer
The Customer is an international bank headquartered in the Gulf Cooperation Council with operation centers in EMEA. It provides comprehensive banking services to retail and corporate clients across more than 120 branches in different countries of the region, with total assets of more than 11 billion US dollars as of the end of 2015.
An In-House QRadar Deployment That Needed Independent Tuning
To protect its IT network from external and internal threats, the Customer had acquired IBM Security QRadar SIEM and deployed it with its in-house IT specialists. To verify that the solution worked properly, the Customer wanted a deployment review by third-party SIEM specialists, along with QRadar tuning — creating a network hierarchy, configuring out-of-the-box features, setting standard device support modules (DSMs), and developing custom log source extensions (LSXs) to stay resistant to threats.
Deployment Review, Tuning, and Custom Log-Source Support
INNERLUXES's SIEM experts began on site by reviewing the QRadar deployment the Customer's IT department had carried out, which surfaced weaknesses to fix:
- Deployment fixes — updated the distributed QRadar installation, compiled the network hierarchy, and resolved an auto-updates issue.
- Stability and security — installed patches to fix security vulnerabilities and scheduled updates for protocols and DSMs, and grouped internal log sources so they are easy to manage.
- Custom log source extensions — created custom LSXs, including sample-data investigation, event parsing, and mapping, to give visibility into the bank's specific applications.
- Network hierarchy — built 97 hierarchical objects with backups of the entire hierarchy and prepared a network-hierarchy framework shared with the Customer.
- Appliance checks and dashboards — checked all appliances for errors and synced them with the QRadar Console, and developed search and dashboard elements to display unrecognized events.
- Health-check monitoring — installed and tested INNERLUXES's proprietary health-check tool for periodic monitoring of statistical, performance, and behavioral metrics of a live QRadar deployment.
After the on-site work, INNERLUXES continued remotely to finalize the tuning — troubleshooting, creating additional log source extensions for unsupported devices, fine-tuning the installation, documenting all procedures and configurations, and supporting the Customer's IT and information security departments.
Reliable Protection Across the Bank's Network
- The services met the Customer's major requirements.
- A grounded analysis of the initial QRadar deployment let the team fix errors, tailor out-of-the-box features, and create custom log source extensions.
- The result is the protection the Customer's infrastructure needed and assurance for the safety of its clients' data.
Technologies and Tools
IBM Security QRadar SIEM, QRadar API, Python, Regex, PostgreSQL, Linux, Shell.