IBM QRadar SIEM Consulting and Implementation for a US Public University

IBM QRadar SIEM Consulting and Implementation for a US Public University

Industry
Education
Technologies
QRadar

Summary

A US public university's IBM QRadar SIEM was generating an enormous number of false-positive offenses and didn't fully cover the institution's security policies. INNERLUXES audited and tuned the deployment — cutting false positives by roughly half, fixing 70 misconfigured log sources, removing 50 redundant ones, disabling resource-heavy reports, and adding correlation rules to catch brute-force attacks — then handed over a roadmap to align QRadar with the university's policies and strengthen its security operations.

About the Client

The Client is a public university in the US offering a wide range of undergraduate and graduate programs across many fields, from accounting to music and sports.

A SIEM Drowning in False Positives

The university needed to improve the performance of its IBM QRadar SIEM — in particular, to eliminate the enormous number of false-positive offenses it was producing and to ensure the SIEM properly covered the institution's security policies. It commissioned INNERLUXES to audit and then tune the solution.

Audit, Tuning, and a Roadmap

INNERLUXES's SIEM specialists ran the audit with a specialized QRadar health-assessment toolkit for quickly evaluating how the deployment was functioning. The audit surfaced several problems:

  • Several correlation rules working improperly.
  • Incorrect log-source type configuration for 70 log sources.
  • 50 redundant log sources.
  • Unnecessary reports.

1. Eliminating false positives and tuning correlation rules

To fix the "multiple login failures for a single username" rule, the team created a reference map for username-to-workstation mapping to eliminate false-positive offenses, and installed a user-friendly Reference Data Management application so the Client wouldn't have to populate that map from the CLI or API. The tuning eliminated about 50% (14 types) of false positives, sharply reducing both the number of events in offenses and the volume of certain false-positive offense types. The specialists also created and applied two further correlation rules, based on the Client's requirements, to flag brute-force attacks.

2. Fixing and trimming log sources

The team corrected the log-source type configuration for 70 log sources and removed roughly 50 sources that hadn't been seen for about two months. This cut the number of events per day and significantly improved log-data quality.

3. Disabling unnecessary reports

The specialists identified about 20 unnecessary default reports and, using the audit findings, pinpointed the four most resource-consuming. With the Client's agreement, they disabled those four to improve system performance.

4. Defining next steps for QRadar efficiency

INNERLUXES gave the Client a list of recommendations from the audit and tuning to ensure QRadar covers the university's security policies and to boost the efficiency of its security operations center (SOC):

  • Updating QRadar from 7.2.8 to 7.3.1.
  • Applying automatic offense assignment.
  • Installing and configuring QRadar Vulnerability Manager.
  • Building rules that cover the university's security policies.
  • Tracking offboarded employees and their access attempts.
  • Integrating physical access control, and more.

A Fine-Tuned SIEM and a Clear Path Forward

INNERLUXES successfully audited and tuned the Client's QRadar SIEM. The university came away with a fine-tuned system — improved log-data quality, properly configured correlation rules and log sources — plus a set of recommendations for further raising QRadar's efficiency.

Technologies and Tools

QRadar 7.2.8, a QRadar health-assessment toolkit, Linux, RegEx.