IBM QRadar SIEM Deployment and Configuration for a 4M-Subscriber Wireless Telecom Provider

IBM QRadar SIEM Deployment and Configuration for a 4M-Subscriber Wireless Telecom Provider

Industry
Telecommunications
Technologies
QRadar

Summary

A wireless telecom operator with more than four million subscribers wanted continuous monitoring and analysis of all user activity across its corporate systems as its customer base and staff grew. Having selected IBM Security QRadar SIEM, the operator engaged INNERLUXES to deploy and customize it. Over two stages, INNERLUXES designed the SIEM architecture, deployed QRadar, connected the supported log sources, and built extensive custom support for unsupported and awkward log sources — delivering a full-fledged SIEM on time and on budget.

About the Customer

The Customer is a telecommunication company with more than four million subscribers. Having started as a GSM operator on a postpaid system, it was among the first operators in the global telecommunications sector to offer a prepaid system, and it is also known for its commitment to social responsibility.

A Growing Operator That Needed Full Activity Monitoring

With a constantly growing customer base and an expanding staff, the Customer wanted permanent monitoring and analysis of all the activities of end users interacting with its corporate systems and applications. After evaluating available security information and event management (SIEM) solutions, the Customer chose IBM Security QRadar SIEM and looked for a reliable technological partner to deploy it into the existing IT environment and customize it accordingly.

A Two-Stage Deployment With Deep Custom Log-Source Support

The project ran in two stages, the first on the Customer's premises and the second remotely:

  • Architecture and deployment — in a two-week on-site stage, INNERLUXES analyzed the existing IT infrastructure and designed a detailed SIEM architecture of four components: a console, two event processors, and two flow processors. QRadar was deployed on the Customer's virtual environment and all supported log sources transmitting syslog messages were connected, after which the consultants analyzed the unsupported sources to plan universal device support modules (uDSMs) and custom log source extensions (LSXs).
  • Customization — in the remote stage, the team developed uDSMs for 10 unsupported platforms and 13 custom LSXs, delivered with XML files of event-normalization rules, shell scripts for automatic event mapping, and administrator manuals, and converted and installed the provided root SSL certificate.
  • Custom log collectors — INNERLUXES built custom software to collect logs from Microsoft Exchange (which cannot write events to log files or send them over syslog) and another custom system to upload multiline-format logs to a third-party file server.
  • Administrator training — at the final stage, INNERLUXES's SIEM experts ran specialized training for the Customer's QRadar administrators, giving them an overview of the new system and teaching the basics of developing LSXs.

A Full-Fledged SIEM, On Time and On Budget

  • Provided uDSMs for 10 unsupported log sources.
  • Developed 13 log source extensions.
  • Ensured the processing of more than 940 unique audit events by unsupported log sources.
  • Implemented 20 additional normalization fields.
  • Developed custom software for systems that could not send events to QRadar automatically and for those with a multiline event format.

The implemented solution now provides constant monitoring of user activity, consolidates log data from a multitude of sources, normalizes events instantly, and reveals connections between them, which lets the Customer distinguish real offenses from false positives.

Technologies and Tools

IBM Security QRadar SIEM v7.2.6, QRadar API, Python, PowerShell, Regex, PostgreSQL, Oracle, Linux, Windows Server, WinCollect, VMware vSphere.