- 10 open source companies to watch
- Mythbuster busts his own tale
- $208 million petascale computer gets green light
- Sony recalls 73,000 Vaio laptops
- Chrome and Firefox and add-ons
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
When network managers are tracking down the source of a security breach, the search often stops cold at the IP address
For instance, a remote user logging on to the network via a VPN connection could have been assigned the same IP address that a traveling user had tapped earlier in the day. After learning the IP address on which the event occurred, the network manager would have to check Windows logs or other identity databases manually to determine which user had been using that IP address at the time of the breach.
That's why Q1 Labs next week is making available an updated version of its QRadar network- and security-management product that relates user identities to specific network and security events and speeds the process of pinpointing the source of a policy, compliance or security breach.
QRadar, which is packaged as an appliance, monitors network flow data and collects events from network and security devices. Now the product relates user identity data from RADIUS and Active Directory servers and from firewalls to IP addresses and security events. The product maps the user identity to asset profiles in numerous ways, including host name to IP address; DNS to IP; group name; user name to IP; media-access-control (MAC) address to IP; and switch port, switch and location.
"This will let network managers not only see the IP address associated with the threat, but also the user ID associated with that IP address and at the time of the threat. QRadar can also keep a history of who that user is and past threats or events associated with the user," says Tom Turner, vice president of marketing at Q1 Labs. "The goal is to answer the questions, 'Who is attacking my network?' or 'Who is out of compliance?' without having to do additional manual forensics."
Turner says QRadar combines network behavior-analysis features with security event management (SEM) capabilities and user identity tracking, making it prime competition for Cisco's MARS (Monitoring Analysis and Response System) product. Q1 Labs also competes with SEM vendor ArcSight and Arbor Networks in the network behavior-analysis market.
Also in this release the company added a bit of network access control (NAC) technology to integrate with customers' NAC efforts. By conforming with Trusted Computing Group's Trusted Network Connect open standards, QRadar performs postadmission monitoring of user IDs on the network and alerts a policy server or gateway, such as Juniper Networks' Infranet Controller, to the policy-violating behavior. From there, policy creators and enforcers may decide to update the user profile or employ stricter enforcement policies.

Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses...
Vulnerability Management For DummiesDownload this concise book "Vulnerability Management for Dummies," to learn about the simple steps...
The ROI and TCO Benefits of Data Deduplication for Data Protection in the EnterpriseThis paper examines and quantifies the costs and benefits of backup with deduplication storage as...

Life on the edge of your WAN has changed dramatically. With the need to deliver advanced services,...
PoE Plus: Impact on the PoE MarketThe standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...
Harnessing the power of communications to increase workplace performanceDue to the convergence of IT and telecommunications technologies, the business workplace has been...

We have so many holes punched in our firewalls today that many industry insiders question the value...
The self-managed networkWe aren't there yet, but advances in network and systems management tools are making it possible to...
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment