<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Solving puzzles and mysteries</title>
	<link>http://gsandahl.net/2007/05/24/206/</link>
	<description>Random rants on Defensive Security</description>
	<pubDate>Fri, 21 Nov 2008 23:39:06 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.2</generator>

	<item>
		<title>By: goran</title>
		<link>http://gsandahl.net/2007/05/24/206/#comment-5246</link>
		<author>goran</author>
		<pubDate>Fri, 25 May 2007 11:21:53 +0000</pubDate>
		<guid>http://gsandahl.net/2007/05/24/206/#comment-5246</guid>
		<description>QRadar is a great product, which I have tested rather extensively in lab environement. In contrast with other similar products, our results indicated that its built in correlation engine is very accurate. 

However, all this boils down to the quality of the log sources of course. But having a fine tuned IDS/IPS, a firewall log, service logs etc allows the device to very accurately detect and describe attack patterns. I'll say most of the fine tuning would still be necessary on the IDS/IPS. And as with any product that can base-line, its a matter of it getting to know the environent and baseline. 

It has also a built in NBAD feature, where it can do traffic anomaly detection using for instance netflow data. That is a feature most SIEM-products doesn't have, yet. 

I plan to blog about QRadar sometime in the future.</description>
		<content:encoded><![CDATA[<p>QRadar is a great product, which I have tested rather extensively in lab environement. In contrast with other similar products, our results indicated that its built in correlation engine is very accurate. </p>
<p>However, all this boils down to the quality of the log sources of course. But having a fine tuned IDS/IPS, a firewall log, service logs etc allows the device to very accurately detect and describe attack patterns. I&#8217;ll say most of the fine tuning would still be necessary on the IDS/IPS. And as with any product that can base-line, its a matter of it getting to know the environent and baseline. </p>
<p>It has also a built in NBAD feature, where it can do traffic anomaly detection using for instance netflow data. That is a feature most SIEM-products doesn&#8217;t have, yet. </p>
<p>I plan to blog about QRadar sometime in the future.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tomas</title>
		<link>http://gsandahl.net/2007/05/24/206/#comment-5235</link>
		<author>Tomas</author>
		<pubDate>Fri, 25 May 2007 08:16:56 +0000</pubDate>
		<guid>http://gsandahl.net/2007/05/24/206/#comment-5235</guid>
		<description>Göran, how easy is actually the "doctor-like" product from http://www.q1labs.com to use? From their product page it seams just to plug it in and it almost automatically works but since I am skeptical I think it require a lot of fine tuning as any other product. Maybe it needs less...?</description>
		<content:encoded><![CDATA[<p>Göran, how easy is actually the &#8220;doctor-like&#8221; product from <a href="http://www.q1labs.com" rel="nofollow">http://www.q1labs.com</a> to use? From their product page it seams just to plug it in and it almost automatically works but since I am skeptical I think it require a lot of fine tuning as any other product. Maybe it needs less&#8230;?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
