IBM Security QRadar

 View Only
  • 1.  Distributed Brute-Force Attacks

    Posted Mon October 07, 2019 11:37 AM
    Does QRadar help in detecting distributed brute-force (password guessing) attacks?

    ------------------------------
    Gokul Kannan Sadasivam
    ------------------------------


  • 2.  RE: Distributed Brute-Force Attacks

    Posted Wed October 23, 2019 05:02 AM
    Yes QRadar have tons of plugins and Enhanced Solutions , in which UBA(User Behavior Analytics) comes with lot of use-case which automatically triggers the Password-Guess and lot more stuffs.
    For more Info regarding UBA and detection of Brute-Force please find below link;
    https://www.ibm.com/support/knowledgecenter/en/SSKMKU/com.ibm.UBAapp.doc/c_Qapps_UBA_rules_BruteforceAuthenticationAttempts.html
    https://is.muni.cz/th/98724/fi_d/thesis.pdf

    ------------------------------
    Pranav Sankar
    ------------------------------



  • 3.  RE: Distributed Brute-Force Attacks

    Posted Wed January 15, 2020 02:24 AM
    Heyy Gokul,

    * Can you please tell what "Default senseValue: 5" means in the URL that you mentioned 
    https://www.ibm.com/support/knowledgecenter/en/SSKMKU/com.ibm.UBAapp.doc/c_Qapps_UBA_rules_BruteforceAuthenticationAttempts.html
    Ans: - Please refer below link and let me know its been cleared.

    https://www.ibm.com/support/knowledgecenter/en/SSKMKU/com.ibm.qradar.doc/c_qradar_adm_sense.html

    ------------------------------
    Pranav Sankar
    ------------------------------



  • 4.  RE: Distributed Brute-Force Attacks

    Posted Thu January 16, 2020 02:14 AM
    Sir,

    Thanks for the link. I have gone through it completely and gained useful information.

    Assume two servers in the DMZ network. The two servers are accessible from the Internet and also from the internal machines. How to configure QRadar to read the login failures of both the servers and take a decision based on it?

    For example, user1 has a failed login to server1 and after a while, user1 has another failed login attempt to server2. Now I want QRadar to raise the risk score. How to achieve this?

    Regards,
    Gokul