Building a Next-Gen SOC with IBM QRadar: Accelerate your security operations and detect cyber threats effectively
暫譯: 使用 IBM QRadar 建立下一代安全運營中心:加速您的安全操作並有效檢測網路威脅
Kothekar, Ashish M.
- 出版商: Packt Publishing
- 出版日期: 2023-06-28
- 售價: $1,880
- 貴賓價: 9.5 折 $1,786
- 語言: 英文
- 頁數: 198
- 裝訂: Quality Paper - also called trade paper
- ISBN: 1801076022
- ISBN-13: 9781801076029
-
相關分類:
資訊安全
海外代購書籍(需單獨結帳)
商品描述
Discover how different QRadar components fit together and explore its features and implementations based on your platform and environment
Purchase of the print or Kindle book includes a free PDF eBook
Key Features:
- Get to grips with QRadar architecture, components, features, and deployments
- Utilize IBM QRadar SIEM to respond to network threats in real time
- Learn how to integrate AI into threat management by using QRadar with Watson
Book Description:
This comprehensive guide to QRadar will help you build an efficient security operations center (SOC) for threat hunting and need-to-know software updates, as well as understand compliance and reporting and how IBM QRadar stores network data in real time.
The book begins with a quick introduction to QRadar components and architecture, teaching you the different ways of deploying QRadar. You'll grasp the importance of being aware of the major and minor upgrades in software and learn how to scale, upgrade, and maintain QRadar. Once you gain a detailed understanding of QRadar and how its environment is built, the chapters will take you through the features and how they can be tailored to meet specifi c business requirements. You'll also explore events, flows, and searches with the help of examples. As you advance, you'll familiarize yourself with predefined QRadar applications and extensions that successfully mine data and find out how to integrate AI in threat management with confidence. Toward the end of this book, you'll create different types of apps in QRadar, troubleshoot and maintain them, and recognize the current security challenges and address them through QRadar XDR.
By the end of this book, you'll be able to apply IBM QRadar SOC's prescriptive practices and leverage its capabilities to build a very efficient SOC in your enterprise.
What You Will Learn:
- Discover how to effectively use QRadar for threat management
- Understand the functionality of different QRadar components
- Find out how QRadar is deployed on bare metal, cloud solutions, and VMs
- Proactively keep up with software upgrades for QRadar
- Understand how to ingest and analyze data and then correlate it in QRadar
- Explore various searches, and learn how to tune and optimize them
- See how to maintain and troubleshoot the QRadar environment with ease
Who this book is for:
This book is for security professionals, SOC analysts, security engineers, and any cybersecurity individual looking at enhancing their SOC and SIEM skills and interested in using IBM QRadar to investigate incidents in their environment to provide necessary security analytics to responsible teams. Basic experience with networking tools and knowledge about cybersecurity threats is necessary to grasp the concepts present in this book.
商品描述(中文翻譯)
了解不同的 QRadar 組件如何協同運作,並根據您的平台和環境探索其功能和實作
購買印刷版或 Kindle 版書籍包括免費的 PDF 電子書
主要特點:
- 掌握 QRadar 的架構、組件、功能和部署
- 利用 IBM QRadar SIEM 實時應對網路威脅
- 學習如何將 AI 整合到威脅管理中,使用 QRadar 與 Watson
書籍描述:
這本全面的 QRadar 指南將幫助您建立一個高效的安全運營中心 (SOC),以進行威脅獵捕和必要的軟體更新,並了解合規性和報告,以及 IBM QRadar 如何實時存儲網路數據。
本書首先簡要介紹 QRadar 的組件和架構,教您不同的 QRadar 部署方式。您將理解在軟體中了解主要和次要升級的重要性,並學習如何擴展、升級和維護 QRadar。一旦您對 QRadar 及其環境的構建有了詳細的了解,後面的章節將帶您了解其功能以及如何根據特定業務需求進行調整。您還將通過範例探索事件、流量和搜索。隨著進展,您將熟悉預定義的 QRadar 應用程式和擴展,這些應用程式能夠成功挖掘數據,並了解如何自信地將 AI 整合到威脅管理中。在本書的結尾,您將在 QRadar 中創建不同類型的應用程式,進行故障排除和維護,並認識當前的安全挑戰,通過 QRadar XDR 解決這些挑戰。
在本書結束時,您將能夠應用 IBM QRadar SOC 的建議實踐,並利用其能力在您的企業中建立一個非常高效的 SOC。
您將學到什麼:
- 發現如何有效使用 QRadar 進行威脅管理
- 了解不同 QRadar 組件的功能
- 了解 QRadar 如何在裸金屬、雲解決方案和虛擬機上部署
- 主動跟進 QRadar 的軟體升級
- 了解如何攝取和分析數據,然後在 QRadar 中進行關聯
- 探索各種搜索,並學習如何調整和優化它們
- 輕鬆維護和故障排除 QRadar 環境
本書適合誰:
本書適合安全專業人員、SOC 分析師、安全工程師,以及任何希望提升其 SOC 和 SIEM 技能的網路安全人員,並有興趣使用 IBM QRadar 來調查其環境中的事件,以提供必要的安全分析給負責的團隊。具備基本的網路工具經驗和對網路安全威脅的知識是理解本書中概念的必要條件。