Example: quiz answers

Virtual Security Operations Center (VSOC) Portal Reports ...

Copyright IBM Corporation 2010 -2016 Virtual SOC Portal Reports user guide Page 1 of 28 Virtual Security Operations Center (VSOC) Portal Reports user guide December 2017 Copyright IBM Corporation 2010 -2016 Virtual SOC Portal Reports user guide Page 2 of 28 Table of Contents OVERVIEW .. 3 REPORTING HIGHLIGHTS .. 3 report DASHBOARD .. 4 GENERATING Reports .. 6 SCHEDULE Reports .. 7 CUSTOMIZING Reports WITH CSV .. 8 GENERAL SERVICE RELATED Reports .. 9 SERVICE LEVEL AGREEMENT report .. 9 SERVICE OVERVIEW report .. 10 Security MANAGER OVERVIEW report .. 11 IDS/IPS DEVICE Reports .. 12 ATTACK METRICS .. 12 GLOBAL ATTACK METRICS .. 12 YOUR ATTACK METRICS .. 13 EXPLANATION OF ATTACK TYPES .. 13 ATTACKS ON VULNERABLE ASSETS .. 17 PREVENTED ATTACK report .. 18 EVENT COUNTS 19 IDS/IPS EVENT TREND .. 20 CONTENT MANAGEMENT .. 21 URL FILTERING CATEGORY .. 21 FIREWALL .. 23 FIREWALL SERVICE OVERVIEW.

© Copyright IBM Corporation 2010-2016 Virtual SOC Portal Reports User Guide

Tags:

  Guide, User, Security, Operations, Report, Center, 2010, Patrol, Security operations center, Soc portal reports user guide

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Virtual Security Operations Center (VSOC) Portal Reports ...

1 Copyright IBM Corporation 2010 -2016 Virtual SOC Portal Reports user guide Page 1 of 28 Virtual Security Operations Center (VSOC) Portal Reports user guide December 2017 Copyright IBM Corporation 2010 -2016 Virtual SOC Portal Reports user guide Page 2 of 28 Table of Contents OVERVIEW .. 3 REPORTING HIGHLIGHTS .. 3 report DASHBOARD .. 4 GENERATING Reports .. 6 SCHEDULE Reports .. 7 CUSTOMIZING Reports WITH CSV .. 8 GENERAL SERVICE RELATED Reports .. 9 SERVICE LEVEL AGREEMENT report .. 9 SERVICE OVERVIEW report .. 10 Security MANAGER OVERVIEW report .. 11 IDS/IPS DEVICE Reports .. 12 ATTACK METRICS .. 12 GLOBAL ATTACK METRICS .. 12 YOUR ATTACK METRICS .. 13 EXPLANATION OF ATTACK TYPES .. 13 ATTACKS ON VULNERABLE ASSETS .. 17 PREVENTED ATTACK report .. 18 EVENT COUNTS 19 IDS/IPS EVENT TREND .. 20 CONTENT MANAGEMENT .. 21 URL FILTERING CATEGORY .. 21 FIREWALL .. 23 FIREWALL SERVICE OVERVIEW.

2 23 TRAFFIC ANALYSIS DENIED .. 24 TRAFFIC ANALYSIS EMAIL .. 25 TRAFFIC ANALYSIS WEB ACTIVITY BY WEBSITE .. 25 SUSPICIOUS HOST CORRELATION report .. 26 Security EVENT AND LOG MANAGEMENT DEVICES (SELM) .. 27 CROSS LOG TYPE Reports .. 27 ALERT-BASED Reports .. 27 Copyright IBM Corporation 2010 -2016 Virtual SOC Portal Reports user guide Page 3 of 28 Overview This document enables you take advantage of the Reporting features in the IBM Security Services Managed Security Services (MSS) Customer Portal , sometimes referred to as the Virtual Security Operations Center (VSOC). Use this guide to learn about basic navigation of the report Dashboard, or to facilitate in-depth analysis to support your Security organization. report templates include descriptions and use cases to help you better understand the various industry standard templates and best practices available to you. Reporting Highlights Security Event and Trend Statistics Firewall Traffic and Utilization Statistics Threat and Vulnerability Research Threat and Vulnerability Mitigation Audit Compliancy Workload Prioritization Suspicious Host Detection IP Intelligence ( Security analytics) Statistical Overview of Your Services Note: Feature sets may vary based on the MSS services you have subscribed to.

3 Appropriate Service and Service level subscription is required. Copyright IBM Corporation 2010 -2016 Virtual SOC Portal Reports user guide Page 4 of 28 report Dashboard The Portal report Dashboard contains many industry standard report templates that you can customize by device, device groups, and time intervals. Click a report template hyperlink to configure report criteria and generate a report . The report templates can facilitate research, vulnerability assessment, threat mitigation, workload prioritization and delegation, and help address audit compliancy requirements. Copyright IBM Corporation 2010 -2016 Virtual SOC Portal Reports user guide Page 5 of 28 The report templates are grouped into several categories: General Service Related Reports on statistics associated with your subscribed services IDS/IPS Devices Reports on device statistics Content Management Devices Reports related to web content, anti-virus, and anti-spam Security Event & Log Management Cross Log Type Reports Firewall Devices Reports on FW statistics Alerts-based Reports report of the alerts and counts associated with your SELM Service The VSOC allows you to save report criteria for future use, and to export a report in PDF and CSV formats.

4 You can schedule Reports at fixed time intervals by selecting one of the calendar icons shown below. The scheduling feature also allows you to email Reports automatically to various members in your organization. Copyright IBM Corporation 2010 -2016 Virtual SOC Portal Reports user guide Page 6 of 28 Generating Reports Step 1: Select the desired time interval from the drop down. Note you also have the option to select from a saved report . Step 2: Select the desired device or device group. Note you also have the option to report on inactive devices. Step 3: Select the desired report options including amount and format. Note you also have options to enable, Resolve DNS, Trending and Group by Network. Note: To save the report , check the box entitled Save this criteria. Step 4: Select, Submit Query on the lower right-hand side. Copyright IBM Corporation 2010 -2016 Virtual SOC Portal Reports user guide Page 7 of 28 Schedule Reports After you have customized (named) and saved your Reports you can set up auto reporting.

5 Step 1: Select the desired report name. Step 2: Schedule the report by selecting the appropriate recurrence pattern (Hourly, Daily, etc.). Step 3: Schedule the appropriate recurrence range. Note the calendar icons for specific end date assistance. Step 4: Select the appropriate report format (PDF, HTML or CSV). Step 5: Verify and / or edit the recipient fields. Step 6: Click Create Schedule on the lower right. Best Practice Tip: If you need to delegate work within your Security team, or adhere to audit compliancy requirements, use the report delivery options to archive Reports to a centralized mailbox. Copyright IBM Corporation 2010 -2016 Virtual SOC Portal Reports user guide Page 8 of 28 Customizing Reports with CSV You can open a CSV (comma separated value) report in Microsoft Excel. It is a powerful and versatile format. It allows you to combine data from multiple sources, and use macros and other Excel tools to manipulate the data and create multiple views of it.

6 Using Excel Pivot Tables to Create Custom Reports from a CSV File The pivot table feature in Microsoft Excel allows you to manipulate report data in many different ways, essentially creating multiple Reports from one exported CSV file. For more information about how to use Excel to manipulate Portal report data, refer to the video, Exporting Portal Data and Using Excel to Manipulate Data and Create Pivot Tables (10 minutes), which is available in the Portal Media Library . Copyright IBM Corporation 2010 -2016 Virtual SOC Portal Reports user guide Page 9 of 28 General Service Related Reports General Service Related Reports can help you research, track, and document ticketing information, including Service Level Agreement bound tickets and Security incident details. These Reports can assist in audit compliancy initiatives. There are three types of service related Reports : Service Level Agreement, Service Overview and Security Manager report Service Level Agreement report report shows charts and statistics on SLA eligible tickets and associated response time.

7 Graphs will track various types of tickets including suspected outages, maintenance and general inquires. *additional SLA levels available in full report Copyright IBM Corporation 2010 -2016 Virtual SOC Portal Reports user guide Page 10 of 28 Service Overview report The Service Overview report shows graphs and charts summarizing SLA eligible tickets, ticket type breakdown and a six-month trend. *example below. Additional report contents available in full report Copyright IBM Corporation 2010 -2016 Virtual SOC Portal Reports user guide Page 11 of 28 Security Manager Overview report The Security Manager Overview report shows the total Security event count and Security incident statistics. The report also includes a detailed Security Incident (ticket) breakdown, which can assist in organization and workload prioritization. Copyright IBM Corporation 2010 -2016 Virtual SOC Portal Reports user guide Page 12 of 28 IDS/IPS Device Reports IDS/IPS device Reports provide statistical threat analysis information about Security event threats impacting your network.

8 Use these Reports to gather statistics on Security events by source and destination, as well as assist in researching attack trends. You also can use these Reports for tuning initiatives. Attack Metrics This report requires Security events from IBM appliances. It displays several graphs of data, detailing the numbers and types of attacks detected during the past 30 days. This report can help identify abnormalities within your network. It is available as Global Attack Metrics as well as Your Attack Metrics. To view more detailed information, click a graph and plot points to generate drill-in reporting. Global Attack Metrics Click a graph for drill-in research capabilities. Copyright IBM Corporation 2010 -2016 Virtual SOC Portal Reports user guide Page 13 of 28 Your Attack Metrics Explanation of Attack Types The attack types included in the Attack Metrics report , along with brief descriptions and examples, are listed below.

9 Protocol Signature A large number of these events in a short time period could indicate an attack. Example: TLS_Weak_Cipher_Suite Servers and clients use certificates when establishing communication using Secure Sockets Layer (SSL). An SSL server that allows weak ciphers (with key-lengths less than 128-bits) could allow a remote attacker to obtain sensitive information. Suggested Action: Consult server documentation to disable weak ciphers. Pre-Attack Probe An attempt to gain access to a computer and its files through a known or probable weak point in the computer system. Example: Ping_Sweep As a prelude to an attack, subnets are often swept with ICMP or other packets that elicit known responses from active hosts. This sort of probe is used to enumerate active hosts on the subnet, and identify potential attack targets. Normal hosts on a network should never engage in sweeps unless they are performing network monitoring or management tasks.

10 Suggested Action: Always filter inbound ICMP (other than replies to outbound requests) through your firewall or filtering router, if possible. If a stateful inspection filter is not available inbound, then block all ICMP outbound to prevent replies from reaching the attacker. Copyright IBM Corporation 2010 -2016 Virtual SOC Portal Reports user guide Page 14 of 28 Unauthorized Access Attempt This usually denotes suspicious activity on a system, or failed attempts to access a system, by a user or who does not have access. Example: SSH_Brute_Force This event detects an excessive number of very short SSH sessions initiated by a single client to one or more servers within a specified timeframe. It may indicate a username/password guessing attack, or a DoS attack. To qualify as this type of attack, a session must have completed encryption negotiations so that a login may be attempted, and the time elapsed from the first encrypted client data until the TCP session ends with a TCP FIN or server RST must be less than the setting for (default 4 seconds).


Related search queries