About cookies on this site Our websites require some cookies to function properly (required). In addition, other cookies may be used with your consent to analyze site usage, improve the user experience and for advertising. For more information, please review your options. By visiting our website, you agree to our processing of information as described in IBM’sprivacy statement. To provide a smooth navigation, your cookie preferences will be shared across the IBM web domains listed here.
Early Threat Detection and Cyber Resiliency on the IBM DS8000, with QRadar, Copy Services Manager, and Safeguarded Copy
Related Media
From 2700070HPT 2700070HPT January 21st, 2021 |
In this video, we show a Proof of Concept, showing the
high level overview and actions easily done by a customer to further harden
their security posture with QRadar, Copy Services Manager, and Safeguarded
Copy. The video shows a live attack on a DS8k, with QRadar
detecting these suspicious behaviors and then immediately invoking a Python
Script (or Ansible) to then pause replication, and do an Ad-hoc,
immediate Safeguarded Copy snapshot, as well as raise an alert for the security
team to investigate. This demo also opens further discussions on using
similar playbooks for an immediate restoration and recovery playbooks.
Here are links to the publicly available code and paper that goes into more depth:
- Tags
- Appears In
Loading