I'm already mentioned in my previous article about Traffic Analysis in Qubes OS, that the IDS system alerts and logs should be passed to a log management system where we can correlate them with other logs and alerts. That system can be called SIEM
However a real SIEM system makes sense in an enterprise environment only, because it is requires 7x24 monitoring, and it is also needs special knowledge and experience to analyze the results.
Qubes OS version 3.2 have been released.
Qubes OS version 3.1 have been released.
One of the best thing in Qubes that you can use special type of VMs called ProxyVM (or FirewallVM). Keep reading →
Qubes OS version 3.0 have been released. Keep reading →