OpenText는 수십 년간의 전문 지식을 통해 데이터를 활용하고, 사람과 프로세스를 연결하며, 신뢰할 수 있는 AI를 강화합니다
기업 전체의 데이터를 매끄럽게 통합하여 정보 단절을 없애고, 협업을 강화하며, 리스크를 최소화하세요
데이터를 AI가 활용 가능하고 구조화되고, 접근 가능한, 최적화된 정보로 변환하세요
규제 및 준수 요구 사항을 충족하고 정보의 수명 주기 전반에 걸쳐 보호하세요
OpenText는 사람들이 콘텐츠를 관리하고, 작업을 자동화하며, AI를 사용하고, 협업하여 생산성을 높일 수 있도록 지원합니다
전 세계 수천 개의 기업이 OpenText의 혁신적인 솔루션으로 성공을 거두고 있는 방법을 확인해 보세요
직원은 OpenText의 가장 큰 자산으로, OpenText 브랜드와 가치의 생명입니다.
OpenText가 사회적 목표를 발전시키고 긍정적인 변화를 가속화하기 위해 어떤 노력을 하고 있는지 알아보세요
디지털 혁신을 이루기 최적인 솔루션과 전문성을 갖춘 OpenText 파트너를 만나보세요
새로운 방식으로 정보 보기
비즈니스, 데이터 및 목표를 파악하는 AI
더 빠른 의사 결정을 만나보세요. 안전한 개인 AI 비서가 업무를 시작할 준비가 되었습니다.
공급망을 위한 생성형 AI로 더 나은 인사이트를 얻어보세요.
AI 콘텐츠 관리 및 지능형 AI 콘텐츠 어시스턴트를 통해 효율적으로 작업하세요.
더 빠른 앱 제공, 개발 및 자동화된 소프트웨어 테스트를 만나보세요.
고객 성공을 위해 고객 커뮤니케이션과 경험을 개선해 보세요.
사용자, 서비스 상담원 및 IT 직원이 필요한 답을 찾을 수 있도록 권한을 부여하세요.
새로운 방식으로 정보 보기
비즈니스, 데이터 및 목표를 파악하는 AI
더 빠른 의사 결정을 만나보세요. 안전한 개인 AI 비서가 업무를 시작할 준비가 되었습니다.
공급망을 위한 생성형 AI로 더 나은 인사이트를 얻어보세요.
AI 콘텐츠 관리 및 지능형 AI 콘텐츠 어시스턴트를 통해 효율적으로 작업하세요.
더 빠른 앱 제공, 개발 및 자동화된 소프트웨어 테스트를 만나보세요.
고객 성공을 위해 고객 커뮤니케이션과 경험을 개선해 보세요.
사용자, 서비스 상담원 및 IT 직원이 필요한 답을 찾을 수 있도록 권한을 부여하세요.
한 번만 연결하면 안전한 B2B 통합 플랫폼으로 모든 대상과 연결할 수 있습니다.
AI가 활용 가능한 콘텐츠 관리 솔루션으로 지식 재구성
기업 보호를 위한 통합 사이버 보안 솔루션
AI 기반 DevOps 자동화, 테스트 및 품질을 통해 더 나은 소프트웨어를 더 빠르게 제공
잊을 수 없는 고객 경험으로 대화 재창조
IT 운영의 비용과 복잡성을 줄이기 위해 필요한 명확성 확보
검증된 OpenText 정보 관리 기술을 사용하여 맞춤형 애플리케이션 구축
사용자 정의 애플리케이션 및 워크플로를 지원하는 실시간 정보 흐름을 제공하는 OpenText Cloud API를 사용하여 원하는 방식으로 구축
안전한 정보 관리가 신뢰할 수 있는 AI를 만나다
데이터와 AI의 신뢰를 높이는 통합 데이터 프레임워크
데이터 언어로 에이전트를 구축, 배포 및 반복할 수 있는 공간
AI를 강화하기 위해 데이터 수집 및 메타데이터 태그 지정 자동화를 지원하는 도구 세트
거버넌스를 사전 예방적이고 지속 가능하게 만드는 서비스 및 API 제품군
AI 여정을 도와주는 전문 서비스 전문가
새로운 방식으로 정보 보기
비즈니스, 데이터 및 목표를 파악하는 AI
더 빠른 의사 결정을 만나보세요. 안전한 개인 AI 비서가 업무를 시작할 준비가 되었습니다.
공급망을 위한 생성형 AI로 더 나은 인사이트를 얻어보세요.
AI 콘텐츠 관리 및 지능형 AI 콘텐츠 어시스턴트를 통해 효율적으로 작업하세요.
더 빠른 앱 제공, 개발 및 자동화된 소프트웨어 테스트를 만나보세요.
고객 성공을 위해 고객 커뮤니케이션과 경험을 개선해 보세요.
사용자, 서비스 상담원 및 IT 직원이 필요한 답을 찾을 수 있도록 권한을 부여하세요.
OpenText는 주요 클라우드 인프라 제공업체와 협력하여 어디서나 OpenText 솔루션을 실행할 수 있는 유연성을 제공합니다
OpenText는 최고의 엔터프라이즈 앱 제공업체와 협력하여 비정형 데이터를 활용함으로써 더 나은 비즈니스 인사이트를 제공합니다
duThe UAE telecom operator secures network resources, optimizes organizational efficiency, and enables growth with OpenText ArcSight

The organization needed to Automate security and compliance monitoring to protect network resources, improve operating efficiency, and support the scalable growth of consumer and business services.
As a rapidly growing mobile and fixed line service provider, du was faced with protecting its growing network and IT infrastructure while controlling costs and efficiently managing IT operations. By deploying ArcSight Enterprise Security Manager, du has been able to automate security and compliance monitoring to cost-effectively support corporate growth while improving efficiency and transforming Big Data into actionable intelligence.
As a company’s size and reliance on technology increases, so does the volume of logs it needs to collect, store, and analyze. This has been the case for du, which generates terabytes of security, network, operating system, database, and application log data each quarter. Emirates Integrated Telecommunications Company (EITC) is a telecommunications operator in the United Arab Emirates (UAE) that is commercially branded as du. It offers mobile and fixed telephony, broadband connectivity, and IPTV services to individuals, homes, and businesses throughout the UAE. The company also provides carrier services for businesses and satellite uplink and downlink services for TV broadcasters. Since its inception, du has consistently maintained a challenging strategic roadmap of supporting sustainable security initiatives.
The company also established a Technology Security and Risk Management (TSRM) organization to ensure that du would be able to maintain its leading edge not only in providing superior security initiatives internally, but also in extending its best practices to support the delivery of managed security services.
TSRM set up a Security Operations Center (SOC) with a Security Incident Response Team (SIRT) in 2008. The core of du’s SOC is a Security Information and Event Management (SIEM) solution from OpenText™. With over six years of maturity, du is now involved in setting up SOCs as well as offering managed SOC services for enterprises and government institutions throughout the UAE.
As du began building out its SOC, it evaluated best-of-breed products to secure its IT infrastructure.
The company selected TippingPoint Intrusion Prevention Systems to improve visibility into network traffic and benefit from real-time intrusion protection. TippingPoint platforms were deployed in-line in 2008 to protect du from cyber threats targeting applications, networks, and critical data. “We immediately gained detailed visibility into security threats that help us continuously remain aware of online risks and protect against fraud, viruses, and malware,” said Marwan Bindalmook, Senior Vice President of Technology Security and Risk Management for du.
The next step was to replace a SIEM solution that lacked the performance and scalability necessary to support du’s business objectives.
“We needed to secure fast-growing infrastructure, and that meant our SOC needed the ability to collect, correlate, and report on security information from a diverse range of devices and applications, including security devices, database management systems, and telecommunications equipment,” Bindalmook explained. “Our data volumes were exploding, and we needed a higher-performance SIEM solution that could scale with our business growth and provide timely and relevant intelligence to help us quickly detect and respond to any security breaches.
After a careful evaluation, du selected ArcSight Enterprise Security Manager (ESM), which provides a Big Data analytics approach to security, transforming Big Data into actionable intelligence that can reduce the costs of a breach and help minimize risk to a business. Using device and application connectors, ArcSight ESM provides a central point for the analysis of daily operations.
Armed with all this data, the real-time correlation capabilities of ArcSight ESM can detect unusual or unauthorized activities as they occur.
The visualization and reporting capabilities of ArcSight ESM support dashboards and on-demand or scheduled reports for the SOC team. ArcSight ESM is designed to efficiently store and analyze large volumes of log data.
This universal log management solution efficiently collects and stores machine data from any log-generating source and unifies the data for searching, indexing, reporting, analysis, and retention.
In addition to the out-of-the-box use cases profiling threat conditions that are available with ArcSight ESM, du continuously develops and refines use cases to identify threats. ArcSight ESM is used to identify the relevance of any given event by placing it within the context of who, what, where, when, and why that event occurred, and it assesses the impact of a threat on business risks. It also provides the real-time monitoring, historic analysis, and automated response necessary to manage higher-level business risk events. The organization has now developed over 550 custom use cases based on its business and risk profiling methods.
A comprehensive security management program typically develops and matures over time, and du has been using ArcSight ESM for the last six years. The architecture, packaging, and out-of-the-box features of ArcSight ESM meant that the solution is uniquely capable of scaling both from capacity and feature perspectives and it could meet du’s logging, monitoring, and analysis needs with a single solution.
The du infrastructure continues to grow, and ArcSight ESM scales to support the growing needs of the company. The SOC is currently leveraging ArcSight ESM to collect more than 30,000 Events Per Second (EPS) and submits about 5,000 EPS for correlation.
ArcSight’s logging format, Common Event Format (CEF) has become the de-facto logging format for almost all device vendors, and out-of-the-box ArcSight ESM supports hundreds of products, and its ecosystem is still growing. Using ArcSight’s FlexConnector SDK, members of the SOC team develop custom connectors. “We’ve already developed 62 custom connectors using the FlexConnector SDK,” said Tamer El Bahey, Senior Director of Security Monitoring and Operations for du. “It takes a single developer only about two weeks to build a new connector, and we consider the FlexConnector SDK a major advantage because of the diversity of devices it allows us to capture event information from in real time.”
ArcSight ESM is helping du improve operational efficiency through the automation of manual tasks and optimizing staff efficiency. Successful threat mitigation depends on being able to quickly identify the critical incidents so that they can be handled before they can cause a major negative impact. Reduction in the critical incident rate was crucial for SIRT to effectively respond to incidents. ArcSight ESM helps du filter out the incidents that were resulting in high IT and business risks and act on them more effectively.
Before the deployment of ArcSight ESM, du had to analyze 7,000 alerts per month. As a result, a sizeable security team was required to process the alerts. To help bring the critical event volume under control, du used ArcSight’s correlation and rule-building framework to optimize its security alerts. With the appropriate correlation rules and alerts, ArcSight ESM was able to remove false positives and redundant alerts.
TSRM was able to create over 550 custom correlation rules that analyze about 30,000 EPS received in real time from about 1,500 log sources. According to El Bahey, “Three years ago we had 72 correlation rules and now we have over 550. ArcSight makes it easy to create custom rules, we’ve written them all internally and they allow us to dramatically improve our workforce productivity.”
TSRM has also created more than 30 customized filters to parse events from non-traditional IT solutions and telecommunications equipment to gain increased visibility. ArcSight ESM has helped du to gain the threat visibility it needs by increasing the percentage of its incident-to-true positive value by more than 400%.
By fine-tuning the priorities of critical events, security analysts can see the most important items first and the SOC can provide better service levels. The SOC has been able to reduce the security alerts that need analysis from over 7,000 per month to fewer than 1,000 per month, a decrease of over 85%.
“We now have a full-fledged SOC, of which ArcSight is the core element,” said El Bahey. “ArcSight helps bridge the gap between business risk and IT risk while improving situational awareness and providing better incident response.”
The company continues to improve operations. Now, 82% of compromise attempts are detected in less than 24 hours. The du infrastructure continues to scale; ArcSight EMS analyzed 1,300 log sources last year and now analyzes 1,500 log sources.
While selecting a replacement SIEM solution, a primary TSRM concern was demonstrating how IT-related security risk related to business risks. Though du had purchased multiple best-of-breed security technologies, TSRM found that its original approach of managing logs in their native formats was not delivering the desired results.
By replacing our original SIEM platform with ArcSight, we’ve been able to integrate logs from diverse technologies under a single umbrella and use ArcSight’s powerful correlation engine to develop threat management and risk management use cases to deliver greater value to the business.
The SIEM solution plays a major role in providing SOC and SIRT services internally. “ArcSight helps us to closely align business and IT risks, and today any security initiative, regardless of security technology or security service, must be aligned with the objectives of the SOC,” Bindalmook stated. “This helps us maintain the overall objectives of TSRM as well as our Service Level Agreements (SLAs) with business users.”
As a result of setting up a world-class SOC with ArcSight ESM at its core, du is starting to offer managed SOC services by setting up of SOCs for enterprises and government customers throughout the region. By leveraging best practices and custom rules and use cases that have been developed and evolved internally, du is extending an internal security initiative into a premium service offering. In this manner, TSRM is evolving from a cost center into a profit center through its advanced implementation of this SIEM solution.

As a telecommunications service provider in the United Arab Emirate, du has more than 6.5 million mobile customers and almost 50% market share. Over 555,000 fixed line subscribers, 180,000 home services subscribers, and over 70,000 businesses have chosen to use services from du. In a survey conducted by ARC Chart, du was named the Best Mobile Broadband Network in the Middle East and Africa region.