منافسة عامة قيد التنفيذ

عملية توريد وتركيب وتشغيل نظام ورخص الإكتشاف والحماية الإستباقية للأجهزة الطرفية وإكتشاف التهديدات والأنشطة الضارة على مستوى الشبكة للمديرية العامة لمكافحة المخدرات

المديرية العامة لمكافحة المخدرات

رقم المنافسة

220639596606

المعرّف

#425482

رقم المنافسة
220639596606
رقم المنافسة الداخلي
37/1443-1444
الجهة الحكومية
المديرية العامة لمكافحة المخدرات
الفرع / الإدارة
إدارة المنافسات
نوع المنافسة
منافسة عامة
حالة المنافسة
—
طريقة تقديم العروض
—
رسوم الاشتراك
500 ر.س
سعر كراسة الاشتراط
1,000 ر.س
تكلفة الدعوة
200 ر.س
تكلفة الشراء
500 ر.س
الضمان الإبتدائي
—
الضمان النهائي
—
مدة العقد
—
التأمين مطلوب
—
مدة الوقفة (أيام)
—
داخل المملكة
—
التاريخ ميلادي هجري
تاريخ النشر 2022/07/18 15:37 —
آخر موعد للاستفسارات 2022/07/25 1443-12-26
آخر موعد تقديم العروض 2022/08/07 14:00 1444-01-09
موعد فتح العروض 2022/08/08 09:30 1444-01-10
موعد فحص العروض — —
التاريخ المتوقع للترسية — —
تاريخ بدء الأعمال — —
تاريخ خطاب تأكيد المشاركة — —
بداية إرسال الأسئلة — —

موقع التنفيذ

منطقة التنفيذ
—
مدن التنفيذ
—

مجال التصنيف

يشمل مواد توريد
لا

جدول 1 القوى العاملة - تقنية معلومات

العدد وصف البند السنة الاولى السنة الثالثة السنة الثانية الرقم التسلسلي المسمى الوظيفي أقل مؤهل للقبول الحد الأدني لسنوات الخبرة عدد ساعات العمل الاساسي المتوقعة عدد ساعات العمل الاضافي المتوقعة
0 بكالوريوس في هندسة الحاسب الالي 10 ( سنة خبرة في الأعمال الامنية، ) 5( سنوات ( خبرة، في الإشراف على المشاريع، ) 3( سنوات عمل في السعودية، ذو شخصية قيادية 1 1 7 1 مدير المشروع )مهندس( بكالوريوس هندسة حاسب الي 10 0 0
0 بكالوريوس في هندسة الحاسب الالي 6( سنة خبرة في الأعمال الامنية، ) 2( سنوات ( خبرة، في الإشراف على المشاريع، ) 4( سنوات عمل في السعودية، ذو شخصية قيادية 1 1 7 2 تنفيذ المشروع ) مهندس ( بكالوريوس هندسة حاسب الي 6 0 0
0 دبلوم حاسب الي 1 1 7 3 فني حاسب الي دبلوم حاسب الي 3 0 0

3 بند

جدول 2 المواد - تقنية معلومات

البند المواصفات وحدة القياس السنة الاولى السنة الثالثة السنة الثانية الرقم التسلسلي منتج من القائمة الإلزامية
توريد وتركيب النظام المتقدم للكشف وتحليل المخاطر الأمنية مع كامل ملحقاته لثلاث سنوات · الأداء وقابلية التوسع · يجب أن يكون النظام جهازاً. · يجب أن يدعم النظام مراقبة ما لا يقل عن 15 جيجابت في الثانية لكل وحدة استشعار(حساس) · يجب أن يدعم النظام حركة مرور الشبكة بأن تصل إلى 50 جيجابت في الثانية في النظام المشغل الواحد · يجب أن يدعم النظام كمية بيانات تصل الى 10 جيجابت في الثانية عبر منفذ شبكة النظام بسرعة 10 جيجابت في الثانية · يجب أن يدعم المستشعر الافتراضي على تقنية ال VMWare التقاط حركة بيانات حتى 5 جيجا في الثانية. · يجب أن يعمل النظام بطريقة لا تؤثر على أداء الشبكة. · يجب أن يعمل النظام بفعالية وكفاءة دون الحاجة لاتصاله بشبكة الإنترنت، أو الإدارة عن بعد (طرف خارجي). · يجب أن يعمل النظام بدون تنصيب أي برنامج اخر. · أتمتة الكشف والتحليل · يجب أن يقوم النظام تلقائيًا باكتشاف وتصنيف جميع التهديدات بما في ذلك مرحلة الهجوم، دون الحاجة للتدخل البشري. · يجب أن يقوم النظام بتجميع التهديدات وتحديد أولوياتها بمرور الوقت حسب الجهاز المستخدم، حتى في حال تغير اسم وعنوان المستخدم IP) ) · يجب على النظام أن يميز الأصول الرئيسية عن باقي الأصول وذلك لتحديد اولويات المخاطر. · يجب أن يمتلك النظام آلية لإظهار ثقة الكشف تلقائيًا عند اكتشاف التهديدات استنادًا إلى الحالات الشاذة. · يجب أن يكون للنظام القدرة على التمييز تلقائيًا بين سلوكيات البرمجيات الضارة Botnet وتلك التي من المرجح أن تكون تهديدات مستهدفة. · يجب أن يكون للحل القدرة على تصنيف التهديدات التالية: ü سلوك البرمجيات الضارة Botnet , بما في ذلك البريد الضار Spam ، و هجمات حجب الخدمة DDoS، ومسح الثغرات الأمنية الخارجية ، وتعدين البيتكوين Bitcoin mining ، إلخ. ü . المعابر الخفية داخل HTTP و DNS و HTTPS المستخدمة في القيادة والتحكم وتسريب البيانات بدون تنبيهات خاطئة بسبب الإشارات القياسية من الأدوات والتطبيقات الشائعة. ü . برامج الإدارة عن بعد من حركة المستخدم العادي. ü التحكم والسيطرة الغير معروفة باستخدام مؤشرات حركة المرور الأخرى بدون وجود سجلات سابقة ü تسريب البيانات بشكل مستقل عن هوية المستخدم أو عنوان IP ü استطلاع باستخدام مسح الشبكة البطيء أو السريع او الداخلي. ü الاستخدام غير السليم للبروتوكولات الإدارية، بما في ذلك IPMI و iDRAC و SSH و RDP ü تفعيل الجذور الخفية لنظام التشغيل الفرعي باستخدام عملية قرصنة المنفذ ü عمليات الإتصال عن بعد لتنفيذ التعليمات او البرامج بإستخدام بروتوكولات DCERPC أو SMB · يجب أن يقوم النظام بإعادة تصنيف السلوكيات الناتجة عن الأنظمة المعتمدة أو الاستخدام المقبول مثل الماسحات الشبكية. · يجب أن يتمتع النظام بالقدرة على استكشاف حملة التهديدات وتحديدها تلقائيًا وذلك ب: ü ربط نشاط المهاجمين عبر مضيفين متعددين لتقديم عرض شامل للحملة ü هجمات التحكم والسيطرة المتقدمة C&C ü الكشف عن جميع الأجهزة المضيفة التي تتصل بالبنية الأساسية لهجمات التحكم والسيطرة C&C ü تسليط الضوء على الاكتشافات الجانبية ذات الصلة بين المضيفين · يجب أن يكون النظام محايد لجميع البروتوكولات. · تحديد الأولويات والتحقيق في التهديدات · يجب على النظام أن يحدد الأولويات لكل سلوكيات الهجمات المستكشفة. · يجب على النظام أن يسجل كل جهاز ويحديد أولوياته تلقائيًا بناءً على سلوكه بمرور الوقت · يجب ان يكون لدى النظام القدرة على إخطار الموظفين بناءً على درجة التهديد · يجب ان يوفر النظام رؤية نافذة للأصول الرئيسية والمهمة مع توضيح وتحديد سلوكيات المهاجم · يجب ان يوفر النظام درجات مخصصة لكل شكل من اشكال الخطر ومدى اليقين والثقة لهذا الخطر · يجب ان يوفر النظام الرؤية في التوصيل البيني للأنظمة · يجب ان يوفر النظام تسجيلات لحزم سلوكيات المهاجم المحددة لاستخدامها في التحليل · يجب ان يمتلك النظام القدرة على العثور على القواسم المشتركة عبر أجهزة متعددة في الشبكة وتقديمها في حملة هجوم متماسك لجميع الانظمة المشاركة في حملة الهجوم · منهجية الكشف · يجب أن يكشف النظام عن تهديدات غير معروفة، حيث لا يوجد توقيع أو سجل سابق لعنوان المستخدم. · يجب ان يكون النظام قابلا للعمل على جميع أجهزة المستخدم والبنية التحتية (Windows , الأجهزة المحمولة ، Mac ، byod ، إنترنت الأشياء IoT ، أجهزة التوجيه ، جدران الحماية) · يجب أن يستخدم النظام تقنيات سلوك متعددة (التعلم الخاضع للإشراف، التعلم غير الخاضع للإشراف، علم القياس والتعلم العميق) · يجب ألا يستخدم النظام المنهجية القائمة على التوقيع لكشف التهديدات الأمنية. · يجب أن يتمتع النظام بالقدرة على تحليل حركة مرور الشبكة وربطها. · يجب على النظام أن يقوم بأتمتة اقتناص التهديد في سرعة الواير. · يجب أن يكون للنظام القدرة على إجراء المطابقة على IOCs المقدمة عبر STIX والنمذجة العالمية للتهديدات · يجب أن يكون للنظام القدرة على التعلم من سلوكيات المهاجمين الخارجيين وتقنياتهم لاكتشاف التهديدات على الشبكة المحلية كلما أمكن ذلك. · يجب أن يكون للنظام القدرة على عمل نموذج عالمي للتهديدات التي سيتم دمجها مع الشبكة المحلية لتحسين الدقة ورفع الكفاء. · النمذجة المحلية للتهديدات · يجب أن يكون للنظام القدرة على اكتشاف الحالات الشاذة التي يحتمل أن تكون ضارة بناءً على الإنحراف عن المعايير المحلية المستخدمة داخل الشبكة. · يجب أن يكون للنظام القدرة على التعلم المستمر مع تطور الشبكة. · يجب أن يكون للنظام القدرة على اكتشاف التهديدات داخل الأجهزة أو الأجهزة الجديدة التي تم اختراقها عند تحديد الخط المرجعي. · التحليل · يجب أن يحافظ النظام على بيانات الشبكة لكل هجوم مكتشف. · يجب ألا يقوم النظام بفك تشفير حركة المرور من أجل التحليل. · يجب ألا يستخدم النظام بروتوكول NetFlow كمصدر للبيانات. · يجب أن يستخدم النظام حركة مرور الشبكة للتحليل في الوقت الفعلي. · يجب أن يستخدم النظام قدرات الذكاء الاصطناعي لتكملة واتمتة مركز عمليات الأمن السيبراني. · يجب أن يوفر النظام روابط زمنية محدودة للمستخدمين الخارجين لتحليل الأحداث. · يجب أن يوفر النظام أتمتة التحليل لتحديد الهجمات. · يجب أن يكون الحل قادراً على اكتشاف أنوع التهديدات التالية (على سبيل المثال لا الحصر): ü معابر الوصول عن بعد المستخدمة من قبل المهاجمين للسيطرة على الأنظمة المخترقة. ü معابر مخفية عبر DNS أو HTTPS أو HTTP للتواصل مع C&C أو لتسلل البيانات ü القيادة والسيطرة على شبكة الإنترنت (لا تعتمد على سمعة أو قوائم التهديد IP) ü البرامج الضارة باستخدام متصفحات وهمية ü تحديث البرامج الضارة ü البرامج الضارة التي ستحصل على تعليمات جديدة ü البرمجيات الخبيثة التي تكرر الحمولة إلى / استغلال نقاط الضعف ضد المضيفين الآخرين ü TOR إخفاء الهوية. ü نقل البيانات باستخدام طريقة نظير إلى نظير ü سلوكيات تسييل Botnet : تعدين Bitcoinو DoS الصادر والرسائل الالكترونية الضارة. ü نشاط Ransomware تشفير مشاركات الملفات ü عمليات مسح الاستطلاع عبر الشبكة: عمليات فحص المنفذ، وعمليات مسح المنفذ، ومسح عناوين IPغير المستخدمة ü استخدام بيانات اعتماد مسروقة من مضيف لم يتم استخدامه من قبل ü استخدام بيانات اعتماد مسروقة من نظامها العادي، وذلك بطلب خدمات غير عادية أو بأحجام كبيرة ü مضيف يحاول الوصول للخادم عن طريق أسماء وكلمات مرور ü تفحص خدمة Kerberos ü خوادم Kerberos وهمية ü هجمات تخمين كلمات السر ü استخدام البروتوكولات الإدارية، بما في ذلك RDP وSSHو IPMI و IDRAC حيث لا تتم إدارة المضيف. ü الهدف عادةً بواسطة المضيف المصدر على هذا البروتوكول ü اخراج او تسريب البيانات إلى وجهة غير عادية ü مضيف يجمع وحدات تخزين غير عادية من البيانات ثم يرسل البيانات المسربة إلى عنوان IP خارجي ü مضيف يتم استخدامه كمرحل. · يجب أن يكون للنظام القدرة على الكشف عن تعداد مشاركات الملفات. · يجب أن يكون لدى النظام القدرة على اكتشاف استطلاع AD / LDAP باستخدام تقنيات مشابهة ل Bloodhound · يجب أن يكون النظام القدرة على الكشف عن استخدام Powershell / WMI و RPC للتنقل بشكل أفقي عبر تنفيذ التعليمات البرمجية عن بُعد. · يجب أن يكون للنظام القدرة على الكشف عن رموز RDP المسروقة. · يجب أن يكون النظام القدرة على الكشف عن استطلاع خوادم RDP · يجب أن يتمتع النظام بالقدرة على اكتشاف استخدام PSexec وأدوات الإدارة عن بُعد الأخرى للتنقل بشكل أفقي عبر SMB التكامل · يجب أن يتكامل النظام مع أنظمة جمع السجلات مثل Splunk ,او,, Archsite او QRadar او Logrythm · يجب أن يتكامل النظام مع أنظمة حماية النهاية الطرفية مثل Carbon Black , او Cyberreason , او Microsoft Defender ATP · يجب أن يتكامل النظام مع أنظمة الجدران النارية مثل Paloalto , او Fortinet · يجب أن يتكامل النظام مع أنظمة نسخ حركة معلومات الشبكة مثل Ixia, او Gigamon · يجب أن يوفر النظام وصولًا يستند إلى واجهة برمجة التطبيقات (API) لجميع الأحداث والمضيفين ومعلومات التسجيل للتكامل مع حلول الأمن السيبراني وأنظمة التشغيل الأخرى. · التكامل مع أنظمة VMWare التشغيل · يجب أن يتمتع النظام بالقدرة على التحديث بشكل. · يجب تحديث نظام البرنامج بشكل منتظم لمنع حدوث التهديد المتطور باستمرار. · يجب أن يفي النظام بجميع المتطلبات الإلزامية دون اتصال VPN أو استخدام الخدمة السحابية أو أي معلومات يتم إرسالها من الخارج. · يجب ألا يتطلب النظام أي تغييرات في اعدادات الأجهزة عدا ( (span / tap / mirror · يجب أن يكون النظام قادرا على توفير المراقبة عبر البريد الإلكتروني و Syslog. · يجب أن يكون النظام قادراً على تنبيه الأخطار الفردية أو المضيفين المشتبه فيهم عبر البريد الإلكتروني و Syslog · يجب أن يوفر النظام التحكم في الوصول القائم على الأدوار (RBAC) في مختلف عناصر المنتج حتى يتمكن محللو الأمن من تحديد الأدوار المخصصة ذات الوصول المحدود إذا رغبت في ذلك. · يجب أن يتمتع النظام بالقدرة على إرسال جميع السجلات لجميع ا لإجراءات مثل تسجيل الدخول والخروج والتغييرات في الإعدادات. · يجب أن يلتقط النظام كل حركة المرور التي تعبر VMWare vSwitch · يجب أن يوفر النظام رؤية حول أي مضيفات فعلية يتم تغطيتها أو كشفها بواسطة vSensors · يجب على النظام ان يقوم بإرسال التنبيه للمختصين تلقائيًا إذا كانت هناك تغييرات في البيئة الافتراضية التي تؤثر على التغطية. · يجب أن يقوم النظام بالنشر والإقران التلقائي vSensors · التقاط البيانات الوصفية (التحليل الجنائي ، الامتثال) · يجب أن يكون الحل قادرًا على توفير بيانات تعريف شبكة غنية للبحث عن التهديدات والتحقيق والامتثال · يجب أن تتضمن البيانات الوصفية بروتوكولات للرؤية مثل RDP و SMB و LDAP و RPC و Kerberos · يجب تنظيم البيانات الوصفية حسب اسم الجهاز لسهولة التحقيق · يجب أن تكون البيانات الوصفية بتنسيق يمكن للفرق الأمنية فهمها بسهولة · يجب أن يكون قادرًا على توصيل البيانات الوصفية إلى بحيرات البيانات الشائعة مثل ELK و Kafka و Syslog و JSON · يجب أن يكون من السهل نشره بدون صيانة مستمرة وضبط الأداء · يمكن ربطه بمصادر البيانات الأخرى عند الحاجة. · يوفر تحقيق ذكي في النشاط حسب الجهاز · يجب أن يتم تركيبه في المقر مع توفر سعة تخزين غير محددة عند الحاجة وامكانية استخدام ال SIEM/Datalake Performance and Scalability Support monitoring of at least 20Gbps aggregate per sensor Support up to 50Gbps aggregate traffic in a single Brain (1 Rack Unit) Support 10Gbps peak traffic via 10Gbps network interfaces Support at least 1Gbps up to 5Gbps capture of traffic with a VMWare virtual sensor, while minimizing resource requirements Operate passive to the network i.e. not taxing network performance Operate effectively and efficiently in an air-gapped environment without external influence i.e. people or other technology The solution must be agentless 2a Automatically identify and classify all threats, including attack phase and risk, without requiring any manual intervention 2b Aggregate and prioritize threats over time by host, even across IP and user identity changes 2c Differentiate key assets from other hosts for risk prioritization 2d Possess a mechanism to automatically show the confidence of detection when threats are detected based on anomalies 2e Ability to automatically differentiate between general botnet behaviors and those that are more likely to be targeted threats 2f Ability to categorize the following Threats: • Botnet behavior including spam, DDoS, external vulnerability scanning, Bitcoin mining, etc. • Hidden tunnels within HTTP, HTTPS, and DNS used for command-and-control and data exfiltration. Without false positives due to standard beaconing from common tools and apps such as news tickers” will take out simple beacon detectors • The use of algorithmically generated domains or DGAs • Custom RATs (remote administration tools) from normal user traffic • Unknown command & control (no reputation history) using other traffic attributes • Data exfiltration independent of user identity or IP address • Internal reconnaissance of an attacker • Reconnaissance using slow or “paranoid” network scans • Improper use of administrative and management protocols, including RDP, SSH, iDRAC, and IPMI • Activation of sub-OS rootkits using port hijacking • Remote execution of procedure calls or code via SMB or DCERPC protocols 2g Automatically re-categorize behaviors that are caused by approved systems or usage, e.g. network scanners 2h Ability to automatically identify and outline attack campaigns 2h-1 *Link attacker activity across multiple hosts to give comprehensive campaign view 2h-2 *Advanced C&C detection is the foundation 2h-3 *Detect all hosts that have connected to the C&C infrastructure 2h-4 *Highlight relevant lateral detections between hosts 2i Solution must be protocol agnostic 3a Automatically score and prioritize each individual attacker behavior detected 3b Automatically score and prioritize each host based on its behaviors over time 3c Ability to notify staff based on the threat score 3d Provide elevated visiblity of key assets with identifed attacker behaviors 3e Provide individual scores for both threat and certainty / confidence 3f Provide visibility into host interconnectivity 3g Provide packet captures of identified attacker behaviors for analysis 3h Have the ability to find commonalities across multiple devices in the network and present it in a coherent attack campaign of all hosts participating in the campaign 4a Directly identify threats based on packet-level analysis of network traffic 4b Ability to detect network-based threats within encrypted traffic 4c Detect custom or unknown threats, where there is no signature or IP/domain reputation history 4d Solution to be applicable across all user and infrastructure devices (Windows, Mac, mobile devices, byod, IoT, routers, firewalls) 4e Use multiple behavior techniques (Supervised Learning, Unsupervised Learning, Hueristics, Deep Learning) 4f Solution must not use signature-based methodology for detection 4g Solution must have the ability to analyze and correlate network traffic: North, South, East, West traffic 4h Solution must secure the data center within the virtual environment as well as the underlying infrastructure 4i Automate threat hunting at wire speed 4j Ability to perform matching on IOCs introduced via STIX 5a Incorporate learnings from global attacker behaviors and techniques to detect threats on the local network whenever possible 5b Global modeling of threats to be combined with local network learning to improve accuracy and relevance for the local network 6a Detect potentially-malicious anomalies based on deviation from learned local norms within the network 6b Continually learn as the network and usage evolves 6c Ability to detect threats within new devices or devices that were already compromised when baselined 7a Maintain network packet captures of detected attacker behaviors 7b Must not decrypt the traffic in order to analayze 7c Solution must not use Netflow as a data source 7d Solution must use raw network traffic for real-time analysis 7e Utilize Artifical Intelligence capabilities to augment and automate SOC operations 7f Provide limited time links of Hosts or Events for analysis by non-system users. 7g Automate analysis to identify attacks 7h Ability to provide time-limited access to a specific event in the system with others without creating an account 7i All information about detections and hosts available via RESTful API to support automation Ability to detect enumeration of file shares Ability to detect AD/LDAP reconnaissance using techniques similar to Bloodhound Ability to detect use of Powershell/WMI and RPC to move laterally via remote code execution Ability to detect use of stolen RDP client tokens Ability to detect reconnaissance of RDP servers Ability to detect the use of PSexec and other remote administration tools to move laterally via SMB A host being used as a relay to exfiltrate data to an external system à A host being used as a relay for command and control purposes to gain access deeper into the network 10a Must natively integrate with EDR solution such as Microsoft Defender ATP, Carbon Black, Cyberreason, and others. 10b Must natively integrate with SIEM solutions such as Splunk, Archsite, QRadar, Logrythm, and others 10c Must integrate with Firewalls such as PaloAlto, and Fortinet. Must integrate with NAC solutions such as Forescote, Cisco ISE, and Aruba Clearpass. 10d Solution must provide API-driven access to all events, hosts, and scoring information for integration with other security solutions & operational systems 11a The solution must have the ability to automatically update. To reduce the operational burden of the solution, software updates must be an automated process that doesn't require any human intervention. 11b Software system should be updated with a regular frequency to adapt to the constantly evolving threat landscape. 11c When suspicious activity is identified and alerted upon it is critical that the system provide appropriate commentary around the detection including appropriate triggers as well as steps to verify and where to begin potential remediation. 11d The system must meet ALL of the mandatory requirements without a VPN or cloud connection into the environment or any customer identifiable information being sent externally. 11e In order for a fully effective deployment the solution must not requiring any third party object configuration changes (except for span/tap/mirror) such as adding additional locations for logging destinations. 11f Must be able to provide health monitoring via email and syslog. 11g Must be able to alert on individual threats or suspicious hosts via email and syslog 11h Must provide granular role-based access control (RBAC) into the various elements of the product so security analysts can define custom roles with limited access if desired 11i Must have the ability to send audit log over syslog for actions such as login, logout and changes to settings that impact the security posture of the product 13a Capture all traffic traversing the VMWare vSwitch 13b Provide visibility into which physical hosts are covered or uncovered by vSensors 13c Automatically notify staff if there are changes in the virtual environment that impact coverage 13d Provide automated deployment and pairing of vSensors 14a Solution must be able to provide rich network metadata for threat hunting, investigation, compliance, …etc. 14b Metadata must include protocols for east west visibility like RDP, SMB, LDAP, RPC, Kerberos 14c Metadata must be organized by hostname for easy investigation 14d Metadata must be in a format that can be easily understood by security teams 14e Must be able to deliver metadata to popular data lakes such as ELK, Kafka, Syslog, JSON 14f Must be easy to deploy with no ongoing maintenance and performance tuning 14g Can be correlated with other data sources when needed. 14h Intelligent investigation of activity by device 14i On-prem limitless scale when needed and using the existing datalake/SEIM رخص 1 0 0 1 0
توريد وتركيب النظام المتقدم للرد والاستجابة على الأحداث الأمنية للنهايات الطرفية مع الرخص لمدة ثلاثة سنوات ترغب إدارة الأمن السيبراني من الشركات المتنافسة تقديم عروضها لتوريد و تركيب نظام الرد و الاستجابة على الأحداث الأمنية للأجهزة الطرفية و ذلك لعدد 4000 جهاز طرفى مع التركيب و الرخص لمدة ثلاثة سنوات على أن يتوافق الحل مع المواصفات التالية على الأقل :- # Technical requirements Compliant Endpoint Visibility 1.a The solution must support Windows, Linux and MacOS for agents installations 1.b The solution must have one single agent package for workstations , Servers , VDI , ..etc. 2 The solution must automatically collect executables and script file at the first time executed in the environment 3 The solution must automatically and dynamically collect installed software on all endpoints and alert against any identified CVE 4 The solution must record process activities (process start, image load and process exit) in real time 5 The solution must record when a process creates a remote thread in another process, or when a thread is created in the current process by another process 6 The solution must use Yara rule for detection 7 The solution must capture script execution behaviors and allow searches against it. 8 The solution must record file activities (file creation, modification, access and delete) in real time 9 The solution must record network activities (send, receive, establish and DNS query and response) in real time 10 The solution must record USB activities (insert, remove and copy) in real time 11 The solution must record Windows logs for preconfigured Windows logs IDs in real time 12 The solution must support monitoring customizable windows event IDs 13 The solution must record Windows registry keys activity (key access, modify and delete) in real time 14 The solution must record malware detection activities in real time 15 The solution must store all recorded activities\events in a centralized and indexed database to be available for instance "google-like" searches 16 The solution must automatically collects and reports on all software installed across the endpoints in the enterprise. The software details must provide information such as the software Name, Publisher, Version, and Install Date 17 The solution must able to automatically correlate the software and versions to known CVEs from MITRE to provide alerts when vulnerable software is found 18 The solution must identify Known Vulnerabilities CVE-ID with Details and show Links to MITRE CVE or Microsoft KB for each identified software CVE 19 The solution must able to automatically records the first time an executable or script was executed in the environment and collect a copy of the artifact 20 The solution must be able to acquire live state information from target endpoint(s) including but not limited to: a. Current logged-in users b. Current network connections c. Current running processes d. Current members of the local administrators group e. Current installed software f. Current locally installed certificates g. Computer up-time h. Current Anti-virus information i. Current Windows firewall state j. Current Loaded drivers k. Current Windows autorun key values l. Current ARP and DNS caches m. Current hardware inventory n. Current local routing table 21 The solution must support running advanced visibility tasks including but not limited to: a. Capture desktop image b. Enable key logger c. Acquire internet browsing history d. Run packet capture on a target endpoint e. Report OS State and Apply Patches f. Report and Change Host FW State g. Report and Change AV State 22 Ability to view the full life cycle of an executable/process with the file modifications, registry modifications, cross processes, network connections required for Incident response. 23 The solution must be able to ingest open source IoCs and YARA rules and use it to run scans on target endpoint(s) 24 The solution must allow users the ability to query across collected endpoint behaviors and must support saving search queries 25 The solution must have Advanced Query Builder to allows for users to craft queries that include Boolean logic, targeting of endpoint groups for inclusion/exclusion, and assists users in creating these advanced queries that are useful for investigation, behavior rule creation, and threat hunting 26 The solution shall support auto discovery of assets that are being protected or monitored. 27 The solution must record connected endpoint(s) information including but not limited to: host name, IP Address, processor, memory, OS, OS version and last connected time 28 The solution must be able to dynamically update recorded connected endpoint(s) information 29 The solution must support endpoint grouping (static groups, dynamic groups and imported groups) 30 The solution must be able to show endpoint related task results, alerts, USB activities, login history and installed software as part of the endpoint record. Forensic Investigation and analysis 1 The solution must be able to collect forensic disk\volume\file images, collection output must be in forensic collection common file format (DD, E01, AD1 …etc.) 2 The solution must be able to filter disk\volume\file collect based on: a. File extension b. File path c. File name d. File size e. File creation and\or modification date 3 The solution must support file system, physical disk and logical disk images 4 The solution must support scanning deleted and unused disk areas 5 The solution must support scanning archived files 6 The solution must support full memory and\or process dump, collection output must be in forensic collection common file format (RAW, AFF4 …etc.) 7 The solution must be able to extract socket, handles, DLL information from a live process(es), and must support detecting hiding process and injected DLLs 8 The solution must be able to provide event Context (what happened on any endpoint at any time). 9 The solution must be able to provide Endpoint Collector Real-Time & Retrospective Analysis capabilities for Custom Search and Hunting with Advanced Query Builder 10 Raw access to memory, network card and disk 11 The solution must be able to extract and parse windows forensic artifacts including but not limited to: a. Windows Prefetch b. Disk space c. Disk volumes d. Windows registry (jump lists, shell items, ShimCache …etc.) e. Internet browsing history Advanced Threat Detection and Prevention 1 The Solution must support receiving threat intelligence feeds sent by the solution provider 2 The solution must support configuration for automatically check for threat intelligence feeds' updates with configurable intervals 3 The solution must support consuming threat intelligence feeds from other sources (commercial and\or non-commercial) with standard threat intelligence feeds formats (CSV, JSON and STIX) 4 The solution must automatically match all received threat intelligence feeds with all recorded activities\event for detection 5 The solution must integration with virus total for detection 6 The solution must support behavior-based detection via detection rules 7 The solution have preconfigured behavior-based detection rules for detecting know bad behavior, the solution vendor must update the behavior-based detection rules frequently 8 The solution must provide simple method(s) for creating custom behavior-based detection rules 9 The solution must support applying customizable behavior-based detection rules on customizable dynamic endpoint groups. 10 The solution must support integration with other security controls (NIPS, HIPS, FW, HFW, AV …etc.) to support detection by integrations 11 The solution provider should provide natively integrated security controls (network security and forensic and deception) that can constitute a full advanced detection and response platform when integrate with the solution 12 The solution must support running tasks to detect the existence of vulnerability(ies) in an enterprise-wide scale 13 The solution agent must include embedded anti-virus\malware engine 14 The solution must support file(s)\process blacklists 15 The solution must support prevention based on file known bad signatures 16 The solution must support prevention based on YARA rules 17 The solution must use YARA rule editor for prevention rules 18 The solution must support tamper prevention for the agent process 19 The solution must require password for agent uninstallation 20 The solution must support alert enrichments with mapping capability to MITRE ATTCK framework tactics and techniques 21 The solution must report detection and prevention alerts centrally 22 The solution must support yara rules for detection Incident Response 1 The solution must support live target system console/shell access for windows, Linux and Mac operating systems 2 The solution must support live target system file system access with the ability to copy, download, delete, rename and upload files on the target system for windows, Linux and Mac operating systems 3 The solution must support live process with the ability to end process, end process tree, dump process to file, search for similar process on other endpoints on the target system for windows, Linux and Mac operating systems 4 The solution must support running basic response tasks including but not limited to: a. Delete in use file(s) b. Kill process(es) c. Delete 5 The solution must support running advanced response tasks including but not limited to: a. Network isolation b. Halt process(es) c. Modify registry keys d. Install\uninstall application\patch e. Log-off user(s) f. Enable\disable firewall g. Modify\create firewall rules h. Restart\shutdown\standby\hibernate target host 6 The solution must provide multiple fast and efficient methods for incident profiling (Similar process instant searches, IoCs scans, YARA scans, behaviors searches …etc.) 7 The solution automated incident response task based on an occurrence of behaviors/alerts. 8 The solution must support automated incident response playbooks. 9 Response action must be persistent if the target system restarted 10 Incase on network isolation the solution must support configuration for isolated hosts to be able to communicate with specified host(s) 11 The solution must support running script tasks including but not limited to the following scripting languages: VBS, PowerShell, Patch Script, Python, C++, bash …etc. 12 The solution must support process / tree termination from the detection rules Management and administration 1 The solution must support dynamic endpoints logical grouping and applying different settings and/or policies to dynamic groups. 2 The Solution must support Linux server hosted Gateway services to support off-enterprise network communications with the agents 3 The solution management interface must support Web based access and doesn't require any additional management application\add-on to be installed on the web browser 4 The solution must support detailed rule based access for system users 5 The solution must support keeping isolated user management database 6 The solution must support integration with Active directory for authentication and users information 7 The solution agent must support mass installations via AD GPO and/or SCCM system 8 The solution agent must support automated updates\upgrades with minimum administration involvements 9 The solution must support native integration with the same vendor technologies for Network advance Threat detection and Deception 10 The solution must provide an open API for integration 11 The solution must support the ability to arrange endpoints and users in logical groupings. 12 The solution must provide the ability to encrypt communications between components. Endpoint Protection 1 Must provide Process Blocking (by File hashes, IOC or YARA rules) 2 Must provide Global Quarantine of Malware Samples 3 Must discover known application vulnerabilities with details 4 Must provide links to MITRE CVE and/or Microsoft KB 5 Must alert on USB Insertion Installation and Form Factors 1 The solution must support hardware appliance and virtual appliance installations 2 The solution must be fully on premise /Fully Air Gapped. 3 The solution should support Statatic and dynamic grouping for endpoints 4 The solution should support multi-tenant with overall administration for all tetnat and specif view for each tenant 5 The solution must have Windows server hosting user interface and management services isolated from the core solution's services which must be hosted on Linux server 6 The solution must support private and public servers' deployments 7 The solution must support portable form factor servers deployment (all solution services deployment in one portal server) 8 The solution should be part of a platform and suppport out of box integration with NDR & deception soultins for 360 degree visibility & detection 9 The EDR solution must have native integration with Deception solution on the same platform from same vendor to report any post detection attacks . 10 The EDR solution should support distributed management , scalable to handle up to 50K agent under single backend manager. رخص 4000 0 0 2 0

2 بند

كراسة الشروط الرئيسية

كراسة الشروط والمواصفات وملاحق المنافسة

635 KB تم التحميل

2022/425482/main_booklet_كراسة_الشروط.html

فتح

المستندات الداعمة (2 ملف)

ملحق الاسئلة والاستفسارات.pdf

13 KB تم التحميل

2022/425482/idd_0DDF37DC-128D-CA44-8666-821128100000_ملحق_الاسئلة_والاستفسارات.pdf

فتح

نموذج عقد تقنية المعلومات.pdf

566 KB تم التحميل

2022/425482/idd_1E093A99-7296-CE9F-87B9-821128500000_نموذج_عقد_تقنية_المعلومات.pdf

فتح

لم يتم ترسية هذه المنافسة بعد

لا توجد بيانات للمحتوى المحلي

معايير التقييم

لا توجد معايير تقييم

أخبار المنافسة

لا توجد أخبار