The security automation industry is still in its infancy, with most vendors just a year or two old, but there are already some promising technologies that enterprises can put to use -- if they have already laid the required ground work.
The main problem that security automation is designed to address is that there are so many attack attempts coming in, so quickly, that human beings just can't keep up.
Then there's the enormous amounts of money cybercriminals are bringing in from ransomware and other attacks that allows them to invest in new kinds of attacks, the threats posed by nation-states, and the massive staffing shortage.
It's a perfect storm.
"Even the biggest companies can't keep up," said Jon Oltsik, senior principal analyst at Enterprise Strategy Group.
According to a survey the research firm conducted last fall, 91 percent of companies said that the time and effort required for manual processes limits their incident response effectiveness, and the same number are actively trying to increase their staffs.
And 62 percent already have automated incident response processes in place, and another 35 percent are beginning automation and orchestration projects or plan to do so in the next 12 to 18 months.
"Two years ago, nobody knew about this technology," said Oltsik. "Last year, I saw it a lot more. Now we're seeing budget line items for it, and we also see a lot of venture capitalist investment in this space as well."
He estimates the market size of the security automation and orchestration sector to be between $100 million and $200 million, with several small vendors in the $10 million to $20 million in sales range.
Security automation, could, in theory, allow companies to investigate incoming threats and respond to them immediately, without human intervention -- at least, for the most common, labor-intensive types of attacks. Security analysts would then be freed up to focus on the more complex types of attacks.
There have been some recent signs that this may be possible.
"We've had better detection accuracy," said Oltsik. "The false positive rates are lower. And we're using the cloud more, which is throwing more processing power at some of these things."
Most of the progress up until now has been in preventing attackers from entering the enterprise in the first place. Anti malware systems, next-generation firewalls, and other systems that spot threat and block them.
Most recently, threat intelligence comes with scoring systems, said Oltsik. That allows companies to add more automation for threats that have a very high likelihood of being very dangerous, and handle the questionable cases with the old manual processes.
Some of the larger companies are also deploying orchestration platforms. These allow for automated processes that involve multiple systems.
"But these types of incidence response platforms are limited right now to the elite organizations, the Fortune 500 companies," he said.
In addition, companies also write scripts to create their own automated processes from scratch, but this requires some technical expertise.
According to the most recent SANS Institute incident response survey, most processes are still very manual.
The most automated process, with 50 percent of respondents saying they had some degree of automation, was for remotely deploying custom content or signatures from security vendors.
In second place, at 49 percent, was blocking command and control to malicious IP addresses, followed by removing rogue files, at 47 percent.
Processes least likely to be automated included isolating infected machines from the network during remediation, and shutting down systems and taking them offline.
But, overall, security automation is about 10 years behind the automation of other technology processes, said Ariel Tseitlin, partner at Foster City, Calif.-based investment firm Scale Venture Partners.
"But we've seen the tremendous effect of automation in IT, and we're gong to see that in security," he said.
The prevention part of the security puzzle is the most automated, he said. Then, in the past two years, detection has seen an enormous amount of investment.
Now, there's a lot of work being done on the boundary between detection and response, where companies need to figure out which of the issues they've spotted are real problems that need to be investigated.
"Then, on the incident response side, there's an enormous amount of work that is being done manually today," he said. "That's where I think a lot of the value will come over the next couple of years."
However, all the products available today are still in their early stages, he said, and there are no clear established leaders in this space.
It makes sense to automate detection, but fully automating the remediation process is risky, said Jay Leek, managing director at ClearSky Cyber Security, a cybersecurity consulting firm.
"I would always recommend, at least today, putting a person between these two different divisions," he said. "You don't want to have false positives here."
The individual steps of the remediation process could be automated, he said, just as long as there's a human being pushing the button to get it started.
"But i don't like the idea of automating the whole end-to-end process today," he said. "It's too immature and ripe for false positives. The last thing you want to do is create some sort of business disruption."
There are vendors in the market who are already promising to automate the entire process, including automatically re-imaging end point devices and sending users off to anti-phishing training, said Nathan Wenzler, chief security strategist at AsTech Consulting.
"But at the end of the day, the reality is that anyone who's been trying to do that at scale, that hasn't really worked well," he said. "They either get so many false positives, or so many false negatives. You get annoyed users, especially if you do get a system that's re-imaged and there's nothing wrong, or at bad times."
Soon, security automation may become ever more widely available and easier to use. Major vendors have been buying up small orchestration companies and integrating their features into their platforms, and SIEM vendors have been adding automation and orchestration capabilities to their platforms.
Vendors are also starting to offer pre-built routines and run books so that companies don't have to create their remediation processes from scratch.
One positive aspect of the way automation technology is evolving is that we don't have vendor stacks or technology silos, where products from one group of companies don't play well with others, according to Joseph Blankenship, analyst at Forrester Research.
That's happened before, in other areas of IT. In security, however, enterprise environments tend to be very heterogeneous.
"It's common for enterprises to have 20, 50 or more different vendors," he said.
As a result, vendors are motivated to work well together, and limitations on interoperability aren't likely to be accepted by customers, he said.
For companies looking to deploy security automation technology, it's not enough to establish whether the vendor's product is ready for prime time.
The company has to be ready, as well, said Blankenship.
"It's definitely not a buy it and plug it in scenario," he said. "There's definitely ground work that needs to be done. If you plug bad data into an automated system, all you're going to do is make bad decisions faster."
In addition, many companies don't actually know what their processes are, and may not yet have well-defined playbooks, he said.
"Many have analysts that each do their own things as far as how they handle different investigations," he said. "In order to automate these things, you have to have standardization."
Link:
Security automation is maturing, but many firms not ready for ... - CSO Online
- Automation Personnel Services - Temporary Staffing ... [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation | Define Automation at Dictionary.com [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation | Definition of automation by Merriam-Webster [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation | The Car Company Tycoon Game [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation - Wikipedia, the free encyclopedia [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation - Cloud process & workflow automation | Microsoft ... [Last Updated On: June 29th, 2016] [Originally Added On: June 29th, 2016]
- Riverside Automation - Machine Controls [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Automation: The Car Company Tycoon Game Windows - Mod DB [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- System Integration | Industrial Automation [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- WinAutomation - Smart Macro Recorder, Web Automation ... [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Automation Solutions - Home [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- The Automation Conference [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Rohtek Automation [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- JL Automation, LLC | Home Automation, A/V Automation [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Four fundamentals of workplace automation | McKinsey & Company [Last Updated On: August 27th, 2016] [Originally Added On: August 27th, 2016]
- Leviton Security & Home Automation [Last Updated On: August 27th, 2016] [Originally Added On: August 27th, 2016]
- EVA Automation [Last Updated On: September 6th, 2016] [Originally Added On: September 6th, 2016]
- News | Automation | The Car Company Tycoon Game [Last Updated On: September 6th, 2016] [Originally Added On: September 6th, 2016]
- Automation - The Car Company Tycoon Game on Steam [Last Updated On: September 6th, 2016] [Originally Added On: September 6th, 2016]
- Test automation - Wikipedia, the free encyclopedia [Last Updated On: September 6th, 2016] [Originally Added On: September 6th, 2016]
- Job Seekers - Automation Personnel Services [Last Updated On: October 8th, 2016] [Originally Added On: October 8th, 2016]
- Custom Automation & Machine Design | Automation GT [Last Updated On: October 31st, 2016] [Originally Added On: October 31st, 2016]
- iAutomation [Last Updated On: October 31st, 2016] [Originally Added On: October 31st, 2016]
- Test automation - Wikipedia [Last Updated On: November 16th, 2016] [Originally Added On: November 16th, 2016]
- Automation - Official Site [Last Updated On: November 19th, 2016] [Originally Added On: November 19th, 2016]
- Beckhoff Automation - Wikipedia [Last Updated On: November 21st, 2016] [Originally Added On: November 21st, 2016]
- Automation - Security Hyperstore [Last Updated On: November 21st, 2016] [Originally Added On: November 21st, 2016]
- IT Automation - BMC [Last Updated On: November 29th, 2016] [Originally Added On: November 29th, 2016]
- ID Automation [Last Updated On: November 29th, 2016] [Originally Added On: November 29th, 2016]
- The Best Home Automation Systems of 2016 | Top Ten Reviews [Last Updated On: December 24th, 2016] [Originally Added On: December 24th, 2016]
- What is Home Automation? | Home Automation Systems [Last Updated On: December 24th, 2016] [Originally Added On: December 24th, 2016]
- Beyond Automation - hbr.org [Last Updated On: December 25th, 2016] [Originally Added On: December 25th, 2016]
- Build automation - Wikipedia [Last Updated On: December 26th, 2016] [Originally Added On: December 26th, 2016]
- Home automation - Wikipedia [Last Updated On: January 10th, 2017] [Originally Added On: January 10th, 2017]
- Automation | Food Engineering [Last Updated On: January 13th, 2017] [Originally Added On: January 13th, 2017]
- Home Automation - Enerwave Home Automation [Last Updated On: January 14th, 2017] [Originally Added On: January 14th, 2017]
- Automation - DESHAZO [Last Updated On: January 14th, 2017] [Originally Added On: January 14th, 2017]
- Robots, Automation, EOAT, Grippers, Conveyors, Guarding [Last Updated On: January 26th, 2017] [Originally Added On: January 26th, 2017]
- Werner Electric | Automation [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Automationtechies | Automation Engineering Recruiting [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Automation - Mazak Corporation [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Automation | Technologies | Systems | Integrator ... [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Test Automation Services for Development of Regression ... [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Carlo Gavazzi Automation Components [Last Updated On: January 30th, 2017] [Originally Added On: January 30th, 2017]
- UI Automation Overview - msdn.microsoft.com [Last Updated On: February 5th, 2017] [Originally Added On: February 5th, 2017]
- New telecom transformation goals require service automation - TechTarget [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Global Hazardous Waste Handling Automation Market: By Products ... - Business Wire (press release) [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- 2M Automation wins IoT support from Schneider - Electronics EETimes (registration) [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Futures Shaped by Automation and Catastrophe: Peter Frase on Capitalism's Endgame - Truth-Out [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Automation expected to displace insurance underwriters, real estate brokers - CIO Dive [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Automation, robots could replace 250000 public sector workers in the next 15 years - Computer Business Review [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Design Automation Conference - Business Wire (press release) [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- The Perks Of Automation And The Risks: Why To Think Twice About Getting Into That Driverless Uber - Forbes [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Lib Dems Should Embrace Automation of the Workforce - Liberal Democrat Voice [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Voices Reinventing enterprise finance by overhauling AP automation - Accounting Today [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How Accountants Can Use Automation Their Advantage - Accountingweb.com (blog) [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- DFLabs Launches the First Security Automation and Orchestration Platform based Upon Supervised Active Intelligence - Business Wire (press release) [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- QAD Automation Solutions is Honda Approved - Yahoo Finance [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- VIDEO: Going Big on Automation in a Small Footprint Facility - ENGINEERING.com [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Building a better model of human-automation interaction - Phys.Org [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- AlixPartners examines automation in manufacturing and logistics management - Logistics Management [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Report: Test automation is increasing - SD Times - SDTimes.com [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Automation is the unavoidable future of the economy - The Daily Cougar [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- GM's Cruise Automation Is Testing An App to Order Self-Driving ... - Fortune [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Speeders beware: Legislation would allow automation crackdown ... - SFGate [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Orbita Ingenieria: New Age Terminal Automation - Port Technology International [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- A Sharper Focus on the Edge - Automation World [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Rockwell Automation Surged 10% in January as Growth Picked Up Steam - Motley Fool [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Most people are optimistic about workplace automation, social data suggests - ZDNet [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Improving Behavior Through Automation of Vehicle Systems - School Transportation News (blog) [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- 'We employ insane levels of automation' Kris Canekeratne - Times of India [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Why Don't We See More Automation in Federal Networks? - Nextgov [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Technobabble: Automation and the modern worker - CIO Dive [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Readers Write (Feb. 12): The moose population; jobs, start-ups and automation; diversity in the funny pages - Minneapolis Star Tribune [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Automation Nightmare: Philosopher Warns We Are Creating a World Without Consciousness - Big Think [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Automation can replace bureaucrats and save taxpayers money - Hot Air [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Automation can revitalize the US workforce - Fox News [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- TigerStop hopes to ride automation to new heights - The Columbian [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Hexadite Unveils Custom Playbooks Following One Millionth Automated Cybersecurity Investigation - Yahoo Finance [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- NEC updates postal automation system for Hongkong Post - ETCIO.com [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]