As networks continue to evolve and security threats get more complex, security analytics plays an increasingly critical role in securing the enterprise. By combining software, algorithms and analytic processes, security analytics helps IT and security teams proactively (and reactively) detect threats before they result in data loss or other harmful outcomes.
Given that the average time to identify and contain a data breach in 2021 was 287 days, its more important than ever for organizations to include security analytics in their threat detection and response programs. But how has this technology changed over the last decade? In this article, I will explore the evolution and importance of security analytics.
This evolution has had two main trends.
First, security analytics is becoming more sophisticated. In the last 10 years the industry has transitioned from rule-based alerting to big data and machine learning analysis. Second, products have become more open and customizable.
As these technologies have advanced, so too have their specific use cases, with organizations using these for identity analytics (examining authentication, authorization and access for anomalies), fraud (finding anomalous transactions), and more. Today, security analytics plays a central role in Security Information and Event Management (SIEM) solutions and Network Detection and Response products (not to mention standalone security analytics software).
To better understand this evolution and the capabilities of current security analytics solutions, lets dive into the three primary generations of security analytics advancement.
Traditional security analytics focused on correlation and rules within a proprietary platform.
Users imported data into a closed database, the data was normalized and run through a correlation engine, and then the system produced alerts based on rules. Products typically included alert enrichment, which provided more useful context along with an alert, such as linking it to a specific user, host, or IP address.
However, this era often suffered from alert fatigue where the analytic solution produced more alerts than the security team could investigate, including high numbers of false positives. Sorting which alerts were important and which ones werent involved a great deal of manual work. Furthermore, these solutions were often entirely proprietary, with little to no options for customization. This prevented the security team from tweaking rules to cut down on the number of bad alerts. They were stuck with the alert fatigue issue.
The second generation of security analytics began to incorporate big data and statistical analysis, while remaining a black box to users.
These solutions offered data lakes instead of databases, which allowed for a greater variety of data to be gathered and analyzed, but they were still proprietary. New analytics capabilities emerged, such as the ability to include cloud data, network packets and flow data, but users still couldnt see how they worked or verify the results.
Data enrichment was better, but users largely could not customize the contextual data they wanted with their alerts. For example, a security team might want to add asset criticality data so they can prioritize events that affect key pieces of their infrastructure or include information from external sources like VirusTotal.
Many solutions started offering threat hunting capabilities as well, which made it easier for security teams to proactively search for suspicious activity that evaded perimeter security controls.
But false positives and limited bandwidth on security teams continued to be a major challenge. In fact, this remains a challenge today. According to the 2021 Insider Threat Report from Cybersecurity Insiders, 33% of respondents said the biggest hurdle to maximizing the value of their SIEM was not having enough resources and 20% said too many false positives.
The third generation of security analytics technologies brings us to the current day, where machine learning, behavioral analysis and customization are driving innovation.
There are now SIEM products that allow organizations to use their existing data lakes, rather than forcing customers to use proprietary ones. And some solutions have opened their analytics, enrichment, and machine learning models so users can better understand them and modify as needed.
Today, powerful algorithms find patterns in data, set baselines and identify outliers. Theres also a greater focus on identifying anomalous behavior (a user taking suspicious actions) and on prioritizing and ranking the risk of alerts based on contextual information like data from Sharepoint or IAM systems. For example, a user accessing source code with legitimate credentials might be a low-priority alert at best, but that user doing so in the middle of the night for the first time in weeks from a suspicious location should trigger a high-priority alert. Thanks to these capabilities, analytic solutions are reaching the point where they can trigger remediation actions automatically.
Security analytics have evolved quickly in recent years and as we look ahead, the industry is starting to combine SIEM, User Entity Behavioral Analytics (UEBA), Security Orchestration, Automation and Response (SOAR) and Extended Detection and Response (XDR) for a more automated and telemetry rich approach to threat detection and response.
But today, the latest advancements are helping to reduce the workload on security teams, allowing them to better detect and contain both known and unknown threats more quickly. Open access to security analytics is also a monumental shift that helps teams better understand and tweak these solutions so they can verify models and generate better results.
Ideally, analytics solutions should have strong pre-built libraries of machine learning models that dont require users to be data scientists to edit them (but give them the editing option if needed). As these capabilities continue to develop, I believe theyll be a key factor in helping security teams reduce that 287-day average time to contain a breach in the coming years.
See the rest here:
The evolution of security analytics - Help Net Security
- EvolutionM.net - Mitsubishi Lancer Evolution | Reviews, News ... [Last Updated On: June 12th, 2016] [Originally Added On: June 12th, 2016]
- Evolution - Wikipedia, the free encyclopedia [Last Updated On: June 19th, 2016] [Originally Added On: June 19th, 2016]
- Darwin's Theory Of Evolution [Last Updated On: June 22nd, 2016] [Originally Added On: June 22nd, 2016]
- Evolution - Conservapedia [Last Updated On: June 28th, 2016] [Originally Added On: June 28th, 2016]
- History of Evolution | Internet Encyclopedia of Philosophy [Last Updated On: June 28th, 2016] [Originally Added On: June 28th, 2016]
- Darwin's Theory Of Evolution [Last Updated On: June 28th, 2016] [Originally Added On: June 28th, 2016]
- Evolution - Simple English Wikipedia, the free encyclopedia [Last Updated On: June 29th, 2016] [Originally Added On: June 29th, 2016]
- Evolution (2001) - IMDb [Last Updated On: July 5th, 2016] [Originally Added On: July 5th, 2016]
- Introduction to Human Evolution | The Smithsonian Institution ... [Last Updated On: July 7th, 2016] [Originally Added On: July 7th, 2016]
- EvolutionM.net - Mitsubishi Lancer Evolution | Reviews, News ... [Last Updated On: July 12th, 2016] [Originally Added On: July 12th, 2016]
- Evolution - Biology-Online Dictionary [Last Updated On: July 12th, 2016] [Originally Added On: July 12th, 2016]
- Introduction to Human Evolution | The Smithsonian Institution ... [Last Updated On: July 12th, 2016] [Originally Added On: July 12th, 2016]
- Evolution - Bulbapedia, the community-driven Pokmon encyclopedia [Last Updated On: July 12th, 2016] [Originally Added On: July 12th, 2016]
- What is Evolution - explanation and definitions [Last Updated On: July 12th, 2016] [Originally Added On: July 12th, 2016]
- Apps/Evolution - GNOME Wiki! [Last Updated On: July 12th, 2016] [Originally Added On: July 12th, 2016]
- History of Evolution | Internet Encyclopedia of Philosophy [Last Updated On: July 12th, 2016] [Originally Added On: July 12th, 2016]
- Recent Articles | Evolution | The Scientist Magazine [Last Updated On: July 16th, 2016] [Originally Added On: July 16th, 2016]
- Evolution - The New York Times [Last Updated On: July 25th, 2016] [Originally Added On: July 25th, 2016]
- Evolution : Pictures , Videos, Breaking News [Last Updated On: August 2nd, 2016] [Originally Added On: August 2nd, 2016]
- Faculty & Staff - Biology | Biology | High Point University ... [Last Updated On: August 8th, 2016] [Originally Added On: August 8th, 2016]
- Evolution (software) - Wikipedia, the free encyclopedia [Last Updated On: September 2nd, 2016] [Originally Added On: September 2nd, 2016]
- Evolution | Answers in Genesis [Last Updated On: September 2nd, 2016] [Originally Added On: September 2nd, 2016]
- Evolution (2001) - Rotten Tomatoes [Last Updated On: September 18th, 2016] [Originally Added On: September 18th, 2016]
- Human evolution - Wikipedia, the free encyclopedia [Last Updated On: September 22nd, 2016] [Originally Added On: September 22nd, 2016]
- Evolution - Wikipedia [Last Updated On: October 20th, 2016] [Originally Added On: October 20th, 2016]
- MyEvolution // About Evolution [Last Updated On: December 9th, 2016] [Originally Added On: December 9th, 2016]
- Evolution of the Web [Last Updated On: December 10th, 2016] [Originally Added On: December 10th, 2016]
- Evolution | Pokmon Wiki | Fandom powered by Wikia [Last Updated On: January 14th, 2017] [Originally Added On: January 14th, 2017]
- Evolution - RationalWiki [Last Updated On: January 14th, 2017] [Originally Added On: January 14th, 2017]
- Tracking the Evolution of Student Success - Inside Higher Ed [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Ivanka Trump's Beauty Evolution, From 1998 to Today Watch - Us Weekly [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Lumpy, hairy, toe-like fossil could reveal the evolution of molluscs - The Guardian [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- USM Darwin Day: 'Genesis' a parallel to evolution - The Student Printz [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Cultural evolution and the mutilation of women - The Economist [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- How Evolution Alters Biological Invasions - ScienceBlog.com (blog) [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Psychonauts in the Rhombus of Ruin Feels Like an Evolution of Double Fine's Adventure Game Roots - UploadVR [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- The Evolution of Accessible Travel: 5 Podcast Takeaways - Skift [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Convergent Evolution: Why Some Plants Became Carnivorous - Science 2.0 [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- The Queer Evolution of Kristen Stewart - Advocate.com [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Gold's Gym Regina rebrands to become Evolution Fitness - Regina Leader-Post [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Late-night hosts on the evolution of Trump: 'Dickish to dictatorish' - The Guardian [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Exhibition charts 500 years of evolution of robots - Phys.Org [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Blockchain: Investment (R)Evolution For Developing Markets - Forbes [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- See the Evolution of the Famed Porsche 911 in 7 Photos - WIRED [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How evolution turned ordinary plants into ravenous meat-eaters - Wired.co.uk [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Are Evolution Fresh Drinks 'Poison'? - snopes.com [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- The Evolution and Maturation of HPC in the Enterprise - CIO [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- From Whoa to 'Wick:' The Evolution of Keanu Reeves - Film School Rejects [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- 'Goldilocks' genes that tell the tale of human evolution hold clues to variety of diseases - Science Daily [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- London exhibition charts 500 years of evolution of robots - Chicago Sun-Times [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Chimpanzee feet allow scientists a new grasp on human foot ... - Science Daily [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- 'Evolution To Revolution' As New York Fashion Week Gets Political - NPR [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Orangutan squeaks reveal language evolution, says study - BBC ... - BBC News [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Deeper origin of gill evolution suggests 'active lifestyle' link in early ... - Science Daily [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Horse evolution bucks evolutionary theory - Science News [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- From Tara Palmer-Tomkinson to Cara Delevingne: the evolution of the It girl - The Guardian [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Evolution gives rhyme its reason - Aurora News Register [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Evolution of in-car audio tech moving at 'speed of sound' - Times of India [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Scientists solve fish evolution mystery - Phys.Org [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- The Difference Between Healthy Love & Unhealthy Love - Collective Evolution [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- This Woman Was Raped & Forgave Him, So They Did A Ted Talk Together - Collective Evolution [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- A primer on Darwin Day: Some religious groups embrace 'Theistic evolution' - LancasterOnline [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Pokmon Go Eevee evolution: How to evolve Eevee into Vaporeon, Jolteon and Flareon with new names - Eurogamer.net [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Evolution of baseball from power to speed has left SBs behind - Chicago Sun-Times [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- More order with less judgment: An optimal theory of the evolution of cooperation - Science Daily [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- How the horse can help us answer one of evolution's biggest questions - Raw Story [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- China Is Now The World's Largest Producer of Solar Power ... - Collective Evolution [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Community Viewpoint: Evolution, like gravity, is much more than theory it is a fact - Kdminer [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- See the Evolution of Movie Magic With Every Oscar Winner for ... - Gizmodo [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- How the horse can help us answer one of evolution's biggest questions - Phys.Org [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- How evolution alters biological invasions - Phys.Org [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- The Evolution of Valentine's Day - Inside Science News Service [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Why evolution may be tech billionaires' biggest enemy - The Week Magazine [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Russell Westbrook is leading an evolution in NBA rebounding - Washington Post [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Eye Evolution: A Closer Look - Discovery Institute [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- How evolution alters biological invasions -- ScienceDaily - Science Daily [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Evolution always wins: University of Idaho video game uses mutating aliens to teach science concepts - The Spokesman-Review [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Geneticists track the evolution of parenting - Phys.Org [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- How this cockeyed squid shines a light on deep sea evolution - Christian Science Monitor [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Cockeyed squid shines light on deep sea evolution - Christian Science Monitor [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]