Welcome Guest. | Log In | Register | Membership Benefits

LogRhythm SIEM Pattern Recognition Engine Uncovers Security Threats

AI Engine users have immediate access to all relevant forensic data

Feb 09, 2011 | 06:10 PM | 


BOULDER, Colo., Feb. 8, 2011 - LogRhythm, the company that makes log data useful, today announced the LogRhythm Advanced Intelligence (AI) Engine for its integrated SIEM 2.0 (security information & event management) platform which transforms the creation of complex pattern recognition policies into a simple drag and drop operation. The AI Engine enables organizations, without writing any scripts, to detect sophisticated intrusions, fraud, insider threats, zero-day attacks, advanced persistent threats (APT) and other suspicious activity that would otherwise go unnoticed. AI Engine goes beyond simple correlation and provides advanced pattern recognition capabilities that identify related events, statistical deviations, and behavioral abnormalities within all log data, rather than just a pre-filtered subset of security events. AI Engine users also have immediate access to all relevant forensic data enabling rapid investigations and remediation.

"LogRhythm has removed the two biggest barriers to making pattern recognition within log and SIEM data really work -- they've made it incredibly easy to create and modify sophisticated rules and apply those rules against all log data," said Chuck Daye, Senior Vice President and MIS Administrator at The First National Bank and Trust Company, Chickasha, Oklahoma. "With a broad library of rule sets available out-of-the-box and highly intuitive GUI, AI Engine will enable us to gain much broader visibility to threats and risks in our datacenter, branches, and even ATM locations."

Real-Time Pattern Recognition across Log and SIEM Data

Organizations are increasingly being targeted by surgical and sophisticated attacks. According to the Verizon/Secret Service 2010 Data Breach Investigations Report 54% of all breaches involved modified or custom malware. Since custom attacks cannot be detected with traditional signature-based security solutions, a more comprehensive approach to identifying threats is necessary. To make the invisible visible across the largest IT networks, the LogRhythm AI Engine goes beyond basic correlation and performs pattern recognition on all log and SIEM data in real-time. Traditional SIEM 1.0 products only correlate on the 1-5% of logs deemed to be security events at the time of capture.

The ability of AI Engine to perform pattern recognition enables LogRhythm to identify threats and conditions that do not follow a sequential "if a, then b, then c" pattern, and would not be detected by traditional correlation rules. Leveraging LogRhythm's universal time stamping function, AI Engine's TrueTimeT feature ensures pattern recognition and correlation on all logs is based upon the actual time of occurrence rather than the time of collection or analysis, thus minimizing false positives and avoiding false negatives.

Complex Rules: No Scripting, No Problem

To create or modify advanced pattern recognition rules extremely quickly and easily, AI Engine features a highly intuitive graphical user interface that uses point and click, drag and drop operations rather than complex scripting. The AI Engine provides a building block work flow palette for creating pattern recognition policies, a large library of pre-defined immediately usable rules, a common event language of English terms and over 50 intuitive metadata fields to further define policies. For the first time, creating, modifying and managing complex rules is simple. The AI Engine provides the flexibility to create very granular rules for detecting specific patterns, exceptions or conditions, and the ability to apply more general rules for broader visibility.

"Until now, building correlation rules in SIEM products has effectively required a PhD in scripting languages and a very precise understanding of the activity, condition or exception you were looking for," said Chris Petersen, co-founder and CTO of LogRhythm. "We designed the LogRhythm AI Engine to harness hybrid analysis techniques applied across all log data to deliver next generation pattern recognition capabilities, including complex correlation. We focused on delivering what is inherently sophisticated via an easy-to-use, wizard-based rule builder that empowers our customers with new levels of visibility into intrusions, insider threats, and network abuse that would likely go unnoticed by first generation SIEM products."

Detect and Protect Against Stealthiest Attacks

AI Engine performs pattern recognition on multiple variables and contextual information, enabling organizations to detect and protect against sophisticated attacks that fly under the radar of traditional security solutions. Some examples include:

. Same account being used to login from two different countries nearly simultaneously . Data leaving the network destined for a rogue nation . Non-email servers sending thousands of SMTP messages to hosts across the world (i.e. a botnet infestation sending spam) . Observing the exact same error message on more than 100 different servers . A user downloading a statistically large number of account records from a CRM database

Pricing and Availability

The LogRhythm AI Engine is in beta and will be available next month. LogRhythm AI Engine appliances support up to 1 billion logs per day. The AI Engine is also available in a software form factor that can be deployed in VM environments including VMWare, Microsoft and Citrix. The AI Engine integrates seamlessly with any existing LogRhythm deployment. Entry-level pricing starts at $6,000.

About LogRhythm

LogRhythm, the leader in log management and SIEM 2.0, delivers log and security event management, file integrity monitoring, and network and user monitoring in a single integrated solution. LogRhythm empowers organizations to comply with regulations, secure their networks, and optimize IT operations. The company received the coveted "Recommended" 5-star designation from SC Labs and has received SC Magazine's Innovator of the Year Award, Readers Trust Award for "Best SIEM" solution and the "Best Buy" designation for Digital Forensics. It is a winner of the 2010 Red Herring 100 Award and was placed by Gartner Inc. in the visionaries quadrant of the Security Information and Event Management (SIEM) Magic Quadrant report for 2010. LogRhythm is privately held and based in Boulder, Colorado with European Headquarters in Maidenhead, England, and Asia Pacific operations in Hong Kong. For more information visit: www.logrhythm.com.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS












Featured Webcasts
Featured Whitepapers
Featured Reports
Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)