Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics

2/27/2014
01:39 PM
50%
50%

Big Data A Big Focus Of Security Analytics Products

At the RSA Conference this week, vendors pitched big the importance of properly leveraging big data to improve security

RSA CONFERENCE 2014 -- San Francisco -- "Big data" is a phrase still greeted with skepticism in the world of security.

RSA Conference 2014
Click here for more articles about the RSA Conference.

"The term is sort of nebulous to security people," says Jon Oltsik, senior principal analyst with Enterprise Strategy Group. "They've already been collecting tons and tons of data."

But there is no shortage of vendors building a case for big data around network forensics and risk management. Here at the RSA Conference, a number of companies -- from IBM to Agiliance to EMC's RSA security division itself -- have made announcements about leveraging big data to improve security.

"There [are] so many events happening at the network layer, so the ability to do stream processing across those events and detect anomalous, malicious behavior is important," Oltsik says.

In partnership with Pivotal, EMC's RSA security division released the "Big Data for Security Analytics" reference architecture (PDF), with the goal of speeding the detection and response time for enterprises dealing with attacks.

"The architecture uses a much more open and flexible Hadoop-based architecture that has an entire ecosystem of tools built around it, rather than proprietary tools that can’t take advantage of these innovations," explained Paul Stamp, director of product marketing at RSA, in a blog post. "Through this reference architecture, security teams can get a complete set of analytic tools, specifically designed for enterprise security and threat detection, not just a generic platform that leaves much of the creation of tools to support the security team to the end customer."

An announcement from Agiliance fits into the same mold. The company released RiskVision 7, which introduced what the company calls "Big Data Risk Management." With RiskVision 7, customers can mine petabytes of operational and security risk data from such sources as ERP systems and third-party business applications. The latest version of RiskVision contains a new object framework that allows the consumption of large data records and a new logic framework that offers dynamic data workflows to streamline operational risk audits, according to the company.

"Agiliance eschews the status quo in risk management by replacing managerial opinion and tactical consulting with a purpose-built, big data solution for customers and partners to manage business performance," said Joe Fantuzzi, president and chief executive officer at Agiliance, in a statement. "Modern risk management requires real-time data and business self-sufficiency so risk owners can respond to business, board, and regulator demands in a timely and accurate fashion."

Rounding out the product releases was a partnership from Narus and IBM, in which the two companies pledged to work together to provide faster resolution of security threats using IBM's InfoSphere BigInsights and Narus' nSystem technology. In the joint announcement, the companies stated that the integration with IBM InfoSphere Stream enables nSystem to run streaming data analytics on large data flows.

"The Narus and IBM collaboration brings big data analytics innovations to market and provides the stability and scalability required to address the needs of large enterprises," said John Trobough, president at Narus, in a statement. "The initial focus on cybersecurity brings the deep visibility and rich context required to make the right security decisions quickly and accelerate the time to resolution of malicious threats."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Brian Prince is a freelance writer for a number of IT security-focused publications. Prior to becoming a freelance reporter, he worked at eWEEK for five years covering not only security, but also a variety of other subjects in the tech industry. Before that, he worked as a ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
SaraJ828
50%
50%
SaraJ828,
User Rank: Apprentice
5/8/2014 | 7:28:48 AM
Big Data A Big Focus Of Security Analytics Products
It has been estimated that nearly half of the data that has been created and stored, is unprotected. I believe there are software that encrypt and protect data. I personally rely on software like Data Protecto. I dont know why companies or countries don't use encryption software to protect their sensitive data.
KellyG077
50%
50%
KellyG077,
User Rank: Apprentice
3/12/2014 | 10:56:57 AM
re: Big Data A Big Focus Of Security Analytics Products
Interesting phrase used at the start of article called big data, And it is very helpful to see people concerned about data security now a days.
As the term used big data and big security, So one should use a best encryption software available,I just found out this encryption software called #dataprotecto which is very handy and useful in protecting high volume of data.
News
FluBot Malware's Rapid Spread May Soon Hit US Phones
Kelly Sheridan, Staff Editor, Dark Reading,  4/28/2021
Slideshows
7 Modern-Day Cybersecurity Realities
Steve Zurier, Contributing Writer,  4/30/2021
Commentary
How to Secure Employees' Home Wi-Fi Networks
Bert Kashyap, CEO and Co-Founder at SecureW2,  4/28/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-22675
PUBLISHED: 2021-05-07
The affected product is vulnerable to integer overflow while parsing malformed over-the-air firmware update files, which may allow an attacker to remotely execute code on SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, C...
CVE-2021-22679
PUBLISHED: 2021-05-07
The affected product is vulnerable to an integer overflow while processing HTTP headers, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK v...
CVE-2020-14009
PUBLISHED: 2021-05-07
Proofpoint Enterprise Protection (PPS/PoD) before 8.17.0 contains a vulnerability that could allow an attacker to deliver an email message with a malicious attachment that bypasses scanning and file-blocking rules. The vulnerability exists because messages with certain crafted and malformed multipar...
CVE-2021-21984
PUBLISHED: 2021-05-07
VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious actor with network access may exploit this issue causing unauthorised remote code execution on vRealize Business for Cloud Virtual Appliance.
CVE-2021-26122
PUBLISHED: 2021-05-07
LivingLogic XIST4C before 0.107.8 allows XSS via feedback.htm or feedback.wihtm.