Exabeam
Exabeam
Background of the Need for More Efficient Security Operations
Recent work style reforms have led to the spread of remote work and increased use of cloud-based SaaS services such as Office 365, making internal networks more complex and widespread. Furthermore, cyberattack methods have become more sophisticated and diverse, and security products are now sending out a large number of alerts, including false positives.
It is difficult for operations managers to respond to all alerts, and there is a risk that important alerts will be overlooked and develop into incidents. In addition, as internal networks become more complex and widespread, the time required to investigate and analyze incidents can lead to more serious incidents.
Exabeam's UEBA technology solves the security operations challenges faced by customers through a new type of security operation centered on people.
(1) Increased complexity of intrusion routes and expansion of targets for monitoring and investigation
Due to the mixture of on-premises, cloud, and home environments, the complexity of intrusion routes and the expansion of targets for monitoring and investigation
It has a SIEM function that enables log collection from on-premise environments, cloud services, and terminals, and can automatically visualize the behavior of each user and detect abnormal behavior.
In addition, the SOAR function can be used to automate incident response and reduce the operational man-hours of security operators.
②ログ分析に高いスキルと膨大な工数が発生
複雑化した膨大なITシステムと、多数のセキュリティ製品の導入により、ログ分析に高いスキルと膨大な工数が発生
With conventional SIEM, even though it is possible to collect logs from multiple IT systems and security products, it was necessary to spend time manually creating rules to analyze the logs in a correlated manner.
Exabeam uses the Smart Timeline feature to automatically organize a wide variety of logs, allowing you to quickly understand the behavior of each user without advanced skills.
(3) Tight operation man-hours
Overwhelming operation man-hours due to a large number of logs and alerts from each management device
While traditional SIEM requires action for each alert, Exabeam combines dynamic and static rules based on machine learning, scores and alerts based on total risk. By notifying operators of alerts when preset thresholds are exceeded, there is no need to respond to individual alerts from each device, reducing the number of items to be investigated and reducing the burden on operators. mitigate.
Please feel free to download it.
Inquiry/Document request
In charge of Macnica Exabeam Co., Ltd.
- TEL:045-476-2010
- E-mail:exabeam-sales@macnica.co.jp
Weekdays: 9:00-17:00