Saturday, 22 February 2025
28.5 C
Singapore
33.4 C
Thailand
21.1 C
Indonesia
26.4 C
Philippines

Elastic revolutionises SIEM with AI-driven analytics

Elastic revolutionises SIEM with its new AI-driven security analytics, enabling SOCs to prioritise attacks efficiently and enhance their operational response.

Elastic, known as the Search AI Company, has unveiled a new AI-driven security analytics platform set to transform traditional Security Information and Event Management (SIEM) approaches for Security Operation Centres (SOCs). Their latest feature, Attack Discovery, simplifies the detection process by filtering hundreds of alerts to highlight the most critical attacks using just one click. This innovation, powered by Elastic’s Search AI platform, automates much of the manual configuration, investigation, and response tasks that have long burdened security teams.

The Search AI platform integrates search and retrieval augmented generation (RAG), drawing on advanced search technology to produce highly relevant results swiftly. This approach ensures that Elastic’s security solutions are built on rich, current data, crucial for delivering precise outcomes tailored to specific security needs.

Transforming alert management with Attack Discovery

Attack Discovery stands out by utilising the Search AI platform to sort through alerts and identify key details that should be assessed. Leveraging Elastic’s Elasticsearch, the feature queries the vast context available in Elastic Security alerts, retrieving pertinent data such as host and user risk scores and alert reasons. This enables the system to instruct the underlying large language models (LLMs) to prioritise the most significant attacks efficiently.

Ravi Rajendran, area vice president of Southeast Asia at Elastic, highlighted the significance of this innovation for Singapore, noting the Cyber Security Agency of Singapore’s findings: two in five businesses in the country struggle with adequate cybersecurity resources despite frequent incidents. “Attack Discovery will empower businesses to slash the resource burden, freeing security teams from the grind of low-level tasks. This allows them to focus their expertise on what matters most: responding to and mitigating real threats,” Rajendran explained.

Proactive cybersecurity measures are essential for business survival

Asjad Athick, Elastic’s Cybersecurity Lead for Asia Pacific and Japan, discussed the high stakes of cybersecurity incidents, emphasising the potential for data loss, reputation damage, and severe financial consequences, especially for small and medium-sized enterprises. “This is why proactive cybersecurity measures are crucial for businesses to protect their public image and ensure survival in today’s ever-evolving threat landscape,” Athick stated, underscoring the importance of swift detection and response to protect businesses in a rapidly evolving threat environment.

In typical SOCs across Singapore, analysts manually sift through thousands of alerts daily, a tedious and error-prone process. Elastic Security’s Attack Discovery automates this by filtering out irrelevant alerts and mapping significant ones to specific attack chains, allowing analysts to focus on genuine threats. This efficient triage process facilitated by LLMs aids analysts in spending less time on preliminary alert assessments and more on detailed investigations and resolutions.

Since its inception in 2019, Elastic Security has expanded to include over 100 prebuilt machine learning-based anomaly detection jobs and, more recently, the Elastic AI Assistant for Security, which aids SOC analysts in rule authoring, alert summarisation, and integration recommendations.

Hot this week

MOVA unveils innovative smart cleaning solutions in Singapore

Experience the future of smart home cleaning with MOVAโ€™s latest innovationsโ€”the Z50 Ultra robot vacuum and X4 Pro wet & dry vacuum. Unveiled at Jewel Changi Airport, these cutting-edge appliances redefine effortless cleaning with AI-driven intelligence, advanced mopping, and powerful suction.

ASUS ZenScreen Duo OLED: A portable dual-screen setup for enhanced productivity

ASUS has launched the ZenScreen Duo OLED, a compact and lightweight dual-screen monitor designed for professionals and gamers on the go.

JBL’s Tour Pro 3 earbuds introduce a more prominent display and more features

JBL's new Tour Pro 3 earbuds offer a larger display, improved sound, and longer battery life. Find out more about these high-end wireless earbuds.

Tesla refreshes Model Y for Singapore, adding new features and design updates

Teslaโ€™s refreshed Model Y is now available in Singapore with an updated design, improved interior features, and enhanced performance.

Apple’s first foldable iPhone might not look like a Galaxy Z Fold

Appleโ€™s foldable iPhone may not resemble Samsungโ€™s Z Fold. A wider design and later launch are expected.

Nvidia acknowledges RTX 5090 and 5070 Ti manufacturing defect

Nvidia confirms a rare manufacturing defect in the RTX 5090 and 5070 Ti, affecting less than 0.5% of GPUs. Affected users can request a replacement.

DJIโ€™s RS 4 Mini stabiliser now features advanced subject tracking

DJIโ€™s RS 4 Mini stabiliser introduces subject tracking, improved battery life, and better handling, making it an excellent tool for content creators.

American Airlines introduces AirTag location sharing for lost luggage

American Airlines now supports Appleโ€™s AirTag location sharing, making it easier for passengers to track and recover lost luggage.

Google may launch YouTube Premium Lite in more countries

Google may launch YouTube Premium Lite in the US, Australia, Germany, and Thailand, offering a cheaper plan with fewer ads. Pricing is yet to be confirmed.

Related Articles