Three Reasons why SIEMs are not Enough

Blog

Security Information and Event Management (SIEM) tools are often used to detect threats. Rules are set up to monitor the environment and once a rule is violated, it triggers an alert. Security Operation Centers spend months configuring the rules to ensure that they are triggered only when malicious behavior is present. However, as you will learn from this blog, it is very easy to break rules and the SOC doesn’t even know! So, when there are fewer rules being triggered which means fewer alerts, the SOC doesn’t realize that there are actually threat actors in the environment, and that is not good.

  1. 25% of the time, the rules are broken.
    1. The rules, out-of-the box, are not suitable for the environment, and are broken. The SOC team needs to configure the rules to customize them to the environment. Additionally, patches, updates, and new software when introduced to the environment can all break the rules as well! After the SOC team has spent so much time carefully configuring the rules, a simple patch can cause a change in the cloud architecture that the rule does not recognize, so the rule no longer fires. This can give the SOC a false sense of security as they are not getting alerts, so they assume all is well. It could actually be a dire situation as not only are threat actors likely to be in the environment, they are moving about the cloud completely undetected with rules no longer able to effectively monitor the cloud.
  2. Constant management increases operational costs.
    1. With it being so easy to break the SIEM rules, this means the SOC really needs to examine all the changes in the environment and review how this impacts rules. Security teams must constantly review patches, updates, application changes, and development changes and review which rules are impacted and then update those rules. This operational overhead is just exhausting. It is also expensive – with 75% of the total cost being for installation, management, and staffing!
  3. Without intent or context, the SOC can waste significant amounts of time chasing alerts.
    1. Rules are a black and white response to a security issue. The intent behind the activity is not a factor into whether or not a rule triggers an alert, in some cases, it was found that only 15% of rules was creating 95% of alerts! These noisy rules means that security analysts are wasting their time on benign activities. Adding insult to injury, during this time, a threat actor could be moving about their environment.

SIEMs can help organizations that have many behaviors or activities that are binary in terms of their response. However, for organizations that have more complex clouds, and most do, those teams really need a platform that looks at the context, the intent behind the activity, and tells the attack story. This makes it easy for SOC to understand why a behavior is concerning, so they know how to address and can do so quickly.

To learn more about Skyhawk Synthesis Security Platform which leverages AI and ML to identify malicious behaviors and the intent behind them, check out our whitepaper on the Three Common Use Cases for Cloud Threat Detection.

Blog

Today’s security team is overwhelmed with alerts. On average, the SOC has 4,500 daily alerts. These need to be resolved fast and at machine speed. SOC, DevSecOps, DevOps, and Cloud Security teams cannot manually address all these alerts, automation needs

ManagementAICloud BreachCloud SecurityData BreachThreat Detection
Blog

In recent months, the debate over agentless vs. agent (or sensor-based) cloud security has witnessed an amplified discussion. According to Forbes, an update of the Falcon Sensor from CrowdStrike causes an endless loop of bluescreens on Microsoft systems. This agent

Cloud SecurityAICloud BreachData BreachThreat Detection
Blog

The EU Network and Information Security (NIS) Directive will be update to a newer version, NIS2 on 17 October 2024.  NIS1 was signed exactly 8 years ago, on July 2016 with the aim of achieving “a high common level of security

Cloud SecurityCloud BreachData BreachDDoS
Blog

At the RSA conference there was a CISO panel, talking about the perils of becoming a CISO. Joe Sullivan, the CISO of Uber who just avoided jail time but did have to pay a $50,000 fine has noticed a real

ManagementAICloud BreachCloud SecurityData BreachThreat Detection
Blog

Euro 2024 viewership has been strong throughout the event and millions of visitors and viewers of the games themselves are also expected. Berlin alone is expected to host 2.5 million tourists during the month of the games. Such a large

Cloud SecurityAICloud BreachData BreachThreat Detection
Blog

According to Gartner, 75% of organizations have a Continuous Threat Exposure Management program in place or are evaluating it. Why are so many organizations embracing this approach? In our opinion, it is the embracing of continuous feedback. As Skyhawk focuses

Cloud SecurityAICloud BreachData BreachThreat Detection

Thanks For Reaching Out!

One of our expert will get back to you
promptly at asafshachar@gmail.com

See the Purple Team
See the breach before it happens
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.