Abstract

It's becoming trendy to talk about big data, however you care to define it. But security practitioners are all too aware of the problems of drowning in data. Mention ‘logs’ to network managers and watch them twitch. That reaction has one of two causes: guilt, because they haven't been monitoring their system logs nearly as much as they should; or exhaustion, because they have. Security Incident and Event Management (SIEM) tools were supposed to put an end to the slog of wading through system logs looking for possible security breaches. But they still produce many false positives and negatives. The MetaGrid system from Red Lambda uses artificial intelligence techniques to monitor networks and identify anomalous behaviour. The company's COO, Todd Krautkremer, explains how the system's ability to correlate data and events – and present its results visually – enables security and network specialists to achieve a higher level of situational awareness when it comes to their networks.

Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call