enterprisesecuritymag

Stellar Cyber Unveils AI-Powered Incident Correlation

Enterprise Security Magazine | Tuesday, August 10, 2021

Changming Liu, CEO, Stellar Cyber

Stellar Cyber has announced a significant advancement in security analyst efficiency, allowing them to detect assaults rapidly.

FREMONT, CA: Stellar Cyber, the provider of Open XDR, the only intelligent, next-gen security operations platform, has announced a significant advancement in security analyst efficiency, allowing them to detect assaults rapidly. Innovative GraphML algorithms are used in the latest incident correlation technology to automatically aggregate and integrate massive amounts of alerts and events into a considerably smaller number of highly accurate and actionable incidents. The development provides security analysts with far more actionable data on how and where attacks happen and the most serious ones.

'Stellar Cybers initial interface aimed to increase security analyst efficiency by presenting a lot of critical information in an easy-to-read format, but the AI-powered incident correlation represents a leap by orders of magnitude," said Rik Turner, Principal Analyst at Omdia. "The new approach uses the company's machine learning algorithms to automatically group and prioritize events, avoiding the pitfalls of a flood of minimally productive alerts. Now analysts can see the source and progression of attacks more quickly and take action to curtail them in a timely fashion."

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

By incorporating several related alerts and events for far higher levels of accuracy and intelligence, switching from an alert-based to an incident-based detection significantly increases detection efficiency. The method reduces the issue of various individual alerts with a high percentage of false positives. This ability allows security analysts to boost their effectiveness by orders of magnitude by drastically lowering the amount of manual work they have to do and the number of cases they have to deal with. The ground-breaking technique prioritizes instances by offering more detail and better context and by using automatic scoring. The Mean Time to Detection (MTTD) and the Mean Time to Resolution (MTTR) decrease immensely, lowering the risk of current cyberattacks.

"Stellar Cyber's new AI-driven incident correlation alert grouping capability makes it far easier for our teams to prioritize collections of alerts that point to an attack. Attacks that might have taken days or weeks to discover are now obvious in minutes," states Presley Prescott, founder, and CTO of LOEPRE, a Stellar Cyber partner and OEM based in Germany.

More in News

Increasing operating requirements are leading to an increase in the strength with which physical key management is being enforced within workplaces, hotels, hospitals, property management businesses and industrial companies. The implementation of an electronic key control system may assist companies in keeping a better track of their key transactions and minimizing the workload that comes with tracking keys manually. Centralized monitoring can help staff members get better visibility about the availability of the keys, user activity, and return status. Such features help businesses improve accountability and keep day-to-day operations more organized. These capabilities also support more consistent key-handling procedures, particularly in facilities managing large numbers of keys across multiple departments. Technological Advancements Shaping Electronic Key Control Systems Biometric authentication is adding another layer of sophistication to electronic key control systems, allowing authorized personnel to verify their identity through fingerprints, facial recognition and other biometric credentials before retrieving designated keys. Smart card readers, PIN-based verification and mobile credentials are also expanding authentication options for different workplace requirements. These technologies can reduce dependence on conventional identification methods while enabling organizations to assign permissions according to employee roles, departments and operational responsibilities.  Cloud connectivity is changing how electronic key control systems are managed across larger facilities and distributed business locations. Connected platforms can consolidate information from multiple cabinets into a unified interface, giving administrators access to centralized records without relying on isolated systems at each site. Mobile applications and remote management capabilities can further support notifications, configuration changes, user administration and system status monitoring. Integration with enterprise software, building management platforms and workforce applications can also help businesses connect key-related information with broader operational workflows.  Artificial intelligence and sophisticated data analytics are opening up new ways to analyze and interpret activity captured by electronic key control systems. Automated analysis can identify unusual usage patterns, repeated access attempts, irregular retrieval behavior and other activity that may warrant administrative attention. Real-time alerts can notify designated personnel when predefined conditions are detected, while analytical dashboards can turn historical records into useful operational insights. These developments are moving electronic key control systems toward more responsive and data-driven management environments.  Security Management and Access Control Electronic key control systems have the potential of improving security by ensuring that some particular criteria are satisfied before the key is issued. Time-based restrictions, designated release rules and approval requirements can help prevent unnecessary access to sensitive keys. These controls are particularly useful when certain keys need to remain unavailable outside approved operating periods. Secure electronic cabinets can keep individual keys locked inside designated compartments until the required release conditions are met. This can help protect keys associated with vehicles, equipment, restricted rooms and valuable assets. Tamper detection, cabinet-door sensors and forced-entry alerts can provide additional protection against physical interference.  Detailed records can also provide facility managers with a clear history of key-related transactions. Information such as access time, return time, key identification and transaction status can support internal investigations, compliance reviews and incident assessments. Organized records can also help identify discrepancies and establish responsibility when irregularities occur. Future Prospects and Innovations Future developments in electronic key control systems will focus more on flexible hardware, depending on the needs of the facilities. Modular cabinets, expandable storage configurations and replaceable components could make system upgrades easier without requiring complete equipment replacement. Compact designs may also help businesses accommodate key management equipment in locations where available space is limited.  Manufacturers are designing systems that are able to recognize the early symptoms of deterioration, which should enable maintenance capabilities that will be more proactive. Future solutions could identify mechanical wear, battery degradation, repeated component faults and declining cabinet performance before failures occur. This approach could help facility teams schedule servicing at suitable times and reduce interruptions caused by unexpected equipment breakdowns. Innovation may increasingly focus on the physical design of key cabinets, including improved compartment flexibility, adjustable storage arrangements and mechanisms designed to accommodate different key sizes and configurations. Enhanced cabinet layouts could make key retrieval more practical in facilities handling varied key inventories while allowing equipment to be configured around specific operational requirements.  Future systems are also likely to become easier for administrators to operate through clearer interfaces, simplified navigation, customizable displays and more intuitive control layouts. A better user experience can reduce the learning curve for employees responsible for system administration and make routine configuration tasks easier to manage. Manufacturers may increasingly prioritize straightforward interfaces alongside functional improvements.  Advancements in identification techniques may help make keys more unique in terms of their digital identity, thus helping differentiate keys that look similar within large inventories. Enhanced identification capabilities may support faster recognition, reduce confusion between similar assets and improve the accuracy of key selection. Such developments could become particularly valuable in facilities where numerous keys have similar physical appearances. ...Read more
Cybersecurity is no longer about network and device protection. There is a need for more robust measures over the development, implementation and assessment of security policies throughout business processes. Governance teams need to monitor the access controls, regulatory compliance and internal controls, but do not need to add extra administrative burdens as digital environments become increasingly connected. Organizations are being helped to manage these responsibilities better with the help of technology. A cyber governance and complaince framework can tie the security policies to operational controls, providing teams with greater visibility of how the operational controls are being adhered to. A digital tool can help security people determine if there are gaps in any processes to be reviewed, rather than having to do so by hand, and prioritize their attention on the processes with risks that need additional investigation. How Are Automation Tools Improving Governance Oversight? Routine governance tasks are transforming because of automation. Security platforms can monitor access permissions, policy controls and user activities against predefined requirements. If a control is not within an accepted condition, the system can notify the team concerned, instead of requiring a manual review. Electronic evidence collection can also ease compliance evaluations. Governance teams must prove that security controls are working as intended. Technology has the potential to capture relevant data from other systems connected to it and present it in an orderly way for review. Risk assessment tools are also getting better at assessing risk. Analytics can help determine the potential risks and the relevance and severity of the same, instead of the same treatment being applied to all security issues. Security professionals can then focus their efforts on areas that require increased security. What Technologies Are Strengthening Compliance Management? The notion of continuous monitoring is an important element of modern governance. Traditional review tools can only be used to get a snapshot of security performance, and monitoring can give ongoing visibility to system activity. This enables teams to recognize changes that could impact existing policies and take action before minor issues turn into major governance issues. Cyber governance and cyber complaince technology can be an integrated way of managing cybersecurity for organizations that are looking for more focused governance. The best solutions will be a mix of automation, monitoring, analytics and human decision making. Organizations can create governance processes that are more responsive, consistent and manageable by leveraging technology to automate repetitive tasks and surface meaningful risks. ...Read more
Security, access control, and efficiency are some of the key factors that are increasingly becoming important in residential neighborhoods, commercial buildings, industries, and public utilities. Organizations and proprietors must find solutions to facilitate access and entry to such places with ease and safety. There are automated gate systems that have been developed using advanced technology and automation processes. These automated gate systems can be integrated with security systems, access control devices, surveillance cameras, and communication systems to achieve efficient access control solutions. How Do Automated Gate Systems Improve Security and Access Control? The primary purpose of automated gate systems is to control access to certain areas and prevent unauthorized persons or vehicles from reaching them. While manual gates need to be operated, automated systems operate with electronic controls, sensors and communication technologies. Security is one of the foremost advantages of automatic gate systems. Access can be controlled by key cards, access codes, radio-frequency identification (RFID) tags, biometric authentication, or mobile applications. These access control mechanisms minimize the possibility of unauthorized access and ensure that there are accurate records of access activity. Automated gate systems come with surveillance cameras and security monitoring systems. This integration makes it possible to monitor the entry points in real-time and to be able to check visitors before granting access. The video footage can also be used to enhance investigations and security audits, if necessary. The installation of automated gates enhances the efficiency of operations, eliminating the need for human intervention. Automated verification processes allow vehicles to come in and out of residential communities, businesses, warehouses and industrial facilities faster. This helps minimize delays while maintaining appropriate security measures. What Factors Are Driving the Adoption of Automated Gate Systems? Modern automated gate systems can now be connected to a wider building management system, enabling their access to be controlled remotely using a mobile device and/or a centralized control system. This connectivity facilitates flexibility and convenience in operations. Technology advancements keep adding system functionality, such as automated gate solutions becoming more effective with the use of artificial intelligence, cloud-based management platforms, license plate recognition and advanced analytics. These technologies aid quicker identification, better monitoring and better security decision-making. Automated gate systems are also being installed in transportation facilities, government buildings, parking structures and critical infrastructure sites. Such applications provide secure working and facilitate the flow of authorized persons and visitors, and remain a vital tool for access control. ...Read more
Too frequently, when a client or regulator requests verification rather than just the protection regulated small and midsize firms find out the limitations of their security program. Despite having controls in place, a lender entering a new state, a fintech responding to a bank review, an insurer getting ready for a renewal or a health technology provider facing an audit may find it difficult to demonstrate that those controls are routinely implemented. The buying question is whether routine security work produces evidence that can withstand outside review without a separate scramble. The first failure pattern is disjoint between compliance and cybersecurity. Security teams triage alerts and vulnerabilities, while compliance owners collect policies and evidence in a different workflow. This duplication adds cost for lean firms and a more serious vulnerability. Documented controls can diverge from the reality of what the security team does. In a stronger service model evidence capture is part of the work itself. Compliance records should be fed with alert disposition, vulnerability reviews, access changes and incident records as routine outputs and not reconstructed in the near of an audit. Alert handling exposes a different procurement risk. If the customer environment is absent from triage, quick closure rates are meaningless. Depending on cloud topology, identity structure, application behavior and available telemetry, a single signal may entail varying degrees of risk. While automation aids analysts in gathering context and minimizing repetitive review, detection logic should continue to be based on predefined security criteria. The discipline of escalation is equally important. Instead of using automation percentage as a stand-in for security quality, a service should clarify what can be closed automatically and what needs to be sent to a human. "Digital Edge Ventures feeds day-to-day security activity into audit-ready evidence, supported by monthly internal reviews and compliance reporting." Continuous evidence changes the economics of compliance. Control performance collected during day-to-day security work can support customer reviews or regulatory requests without forcing staff to rebuild history from tickets and spreadsheets. Dashboard polish is secondary to the underlying mechanism. Executives should examine how evidence is generated, how often it is reviewed, whether identified gaps flow back into remediation and who owns follow-through. The enhanced model keeps the compliance record near to the security activity that produced it. Service ownership becomes decisive when internal security staff is small. Coordinating consultants, tool suppliers, internal IT professionals and compliance advisers may be left to the client by a provider who only finds gaps. After corrections are made, findings should go straight into remediation and continue to be under accountable management. During an incident or audit, this continuity minimizes handoffs and maintains accountability. For regulated SMBs, the practical test is whether one provider can manage the work without forcing the client to build a large internal security function around it. Digital Edge Ventures is the perfect partner for regulated SMBs to have security and compliance managed as one service. Its 24/7 SOC and MDR, continuous compliance monitoring, vulnerability management and incident response planning are aligned with those buying pressures. The service applies traditional SIEM rules at the detection layer. The AI then scores the alerts against the customer context, passing those the AI is unable to determine to the human analysts instead of automatically closing them out. Digital Edge Ventures transforms the security activity of the day-to-day into audit-ready evidence supported by monthly internal reviews and compliance reporting. It can also own the larger security and compliance program in smaller environments. That model offers executives who don’t have a large internal department a practical way to achieve sustained audit readiness and managed security coverage. ...Read more

Weekly Brief