Stellar Cyber announced that its open and highly flexible approach to the long-term storage of large volumes of security data eases concerns about storage complexity and costs seen in legacy SIEMs or some proprietary XDR solutions used by security operations centers.
Cybersecurity is essentially a data problem, with best practices necessitating capturing and retaining all available data to properly evaluate potential threats and keep an audit trail for future investigations.
This approach causes skyrocketing storage costs and makes it much more difficult to identify real attacks, because analysts often can’t see the forest for the trees with the massive amounts of data. Voluminous data also makes forensics and threat hunting almost impossible on some legacy SIEMs due to poor query performance.
Stellar Cyber’s intelligent SOC platform is more efficient, storing only security-relevant metadata in a scalable, elastic data lake, which reduces the amount of storage needed and makes it easier to identify anomalies more quickly.
Once it collects the metadata, Stellar Cyber’s AI-powered analytical engine evaluates it and alerts analysts to even the most complex attacks.
“We were having a real problem storing data from a traditional SIEM,” said Joe Morin, CEO of CyFlare. “Stellar Cyber’s metadata parsing and flexible storage options save us money on resources while making our analysts more efficient.”
Flexible storage designed for scalability and efficiency
Most SIEM products not only force collection and storage of irrelevant data, but they don’t offer any flexibility in what, how or where data is stored. With Stellar Cyber, users have many choices through its Open XDR platform.
They can pick the right data to be collected, customize data retention time by type of data (on a per-tenant basis in a multi-tenancy environments), choose whether data is kept in hot or cold storage, and pick where to house cold storage (on-premises with a NAS or JBOD system or in the cloud) to further save on costs.
“Scaling storage is a top complaint by legacy SIEM users – the SIEM sucks up all the data, but then you have to store it somewhere,” said Zeus Kerravala, principal analyst at ZK Research.
“Stellar Cyber’s platform keeps only the relevant data for security analysis and then gives users a lot of options for how and where it’s stored.”
Stellar Cyber’s fast forensic analysis and threat-hunting capabilities are built on top of its scalable elastic data lake, which is designed for storing large volumes of data with fast search performance on a cloud-native, microservice architecture.
The collected data is normalized, enriched in real time with context, correlated, and can be searched quickly by any data field or any combination of fields. Data is automatically evaluated for anomalies by the platform’s AI-powered detection engine, and analysts can use pre-built or home-grown threat-hunting playbooks to ferret out threats wherever they reside.
“Data storage is a major challenge for users of security systems, particularly legacy SIEMs,” said Steve Garrison, VP of Marketing at Stellar Cyber. “We thought through this issue when designing our Open XDR platform, and now offer a number of ways in which customers can optimize their storage to improve efficiency and save costs.”