UPDATED 09:00 EDT / FEBRUARY 24 2016

NEWS

Nowhere to hide: Rapid7 uses behavior analytics + search to hunt down attackers

IT security has long been viewed as a game of cat and mouse, with security firms building increasingly sophisticated security systems designed to keep the bad guys out, and hackers constantly coming up with ingenious new ways to crack corporate security.

The reality of course is that no matter how secure your systems supposedly are, determined attackers will always find a way to get through. And once inside your network, attackers will do everything they can to hide their presence from you.

To try and stave off these kinds of threats, Boston-based security firm Rapid 7, Inc. is touting a new incident detection and response offering that it claims can detect and investigate suspected intrusions up to ten times faster than is possible with traditional monitoring tools, allowing security teams to minimize the damage sustained from any security breach.

“Current detection technologies, including SIEMs and IPSs, don’t adequately serve customers’ needs because they overwhelm users with alerts and miss essential indicators of compromise,” said Lee Weiner, senior vice president of products and engineering at Rapid7. “We believe the key to solving this problem is enabling security analysts to harness the data in their IT environments and give them powerful analytics and search capabilities so they can quickly and more easily find the information they need.”

And that’s what Rapid7 InsightIDR hopes to deliver, by providing those same capabilities. Rapid7 says it’s new platform is unique in that combines behavior analytics with search and contextual data collection, allowing it to detect even the stealthiest of attacks. The solution was made possible thanks to the integration of log centralization and proprietary search technology the company acquired when it bought out Logentries.com, Inc., in October of last year. By combining behavior analytics with search and contextual data collection, Rapid7 claims it’s able to cut out the “false positives” that are all too common with SIEM and IPS monitoring systems. At the same time, the system “hunts for actions indicative of compromised credentials, spots lateral movement across assets, and automatically sets traps for intruders,” the company said.

Rapid7 InsightIDR is also unique in that it monitors and tracks endpoints down to the most remote, unknown networks, the very same places where attackers will try to hide. The solution also leverages machine learning technology which allows it to evolve just like attackers do, meaning it can quickly learn to recognize and neutralize whatever new techniques they come up with to try and evade detection. Finally, the platform is proactive because it’s able to set “intruder traps” that can spot new attackers as they attempt to explore the network, which means they’re often caught before being able to do any damage.

For the security professional, Rapid7 InsightIDR makes their life much easier too. That’s because the system is able to apply context to an enterprise’s data before presenting it as a series of ‘events’ indicating both users and assets, which analysts can check for evidence of any breach. Rapid7 InsightIDR can pull into data and provide visibility into an enterprise’s entire network of applications, including popular cloud based apps such as Amazon Web Services, Box, Microsoft Office 365, Okta and Saleforce.

Picture1

“For security professionals, incident detection and investigation has always been a cumbersome, manual process,” said Jordan Schroeder, security architect at Visier Inc. “Rapid7 InsightIDR delivers a powerful incident detection solution backed by data aggregation and search capabilities that give me a single view of everything meaningful that’s happening on my network. All of the information I need to understand and solve a problem is at my fingertips.”

Rapid7 will be showcasing its new tool at the RSA Security Conference in San Francisco later this month, ahead of its general release in Q1 2016.


A message from John Furrier, co-founder of SiliconANGLE:

Your vote of support is important to us and it helps us keep the content FREE.

One click below supports our mission to provide free, deep, and relevant content.  

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well” – Andy Jassy

THANK YOU