School of Information Systems

Securonix Announces New Analytics Sandbox Capability

Industry – First Capability to Test Use Cases and Improve SOC Efficiency unveiled at Spark 2020 Conference and RSAC 2020 

by Beth Smith 

 

February 25, 2020 

Securonix, Inc. today announced the launch of the Securonix Analytics Sandbox capability, which provides an isolated test or QA environment within the production setup. This enables security operations teams to test, tune, and validate new use cases prior to pushing them to live production. 

 “Security operations teams are in a catch 22 – they must update use cases rapidly to stay ahead of evolving threats, but must do so in a way that does not add false positive noise or require additional response resources for data storage or compute,” said Sachin Nayyar, CEO of Securonix. “Leveraging the elasticity of its cloud-based architecture, Securonix is able to provide customers the Securonix Analytics Sandbox capability that satisfies these needs.” 

 Across teams, security operations face a common challenge – testing and deploying use cases without impacting efficiency. The process of fine-tuning use cases and adding team-created content or algorithms to live production environments is time consuming and creates excess “noise” – in the form of unverified alerts, false positives, and violations – for already under-resourced security operations and response teams to handle. With Securonix Analytics Sandbox, the teams responsible for developing SIEM content can test and fine-tune use cases against real production data without impeding SOC efficiency. 

 Securonix unveiled its industry-first Analytics Sandbox capability at Securonix Spark 2020, the company’s third annual conference, coinciding with RSAC 2020. Spark 2020 focuses on combating multi-cloud threats, with presentations by Sachin Nayyar, CEO of Securonix; Felipe Boucas, Director of Product for Managed Security Services at Verizon; Rohit Gupta, Global Segment Leader for Security at AWS; Anil Markose, SVP at Booz Allen Hamilton; as well as several other industry CISOs and subject matter experts. 

How Securonix Analytics Sandbox Works 

Securonix Analytics Sandbox allows multiple teams – including data scientists, detection engineers, blue teams, and others – to create multiple test beds to test use cases at scale against production data and analyse the impact in isolation. The use cases tested in the sandbox can be tuned, validated, and then pushed to production. Securonix Analytics Sandbox enables users to keep entity risk scores intact until the new use cases are pushed to live production. Use cases moved from the sandbox to production provide three options to testers:  

  • Delete violations (risk score) and delete meta-data (behavioural profile) 
  • Delete violations (risk score) and keep meta-data (behavioural profile) 
  • Keep violation (risk score) and keep meta-data (behavioural profile) 

 Securonix uses the dynamic resource allocation capability within the AWS cloud platform and the Spark application to allocate resources on-demand for the sandbox environment. This allows Securonix to enable the Analytics Sandbox for its SaaS customers at production scale without impacting performance. 

https://www.itsecurityguru.org/2020/02/24/securonix-announces-new-analytics-sandbox-capability/  

Beth Smith