Splunk leverages its Caspida acquisiton with new security offerings

News Analysis
Sep 22, 20153 mins

It's always interesting to check back in after a corporate acquisition. Splunk isn't letting any time go to waste with its newly acquired Caspida division.

cyber security lock secure security
Credit: Thinkstock

When Splunk acquired security vendor Caspida a few months ago, some eyebrows were raised, while others saw it as a natural move. Long a vendor delivering a broad big data analytics platform, the Caspida acquisition was an admission of what many people already thought – that a huge proportion of the real-world adoption of analytics platforms is in the IT space, specifically security and threat intelligence. The Caspida acquisition was a good way for Splunk to go deep into this sector and follow a dual strategy: a broad platform for general use cases and distinct vertical for the early big data use cases.

This would seem to be the strategy that Splunk is following, and the company is today announcing some major updates to what was formerly called the Splunk App for Enterprise Security. Relabeled to recognize the heightened importance of security as a product direction for Splunk, Splunk Enterprise Security is focused on allowing organizations to trawl through the steps an attacker takes in order to more quickly and efficiently detect and respond to breaches.

The product has been upgraded to better handle multi-stage attack detection and response, as well as ease collaboration between response teams. New features being released include:

  • Investigator Journal keeps track of ad-hoc searches and activities to streamline multi-stage analysis associated with breach detection and response.
  • Investigator Timeline allows any event, activity, or annotation to be placed within an investigation timeline to help analysts better understand, visualize, and communicate the cause-and-effect of events and the details of advanced multi-stage attacks. For example, users could apply the kill chain within the timeline during investigations.
  • Investigator Timeline also allows any security team member to place events, actions, and annotations into the timeline to share their perspective of the scenario to collaboratively investigate incidents, problems, and breaches.
  • Enterprise Security Framework allows customers, vendors, and third parties to create, access, and extend ES functionality with apps that can run within ES and access functionality such as the alert management, risk, threat intelligence, and the identity and asset frameworks.

In addition to the enterprise security app, Splunk is rolling the Caspida technology in Splunk UBA, intended on adding another layer to organizations’ cyber defense arsenal. UBA promises to deliver:

  • Improved detection of cyber attacks and insider threats.
  • Increased security analysts’ effectiveness by only presenting meaningful threats with malicious activities using a kill chain visualization.
  • Operationalization of security by rapidly getting data into Splunk UBA and streamlining incident response by leveraging the full power of Splunk solutions.

“Every second counts, and Splunk security solutions give an edge to security teams by improving the speed and efficiency of attack and breach detection and incident response,” said Haiyan Song, senior vice president of security markets at Splunk. “Splunk solutions are often seen as the nerve center for security because they let teams leverage their entire security technology stack and utilize their data to detect, understand and take action in a coordinated fashion across the organization. Splunk Enterprise Security lets analysts visually correlate events over time and communicate details of multi-stage threats while Splunk UBA uses machine learning to spot the most dangerous offenders – advanced attackers including malicious insiders.”

Splunk got an early start in the space and was borne out of experience in the IT security and general management space. These more verticalized product offerings make sense for a company intent on growing and broadening its customer base.

benkepes

Ben Kepes is a technology evangelist, an investor, a commentator and a business adviser. His business interests include a diverse range of industries from manufacturing to property to technology. As a technology commentator he has a broad presence both in the traditional media and extensively online. Ben covers the convergence of technology, mobile, ubiquity and agility, all enabled by the cloud. His areas of interest extend to aviation technology, enterprise software, software integration, financial/accounting software, platforms and infrastructure as well as articulating technology simply for everyday users.

He is a globally recognized subject matter expert with an extensive following across multiple channels. His commentary has been published on Forbes, ReadWriteWeb, GigaOm, The Guardian and a wide variety of publications – both print and online. Often included in lists of the most influential technology thinkers globally, Ben is also an active member of the Clouderati, a global group of cloud thought leaders and is in demand as a speaker at conferences and events all around the world.

As organizations react to the demands for more flexible working environments, the impacts of the economic downturn and the existence of multiple form-factor devices and ubiquitous connectivity, Cloud computing stands alone as the technology paradigm that enables the convergence of those trends -- Ben’s insight into these factors has helped organizations large and small, buy-side and sell-side, to navigate a challenging path from the old paradigm to the new one.

Ben is passionate about technology as an enabler and enjoys exploring that theme in various settings.

The opinions expressed in this blog are those of Ben Kepes and do not necessarily represent those of IDG Communications, Inc., its parent, subsidiary or affiliated companies.

More from this author