I had a debate last week with one of our Systems Engineers about whether our customers needed McAfee Global Threat Intelligence (GTI) in our SIEM (Security Incident and Event Management) product if we already delivered it via our network IPS. Of course they do.
If you’re not familiar with McAfee GTI, it’s our cloud-based threat reputation engine. McAfee GTI collects and shares reputation data across dozens of McAfee security solutions. This reputation data includes billions of file, IP, mail, web, and other data points, each of which is assessed and assigned a risk score. Through testing, we’ve found that McAfee GTI can improve detection rates by up to 30%. Perhaps more importantly, these real-time reputation feeds can shrink response times from days down to minutes.
As a cloud-based service, McAfee GTI can and has been incorporated into most McAfee products, including McAfee Network Security Platform (network IPS) and McAfee Enterprise Security Manager (SIEM).
So, back to the question: If you already get the benefits of McAfee GTI via network IPS, does it need to be incorporated into your SIEM? The answer is yes, and here’s why:
When we first introduced McAfee GTI integration with Network Security Platform, adoption was a bit slower than we expected. As we dug into the reasons, we found that one common (and entirely ironic) concern was that by enabling GTI, security teams found new events that they had to respond to. We couldn’t argue with that. It wasn’t long, however, before customers started seeing the benefits of GTI, and now the vast majority of our IPS customers turn it on.
But as I think back to the concern of too many security events, I realize that GTI with SIEM helps solve the ‘too many security events’ dilemma. While individual security products may trigger on the same event independently – and kick off independent efforts to resolve an issue – having a correlated view of security events at the SIEM level helps streamline the incident response process, ultimately delivering the best of both worlds.
Tags: GTI, IPS, Network Security, SIEM
Submit your own comments / message for this post