540 thousand events per second: Positive Technologies released the eighth version of MaxPatrol SIEM

Carding 4 Carders

Professional
Messages
2,731
Reputation
13
Reaction score
1,375
Points
113
The new version includes 30 machine learning models and deeper integration with other products of the company.

Positive Technologies has released MaxPatrol SIEM information security event monitoring and incident detection system. The updated product will allow almost a third increase in the percentage of vendor presence among companies that require ultra-large installations (the largest business from the RA600 list), and among government organizations that are tasked with using artificial intelligence technologies.

Major updates:
  1. Optimized hardware requirements: Deploying a system that can handle up to 5,000 events per second now requires less hardware resources. This allows companies to reduce the cost of purchasing equipment and make it easier to install the system, especially in an environment where the cost of equipment is constantly growing.
  2. Improved MaxPatrol SIEM performance: on a single core and using all expert rules, the updated product processes more than 540 thousand events per second. This significantly expands the system's capabilities, allowing you to monitor large data streams without losing quality and without compromising when choosing expert packages.
  3. LogSpace DBMS: The system has been using a proprietary database since version 7.0, which has allowed us to increase the volume and storage time of data by six times compared to other solutions.
  4. Behavioral Analysis Module: The new ML module-Behavioral Anomaly Detection-includes about 30 machine learning models developed on the basis of twenty years of vendor experience in incident investigation.
  5. XIntegration and Improved U: Version 8.0 offers deeper integration with other company products and third-party services, as well as an improved interface for quick access to event information and related data.

To simplify the task of testing hypotheses, integration with Positive Technologies products and third-party services has been expanded: from the event card, you can now send cross-service requests to PT Network Attack Discovery, MaxPatrol EDR, RST Cloud, Whois7, and other systems.

In addition, you can send cross-service requests to the PT Threat Analyzer subsystem from the event card. It helps you build incident detection and prioritization based on compromise indicators — information about attackers and the tools they use for attacks. PT Threat Analyzer collects threat data from various sources, including the PT Threat Intelligence Feeds service, as well as other commercial and open data sources.

In the future, Positive Technologies plans to further optimize MaxPatrol SIEM to meet changing market requirements and customer needs.
 
Top