Ausnahme gefangen: SSL certificate problem: certificate is not yet valid 📌 Anomali Launches Differentiated Cloud-Native XDR SaaS Solution with Support from AWS SaaS Factory

🏠 Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeiträge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden Überblick über die wichtigsten Aspekte der IT-Sicherheit in einer sich ständig verändernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch übersetzen, erst Englisch auswählen dann wieder Deutsch!

Google Android Playstore Download Button für Team IT Security



📚 Anomali Launches Differentiated Cloud-Native XDR SaaS Solution with Support from AWS SaaS Factory


💡 Newskategorie: IT Security Nachrichten
🔗 Quelle: anomali.com

Click here for more information on AWS Partner Network blog.

By Ranjith Raman, Sr. Partner Solutions Architect – AWS
By Oded Rosenmann, Global Practice Lead, SaaS Partners – AWS

Organizations are increasingly looking for new ways to defend themselves against cyber threats, fraud, and ransomware attacks. Many enterprises and government agencies turn to cyber security solutions that provide efficient and effective detection and response capabilities to proactively prevent attackers from breaching their networks and applications.

To help organizations overcome these challenges, Anomali, a leader in intelligence-driven cybersecurity solutions, has recently launched its Cloud-Native extended detection and response (XDR) solution, The Anomali Platform. Building upon its leadership position in the cyber threat intelligence space,  The Anomali Platform provides customers with a new dimension of security visibility across all log telemetry from endpoints to the cloud. The Anomali Platform provides precision detection and optimized response capabilities that extends across their entire security infrastructure.  

With the support of AWS SaaS Factory, Anomali has built the Anomali Cloud-Native XDR offering as a software-as-a-services (SaaS) solution that helps improve organizational efficiencies, providing security teams with the tools and insights needed to detect relevant threats, make informed decisions, and respond effectively.     

“The AWS SaaS Factory team was instrumental in helping us identify appropriate service options aligned with our enterprise customer requirements. Working with the team, we saved months of engineering efforts to build a powerful platform that meets our current needs and allows us to scale.”
Mark Alba, Chief Product Officer, Anomali


Mark Alba, Chief Product Officer, Anomali

The cloud-native XDR solution is fueled by big data management, machine learning, and the world’s largest repository of global intelligence. With the new SaaS model, The Anomali Platform can be easily integrated with existing security infrastructures, enabling CIOs, CISOs, and other business leaders to optimize their overall security investments and create more efficient and effective detection and response programs that proactively address advanced cyber threats.

The SaaS Factory team spoke with Mark Alba, Chief Product Officer at Anomali, to learn more about Anomali Cloud-Native XDR SaaS, the value its new solution brings to customers, and the key lessons learned from the journey to SaaS on AWS.

Check out the new Anomali Cloud-Native XDR SaaS solution >>
 

Q&A with Anomali

AWS SaaS Factory: Mark, thank you for taking the time to speak with us today. Could you share a bit about your background and role at Anomali?

Mark Alba:      

My name is Mark Alba, and I’m the Chief Product Officer at Anomali. I’ve been with Anomali since April 2020 and am responsible for product management, user experience, threat research, and technology incubator functions. 

My background includes over 20 years of experience building, managing, and marketing disruptive products and services. I brought to market the security industry’s first fully-integrated appliance firewall, leading the integration of global threat intelligence into perimeter security technologies and introducing advanced analytics in support of cyber security operations. I’ve also led product efforts in both start-up and large enterprise organizations, including Check Point Technologies, Security Focus, Symantec, and Hewlett Packard Enterprise.

SaaS Factory: What products and solutions has Anomali previously built on AWS?

Mark:          

Anomali has made its mark delivering Threat Intelligence powered detection and response solutions with its ThreatStream, Match, and Lens components of The Anomali Platform.

ThreatStream and Lens are both cloud-native solutions built on the AWS platform.

The ThreatStream component of The Anomali Platform offers threat intelligence management that automates the collection and processing of raw data and transforms it into actionable threat intelligence for security teams.

The Lens component of the platform is a powerful Natural Language Processing engine that helps operationalize threat intelligence by automatically scanning digital content (webpages, PDF’s, Office 365 files) to identify relevant threats.


SaaS Factory: Can you talk about the Anomali Cloud-Native XDR SaaS solution that you recently launched on AWS?

Mark:

What we’ve done is move our Match offering to the cloud as part of The Anomali Platform, combining our threat intelligence management capabilities with our threat detection capabilities to create a cloud-native XDR solution. In short, by moving Match to the Cloud, we have unlocked our capability to ingest telemetry from any telemetry source and correlate it with our global repository of threat intelligence to deliver highly performant threat detection. 

With this single cloud-native platform approach, customers will have the ability to leverage common platform capabilities through a single sign-on experience. Shared cloud capabilities include:

  • High-performance indicator correlation at a rate of 190 trillion EPS  
  • Appliance and cloud-to-cloud-based ingestion of any security control telemetry 
  • Global intel management across open, commercial, and proprietary sources 
  • STIX/TAXII for bi-directional intelligence exchange between TAXII source and clients 
  • Interactive, simplified dashboards for visualization of IOCs 
  • Global Intelligence feed optimizer and scoring 
  • OOTB appliance/API integration for response orchestration with security tools 
  • Vulnerability enrichment aligning global threats with potential org impact.     

 

SaaS Factory: Who are your customers, and what are some of the key customer benefits?

Mark:     

Anomali serves global B2B enterprise businesses as well as large public sector organizations, ISACs, service providers, and Global 1000 customers. This list includes Morgan Stanley, Air Canada, First Energy, Ubisoft, and Bank of Hope.

By correlating the world's largest repository of global actor, technique, and indicator intelligence with our infinite detection capabilities, we deliver a one-of-a-kind extended detection and response solution that continuously detects threats and prevents attacks before they happen. Key benefits for our customers include:

  • Increased threat visibility and insights into emerging threats, and the actors behind them, to respond quickly. 
  • Actionable intelligence to understand the impact and root cause to respond effectively to threats and minimize the damage.
  • Precision detection and increased situational awareness to cut through the noise to analyze and validate relevant threats and enable decisive response 

 

SaaS Factory: What were your primary business motivations for building Anomali Cloud-Native XDR as a SaaS deployment model?

Mark: 

There are a lot of benefits to offering security solutions as a service. It’s flexible, easily accessible, resilient, has cost advantages, and it’s hands-off for our customers. We can manage all the technical issues and the tedious tasks like installing, managing, and updating our software – meaning customers don’t need to lean on their in-house IT expertise and can focus on what they do best. 

     
SaaS Factory: Can you share key areas you addressed when moving to a SaaS model and how the AWS SaaS Factory team supported these efforts?

Mark: 

The AWS SaaS Factory team was instrumental in helping us identify appropriate service options aligned with our enterprise customer requirements. We needed to have an experience that is lightning-fast and can ingest information at great scale to effectively help our customers close security gaps. So, scale and performance were essential for seizing the opportunity to move beyond our previous on-premise deployments. We also focused on refining our long-term approach.  We needed to ensure our technical requirements were met while also managing our costs.  This helped us ensure our customer needs will be met while enabling competitive pricing.  The AWS SaaS Factory team helped us engineer a powerful platform to serve our current needs today and future needs as we scale. We were able to marry a combination of service options, cost, and performance that will grow as our business does. 


SaaS Factory: How is Anomali leveraging AWS services and which services are key?

Mark: 

We’re using AWS services in several ways, pushing data to Guard Duty and pulling data from AWS VPC Flow and Route 53.

The Anomali Platform uses Guard Duty for IOC matching, collecting telemetry data and intelligence from AWS, and then correlating it with our own IOCs and threat data to generate alerts.

We also collect telemetry for our cloud-XDR solution by ingesting data from AWS VPC flow and DNS query into The Anomali Platform and correlating it with our threat intel data and threat models to obtain rich context on billions of IOCs.


SaaS Factory: What are some of the challenges you faced with tenant and data isolation, and how did the SaaS Factory content and workshops help address them?

Mark: 

SaaS Factory conducted technical workshops on tenant isolation models (silo, pool, bridge), SaaS Identity and onboarding, running multitenant workloads, and data isolation and partitioning models. SaaS Factory also facilitated several specialist conversations by bringing experts in topics on storage, data analytics, and machine learning.

...



📌 The Evolution of Anomali: How Anomali’s ThreatStream has evolved into delivering a differentiated approach to XDR


📈 79.86 Punkte

📌 Build differentiated SaaS apps with the Microsoft Cloud | TS05


📈 44.46 Punkte

📌 Anomali, Inc.: Anomali Altitude ist der erste Anbieter von automatisierten, intelligent gesteuerten ...


📈 35.79 Punkte

📌 Anomali is Investing in Intelligence Powered Cloud XDR


📈 35.13 Punkte

📌 AWS launches SaaS Quick Launch for easier deployment of SaaS apps


📈 34.42 Punkte

📌 Tech Data expands Cloud Solution Factory with Windows Virtual Desktop on Azure Click-to-Run Solution


📈 33.95 Punkte

📌 McAfee launches MVISION XDR, a cloud-based advanced threat management solution


📈 33.42 Punkte

📌 Tag Cyber interviews Anomali about Our Intelligence Driven Approach to XDR


📈 31.24 Punkte

📌 Devices on 5G networks demand differentiated security solutions


📈 30.73 Punkte

📌 Devices on 5G networks demand differentiated security solutions


📈 30.73 Punkte

📌 How to Build a SaaS on AWS: a deep dive into the architecture of a SaaS product


📈 27.31 Punkte

📌 Und Microsoft so: Cloud, Cloud, Cloud, Cloud, Cloud, Cloud, Cloud


📈 27.24 Punkte

📌 XDR Alliance Welcomes New MSSP and MDR Members Committed to Open XDR Framework in Cybersecurity


📈 26.69 Punkte

📌 XDR is Dead. Long Live XDR!


📈 26.69 Punkte

📌 Cortex-XDR-Config-Extractor - Cortex XDR Config Extractor


📈 26.69 Punkte

📌 Obsidian SaaS security solution now available on AWS Marketplace


📈 26.55 Punkte

📌 Parablu launches BluVault, a SaaS backup solution for Microsoft Office 365


📈 26.02 Punkte

📌 AppOmni Launches Solution to Protect SaaS Applications for Remote Workers


📈 26.02 Punkte

📌 Votiro launches SaaS solution that eliminates file-borne threats


📈 26.02 Punkte

📌 Top cloud providers in 2021: AWS, Microsoft Azure, and Google Cloud, hybrid, SaaS players


📈 25.26 Punkte

📌 Exploring the Benefits of Cloud Computing: From IaaS, PaaS, SaaS to Google Cloud, AWS, and Microsoft


📈 25.26 Punkte

📌 Tech Data adds Modern Workplace with Microsoft Secure Score to its Cloud Solution Factory offering


📈 24.88 Punkte

📌 Discovering AWS App Runner: The Latest AWS Orchestration Solution You Should Be Aware Of


📈 24.35 Punkte

📌 Factory Pattern: Alle Informationen zum Factory Method Pattern


📈 23.83 Punkte

📌 Zerto Backup for SaaS powered by Keepit, manages and protects cloud SaaS data


📈 23.56 Punkte

📌 Aviatrix cloud network platform serves as a Network Factory for new and existing AWS accounts


📈 23.45 Punkte

📌 Migrating FileNet Into AWS Cloud and Migrating FileNet Security Into AWS Cloud


📈 23.06 Punkte

📌 AWS European Sovereign Cloud: AWS kündigt EU-Cloud an


📈 23.06 Punkte

📌 DevSecOps with AWS – ChatOps with AWS and AWS Developer Tools – Part 1


📈 22.92 Punkte

📌 McAfee debuts remote browser isolation solution, XDR platform


📈 22.42 Punkte

📌 Accurics Terrascan, Sophos XDR Solution, & API Security Need to Know - ESW #227


📈 22.42 Punkte











matomo