Palo Alto Networks today rolled out a new artificial-intelligence (AI) based platform to automate threat detection and remediation that its CTO and founder Nir Zuk says replaces legacy security information and event management (SIEM) tools.
The new platform, called Cortex XSIAM — which stands for extended security intelligence and automation management — will enable continuous vulnerability discovery through attack-surface management and threat intelligence gleaned from tens of thousands of Palo Alto Networks customers, according to the vendor.
Cortex XSIAM collects and analyzes logs, alerts, and other granular data across companies’ security infrastructure — Palo Alto Networks says it also halves the cost of legacy SIEMs — and then uses machine learning to automate response actions. These include cross-correlation of alerts and data, threat detection, and remediation.
A limited set of customers are using Cortex XSIAM now, and the platform will be generally available later this year.
In a blog post about the new platform, Zuk called the product “the autonomous security platform of the future.” The platform, using intelligence and automation, will manage security information and events, freeing up security professionals to manage intelligence and automation, he explained.
“It’s very clear that the SIEM is not the right tool to shorten the time to detect and stop attacks and we need something else,” Zuk said in a video about XSIAM. Incrementally adding more automation tools around SIEM won’t solve the problem of finding and stopping threats in real time, he added.
Zuk compared the approach to car manufacturers adding adaptive cruise control and automatic breaking: “We all know that this is never going to get to an autonomous car,” he said in the video. “If you want to build an autonomous car, you have to build from scratch.”
The same thing needs to happen in the security operations center, Zuk added. “XSIAM is the autonomous car of cybersecurity.”
Comments