<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Big Data Security Intelligence &#8211; nothing to see here &#8211; move along</title>
	<atom:link href="http://raffy.ch/blog/2012/03/16/big-data-security-intelligence-nothing-to-see-here-move-along/feed/" rel="self" type="application/rss+xml" />
	<link>http://raffy.ch/blog/2012/03/16/big-data-security-intelligence-nothing-to-see-here-move-along/</link>
	<description>Big data analytics and visualization</description>
	<lastBuildDate>Sun, 07 Apr 2013 08:03:37 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Raffael Marty</title>
		<link>http://raffy.ch/blog/2012/03/16/big-data-security-intelligence-nothing-to-see-here-move-along/comment-page-1/#comment-51568</link>
		<dc:creator>Raffael Marty</dc:creator>
		<pubDate>Fri, 11 Jan 2013 17:01:54 +0000</pubDate>
		<guid isPermaLink="false">http://raffy.ch/blog/?p=581#comment-51568</guid>
		<description>AbleeTu ... What I was reacting to was that everyone is looking at big data, but what big data is today is an infrastructure layer. Only a handful of companies are working ont he analytical layer of big data. That&#039;s what we really need. 
I didn&#039;t say SIEM was already gone. I strongly believe though that there will be a new wave of SIEMs or whatever they will be called. I am obviously very bullish on visual analytics (see &lt;a href=&quot;http://pixlcloud.com&quot; rel=&quot;nofollow&quot;&gt;pixlcloud&lt;/a&gt;). I have seen too many customers that are struggling with dealing with all their data in the SIEM. They have no idea what they are collecting, what the data tells them, and what to do with it. In order to process that amount of data, we need new data stores. RDBMs is not cutting it anymore (I am happy to have a long discussion with you on this). Think OLAP 2.0. We need better ways for analysts to interact with the data. Not sure I am expressing myself that well...</description>
		<content:encoded><![CDATA[<p>AbleeTu &#8230; What I was reacting to was that everyone is looking at big data, but what big data is today is an infrastructure layer. Only a handful of companies are working ont he analytical layer of big data. That&#8217;s what we really need.<br />
I didn&#8217;t say SIEM was already gone. I strongly believe though that there will be a new wave of SIEMs or whatever they will be called. I am obviously very bullish on visual analytics (see <a href="http://pixlcloud.com" rel="nofollow">pixlcloud</a>). I have seen too many customers that are struggling with dealing with all their data in the SIEM. They have no idea what they are collecting, what the data tells them, and what to do with it. In order to process that amount of data, we need new data stores. RDBMs is not cutting it anymore (I am happy to have a long discussion with you on this). Think OLAP 2.0. We need better ways for analysts to interact with the data. Not sure I am expressing myself that well&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AlbeeTu</title>
		<link>http://raffy.ch/blog/2012/03/16/big-data-security-intelligence-nothing-to-see-here-move-along/comment-page-1/#comment-51488</link>
		<dc:creator>AlbeeTu</dc:creator>
		<pubDate>Wed, 09 Jan 2013 20:54:03 +0000</pubDate>
		<guid isPermaLink="false">http://raffy.ch/blog/?p=581#comment-51488</guid>
		<description>&gt; SIEM being replaced or superseded by big data infrastructure. That’s completely and utterly stupid.

I didn&#039;t quite understand this claim. From what I&#039;m assuming, SIEM still has lots to offer that this new product can not do. I&#039;ve seen customers do this and it is foolish. Regardless, I&#039;d like to hear what you have seen.</description>
		<content:encoded><![CDATA[<p>&gt; SIEM being replaced or superseded by big data infrastructure. That’s completely and utterly stupid.</p>
<p>I didn&#8217;t quite understand this claim. From what I&#8217;m assuming, SIEM still has lots to offer that this new product can not do. I&#8217;ve seen customers do this and it is foolish. Regardless, I&#8217;d like to hear what you have seen.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: VMercer</title>
		<link>http://raffy.ch/blog/2012/03/16/big-data-security-intelligence-nothing-to-see-here-move-along/comment-page-1/#comment-49163</link>
		<dc:creator>VMercer</dc:creator>
		<pubDate>Thu, 22 Nov 2012 17:13:52 +0000</pubDate>
		<guid isPermaLink="false">http://raffy.ch/blog/?p=581#comment-49163</guid>
		<description>Security Management is a 2 layered cake:
1st Layer : IDP/IPS/UTMs... real time/attack protection
2nd Layer : SIEM, Post real time - event/threat analysis, data forensics and law compliance.
Now the legacy RDBMS/SIEMs can&#039;t cope in this Big Data world, so next generation &quot;SIEMs&quot; like Secnology will be needed. 
A 3rd layer Big Data &quot;Hadoop&quot; &quot;Magic&quot; analysis tool sounds sexy but when &amp; at what price. Considering the SIEM still hasn&#039;t made the middle market yet, it&#039;ll still take a Data/Security expert to harness the analytics &amp; make the calls.</description>
		<content:encoded><![CDATA[<p>Security Management is a 2 layered cake:<br />
1st Layer : IDP/IPS/UTMs&#8230; real time/attack protection<br />
2nd Layer : SIEM, Post real time &#8211; event/threat analysis, data forensics and law compliance.<br />
Now the legacy RDBMS/SIEMs can&#8217;t cope in this Big Data world, so next generation &#8220;SIEMs&#8221; like Secnology will be needed.<br />
A 3rd layer Big Data &#8220;Hadoop&#8221; &#8220;Magic&#8221; analysis tool sounds sexy but when &amp; at what price. Considering the SIEM still hasn&#8217;t made the middle market yet, it&#8217;ll still take a Data/Security expert to harness the analytics &amp; make the calls.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Big Data Infosec &#8211; Bigsnarf Open Source Solution &#171; BigSnarf blog</title>
		<link>http://raffy.ch/blog/2012/03/16/big-data-security-intelligence-nothing-to-see-here-move-along/comment-page-1/#comment-42142</link>
		<dc:creator>Big Data Infosec &#8211; Bigsnarf Open Source Solution &#171; BigSnarf blog</dc:creator>
		<pubDate>Fri, 23 Mar 2012 20:46:42 +0000</pubDate>
		<guid isPermaLink="false">http://raffy.ch/blog/?p=581#comment-42142</guid>
		<description>[...] of Big Data Infosec at Blackhat EU 2012 (Link:PDF). Raffael followed up recently with his post (Link:Website). Moar visual analytics! Ed in this post suggested that Infosec stop using &#8220;stoplight [...]</description>
		<content:encoded><![CDATA[<p>[...] of Big Data Infosec at Blackhat EU 2012 (Link:PDF). Raffael followed up recently with his post (Link:Website). Moar visual analytics! Ed in this post suggested that Infosec stop using &#8220;stoplight [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Big Data Information Security Maturity Scale &#8211; Where are you on this scale? &#171; facebookjustice</title>
		<link>http://raffy.ch/blog/2012/03/16/big-data-security-intelligence-nothing-to-see-here-move-along/comment-page-1/#comment-41848</link>
		<dc:creator>Big Data Information Security Maturity Scale &#8211; Where are you on this scale? &#171; facebookjustice</dc:creator>
		<pubDate>Sat, 17 Mar 2012 19:35:52 +0000</pubDate>
		<guid isPermaLink="false">http://raffy.ch/blog/?p=581#comment-41848</guid>
		<description>[...] as “I think we’re in a precarious spot”. Raffael follow up recently with his post (http://raffy.ch/blog/2012/03/16/big-data-security-intelligence-nothing-to-see-here-move-along/) that speaks to me loud. Moar [...]</description>
		<content:encoded><![CDATA[<p>[...] as “I think we’re in a precarious spot”. Raffael follow up recently with his post (<a href="http://raffy.ch/blog/2012/03/16/big-data-security-intelligence-nothing-to-see-here-move-along/" rel="nofollow">http://raffy.ch/blog/2012/03/16/big-data-security-intelligence-nothing-to-see-here-move-along/</a>) that speaks to me loud. Moar [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
