Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    DFLabs Looks to Improve SOAR With Open Integration Framework

    Written by

    Sean Michael Kerner
    Published November 7, 2018
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      DFLabs announced a new version of its IncMan SOAR (Security Orchestration Automation and Response) platform on Nov. 7, providing organizations with a new open model for enabling integration with security tools.

      The IncMan SOAR 4.5 release adds a new open integration framework that makes it easier for organizations to connect disparate security tools together for a more seamless security remediation workflow. The DFLabs update also improves the START Triage module that can be used to limit false positives and reduce the number of alerts that generate incidents that need to be remediated.

      “The new open integration framework is really designed to change the way that we at DFLabs develop our integrations with third-party products, but also change the way that customers can interact with them,” John Moran, senior product manager at DFLabs, told eWEEK.

      SOAR is an emerging area of IT cyber-security that blends alerts with the automated orchestration of different security controls for incident remediation. The State of SOAR Report 2018, released on Sept. 6, found that the high volume of security alerts experienced by many organizations is driving increased demand for SOAR technologies.

      One of the main differentiators between DFLabs’ open integration framework and what some of the other SOAR vendors are doing is the ability to define integrations in a text-based format that works at the action level, Moran said. As such, he explained that instead of having one giant file that defines all the IncMan SOAR integrations with a specific vendor technology, DFLabs just has individual files that define each action.

      How It Works

      Creating integrations with different security technologies via the open integration framework is enabled via the innovative use Docker containers.

      By creating an integration definition container with DFLabs’ open framework and then allowing users to upload individual action files, users just code their new action in its own integration action file, without worrying about messing up anything that already exists, Moran said. By using Docker containers, it makes it very easy for users to share integrations with other customers, he added. Python, Perl, PowerShell and bash scripting are all supported options for programming the integration containers.

      “So the user has the ability to specify what Docker container they would like to execute each integration in, and that allows for increased security and it allows users to use whatever third-party libraries they may need,” he said.

      Start Triage

      The IncMan SOAR 4.5 release also benefits from a series of other features, including an expanded REST API. Additionally, the Start Triage module has been enhanced to provide organizations with new capabilities. Moran explained that a common problem for many IT organizations is they get a high volume of alerts but don’t have proper scoring mechanics in place of the severity of all the incoming information.

      “In the 4.5 release, we have the ability to create triage events from any log source to help weed out false positives,” he said. 

      Now an organization can create a rule that says, for example, if an endpoint detection and response (EDR) solution generates a syslog message with a score of 50 or greater, create an incident out of it, he said. Conversely, if the score is less than 50, the alert will move to the triage module, where a security analyst can perform additional enrichment to make a determination to see whether the alert is an actual incident or not.

      Looking forward, Moran said DFLabs will continue to make its SOAR platform more open. He commented that the open integration framework is a first step in the direction of having a more open development process and community environment surrounding DFLabs overall.

      “I think over the next several months, you’re going to see some other announcements and some other features and products coming out to further achieve a more open community-based feel to the platform and to our services,” he said.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.