Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - SIEM or SIEVE?
Articles

SIEM or SIEVE?

ISBuzz TeamBy ISBuzz TeamJuly 5, 2016Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Security Information and Event Management (SIEM) systems have been the cornerstone of many IT security monitoring strategies. But as the threats facing organizations and the tools used to protect against them have become more complex, SIEMs have become more like sieves.

Sieve. /siv/ noun. 1. A utensil consisting of a wire or plastic mesh held in a frame, used for straining solids from liquids, for separating coarser from finer particles, or for reducing soft solids to a pulp.

How Did This Happen?

With attacks from highly-skilled adversaries hitting organizations from multiple vectors in order to exploit any potential weakness, security professionals have been forced to implement a number of different point tools to mount a reliable defense. Over time, most organizations have built a security arsenal to include intrusion prevention systems, endpoint protection, detection and response systems, antivirus, firewalls, identity and access management systems, and many other tools. These systems create a lot of log data – and the combined weight of that data simply became too much for security teams to reliably manage without a purpose-built tool.

This is why SIEM systems became popular. They became a must-have for organizations to capture and manage all the data that their meshwork of security solutions create. With this data captured in one place, monitoring rules could be constructed, initially to generate alerts when certain event thresholds had been exceeded, but ultimately extending to detect complex event sequences envisioned by security subject matter experts. The theory was that alerts raised by the SIEM would be investigated by the organization’s security incident response team.

But as attacks increased in volume and persistency – and IT infrastructures became more complex – the SIEM-based monitoring approach became too noisy (generating too many alerts) and too difficult to maintain. Thresholds and rules would need to be constantly updated when infrastructure usage changed or new security tools were added. As a consequence, noisy alerts were often ignored, and out-of-date rules missed significant security events. Threats continued to get through the meshwork of tools that SIEMs were designed to hold together – and that’s when SIEM-based monitoring started to act more like a sieve.

Target became the poster child  for missing alerts after its 2013 data breach that resulted in 40 million stolen credit card numbers. And a study that Enterprise Strategy Group (ESG) published earlier this year found that nearly a third of companies are ignoring at least half of all security alerts due to their inability to keep up with the large volume.

To make matters worse, the sheer volume of data being created by the different security and IT infrastructure tools has become too much for many SIEMs to handle. The reality is that simply managing security data has become a “big data” problem, and many SIEMs were not build on “big data” architectures. Thus another opportunity for threats to either be missed or ignored because of data overload came into play.

There’s some irony in the fact that SIEM systems were originally presented as a solution to help security teams deal with high volumes of security-related data, and now their usefulness is being challenged by that very same issue. Clearly, something has to be done.

Saving SIEMs

While SIEMs may be struggling to find their way in the new reality of security data overload, the need for security monitoring is not going away anytime in the near future – nor should it. SIEM systems provide a critical foundation on which to build a cybersecurity defense. The current challenges that SIEMs face – producing too many low-quality security events and not enough meaningful insights to detect advanced threats – can be overcome.

SIEMs just need more brainpower, the type that can be added with advanced analytics that operate on the “big data” store formerly known as the SIEM database.

Basic analytic capabilities – like being able to search event logs, apply thresholds and human expert-created rules, and run reports – are no longer enough. In order to level the playing field with today’s sophisticated cyber criminals, advanced analytics – those that can provide insights regarding  unusual  behaviors in the data, relationships in the data, and even predictions of what may happen next and/or how it can be addressed – are becoming essential.  One way to think of advanced analytics is as a team of “algorithmic assistants” employed by the security team to be ever-vigilant, looking for unusual behaviors in the data. Security pros still use their knowledge to guide the operation of the analytics, but the tedious and sometimes impossible-for-humans tasks of analyzing massive data sets is done by the analytics.

Advanced analytics, such as machine learning-based behavioral analytics, are already proving how they can help SIEM systems do their job better. These capabilities provide numerous improvements over the capabilities of static, human-defined rules and thresholds that have to be continuously updated and fine-tuned based on current threat activity. Machine learning can learn what normal activity looks like in massive and constantly changing security and IT data so it can automate the identification of unusual activity that may indicate a system compromise or a data exfiltration event. And since malicious activity rarely happens in isolation, linking together unusual behaviors based on common entities such as users, hosts, domains, or IP addresses, allows organizations to identify the root cause of an attack more quickly.

Instead of simply reporting on what happened, this type of advanced security analytics allows organizations to spot attacks and identify their root cause in near real time, essentially closing the sieve. While the usefulness of SIEMs may have been stretched to its “leaking” point, complementing them with more intelligent technology, like machine learning-powered advanced analytics, can make all the difference in an organization’s ability to sift out the real threats instead of letting them slide through their defenses.

[su_box title=”About Mike Paquette” style=”noise” box_color=”#336588″][short_info id=’77402′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}