Wearvalley Adds AI-Based Anomaly Detection to 'ChakraMax'
TECHWORLD ·
✦ AI Summary
Wearvalley announced the release of an AI- and machine learning-based anomaly detection module for its ChakraMax integrated access control solution. The module uses existing audit logs to analyze users' work behavior patterns and identify anomalous behavior by comprehensively examining time, user, Client IP, DB Object, and SQL execution behavior. The detection method combines machine learning (ML), security Rule, and AST (Abstract Syntax Tree)-based syntactic analysis, and also provides risk Scores and visualization features.
As corporate IT environments grow more complex and data access paths diversify, identifying insider data leaks and abnormal data access has emerged as a major security challenge for companies. In particular, the rising risk of accounts with legitimate access privileges being compromised and internal users abusing existing privileges has made the importance of detecting such behavior even more apparent.
However, pre-defined security policies and simple access histories alone have limitations in detecting anomalous behavior early. For that reason, anomaly detection technology based on learning users' usual work patterns is becoming increasingly important.
Wearvalley, a database security specialist, has ChakraMax, an integrated access control solution, and announced the release of an AI- and machine learning-based anomaly detection module for the solution. The core of the module is the use of audit logs accumulated in existing systems, and it can analyze users' work behavior patterns to identify abnormal behavior that differs from the usual.
The system is configured to analyze audit log data such as user access histories, database and server access session information, SQL execution histories, and server CMD execution histories, and to identify work patterns by user based on accumulated data. Accordingly, it supports anomaly detection by going beyond a simple determination of whether access occurred and comprehensively considering various contexts such as time, user, Client IP, DB Object, and SQL execution behavior.
To do this, the applied detection framework uses a three-layer composite detection method that combines machine learning (ML), security Rule, and AST (Abstract Syntax Tree)-based syntactic analysis. ML-based statistical analysis is responsible for detecting patterns that differ from a user's usual behavior, predefined security Rule identify known risky behavior, and AST-based SQL syntax analysis enables analysis of SQL structure and syntax.
The described functions work by examining a range of indicators together, including the time of access, access source, command execution, query volume, and response characteristics, to determine whether behavior is abnormal. As a result, it includes the ability to detect after-hours access, such as late-night and weekend access; detect access from new clients through previously unverified IPs; detect risky DDL execution; detect large-volume data queries and extraction; and detect abnormal response times.
It also broadens the detection scope by combining SQL structure analysis. Along with AST-based analysis, it provides support for detecting abnormal SQL patterns, including SQL injection, and for detecting risky SQL syntax.
Wearvalley also said that by applying user behavior pattern-based analysis functions, it compares learned access patterns for each user, can judge behavior as anomalous when a new table that was not accessed during the learning period is accessed, can judge behavior as anomalous when DML is suddenly performed on a table that is usually Read-focused, and can detect sudden spikes in access frequency to specific tables or data. Through this, behavior changes that are difficult to determine with individual Rule alone can also be used as detection targets.
With the application of operational functions, analysis of detection results has become possible, and the way detection events are provided is not limited to a simple list. It offers visualization functions that allow analysis based on time, account, user, Client IP, and queries, enabling security staff to understand trends in anomalous behavior and related information.
It also assigns a risk Score to each detected anomalous behavior, helping to identify high-risk users and accounts first. Based on this, security staff can set investigation and response priorities centered on high-risk events, and additional access controls and security policies can also be established based on the analysis results.
A Wearvalley official said that the focus of existing access control was on user access control and audit log recording. The official then emphasized the importance of using accumulated log data, understanding normal work patterns, and identifying differing behavior, and said that the ChakraMax anomaly detection module uses time, user, IP, DB Object, and SQL execution behavior as analysis contexts to support detection of anomaly signs that can be easily missed by existing security systems.
The speaker said that customers can use AI and machine learning-based anomaly analysis functions on top of the existing ChakraMax access control environment, and added that the company plans to continue strengthening overall detection, prevention, and response capabilities in the data security field by combining accumulated data with AI and machine learning technologies.
Source: TECHWORLD · Kim Gyeong-ju
Original: https://www.epnc.co.kr/news/articleView.html?idxno=406568
References
This article was produced with the help of an automated content generation algorithm.
Source: TECHWORLD
View originalThis article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.