SPiDER ExD

A next-generation AI Security platform based on XDR
(eXtended Detection & Response) that maximizes the
efficiency of security operations, analytics, and threat
response

What is SPiDER ExD?

With the expanding adoption of new technologies like AI and cloud, the attack surface that adversaries can target is also widening. Today, defenders face the critical challenge of responding to new and evolving threats with limited time and resources. Consequently, the importance of implementing AI-driven eXtended Detection and Response (XDR) is growing, as it secures visibility over distributed IT infrastructure and assets and enhances the capabilities of security personnel.

Centered around 'SPiDER ExD', a next-generation XDR-based security platform, IGLOO Corporation performs diversified data collection, AI/ML-based automated threat analysis and detection, and playbook-based automated response with threat scoring. Additionally, it supports organizations with the data, detection and investigation techniques, security features, and intelligence they need.

As a core element of the AI-Driven XDR strategy, SPiDER ExD is a next-generation security monitoring platform based on XDR, implementing unified 'advanced detection-analysis-response' capabilities. Based on a security operation workflow that leverages organic integration and expansion between heterogeneous solutions and services, it allows for the timely expansion of data, detection and analysis techniques, and functions needed for each organization's evolving security environment and threats. By leveraging advanced Artificial Intelligence (AI) models and automation technologies, it accelerates the classification of high-risk alerts and response speeds, thereby minimizing security gaps that attackers could exploit.

Implementing 'AI-Driven XDR' that Maximizes the Efficiency of Security Operations, Analysis, and Response

Advantages

High availability

Leveraging cluster-based big data architecture and Replica function to ensure service reliability

  • 1

    Cluster-based Parallel Node expansion

    Guaranteed scalability as log increases(Scale-Out) Ability to evenly distribute existing data nodes and storage capacity when new nodes are added Minimizes the time required for expansion without service interruption and ensures convenience of management through central management

  • 2

    Distributed storage / retrieval

    Distribute refined event logs to each data node for storage on a condition basis (Default: Day)

  • 3

    Duplicated Storing

    Store preprocessed event logs on two or more distributed nodes to ensure uninterrupted operation in case of storage device failure Duplicated data are created and stored separately from the stored data, and are distributed and stored on different data nodes Automatic recovery using duplicated data in case of data node (server) failure

  • 4

    Compression / Encryption / Backup

    Stored log data is compressed for efficient use of disk storage space For cold data, encryption is applied at the file level before storage Data backup and deletion management are performed according to backup configuration policies

Enhancing convenience of data retrieval and accuracy of analysis

Securing a high level of data analysis accuracy based on one-step enhanced loading and retrieval capabilities

  • 1

    Normalization for Collection and Loading

    Supports setting of each field using regular expressions without separate development of original log through user-defined parser function The indexing fields generated thereby are utilized for search and analysis, enhancing data search convenience and analytical efficiency

  • 2

    Enhanced Log Searching

    Log search possible based on complex criteria (AND, OR, NOT, etc.) Original logs, along with all indexed fields, are displayed, and additional information such as country and harmful IP details Various search functionalities are offered, including custom searches and interactive searches

  • 3

    Real-time Analysis and Detection

    Utilizing in-memory technology for swift analysis, real-time log analysis to enhance detection accuracy An extended analysis engine integrates SIEM and AI analysis models, providing advanced analytical capabilities

  • 4

    Advanced Search-Based Analysis

    Various analysis condition settings, including specific conditions and regular expressions, are supported for all fields of collected logs Exception condition functionality based on detection rules is provided, allowing for exceptions to be set for specific days and times Constructs a reputation DB based on collected data and provides analysis functions through data from the DB

Extensive Scalability

Easy functional extension through platform-based architecture

Open API integration solution

  • SOAR

    Security Orchestration,
    Automation, and
    Response

  • AI

    Supervised/Unsupervised
    analysis based on
    mashine learning

  • Vulnerability Assessment

    Inegration with vulnerability assessment solutions and
    correlation of results

  • Cyber Threat Intelligence (CTI)

    Integration with threat intelligence, risky IPs, URLs, loCs, and detection policies

  • Dashboards

    User defined dashboards

  • Information Security Portal

    Portal for affiliated organizations coordination

  • Information Security Solution

    Integration of blocking and policy

  • Integration with asset management solutions and system managment solutions

  • SOAR

    Security Orchestration,
    Automation, and
    Response

  • AI

    Supervised/Unsupervised
    analysis based on
    mashine learning

  • Vulnerability Assessment

    Inegration with vulnerability assessment solutions and
    correlation of results

  • Cyber Threat Intelligence (CTI)

    Integration with threat intelligence, risky IPs, URLs, loCs, and detection policies

  • Dashboards

    User defined dashboards

  • Information Security Portal

    Portal for affiliated organizations coordination

  • Information Security Solution

    Integration of blocking and policy

  • Integration with asset management solutions and system managment solutions

Advanced Threat Detection and Response

Provides advanced threat detection, additional features, and integration support

A next-generation AI Security platform based on XDR (eXtended Detection & Response) that maximizes the efficiency of security operations, analytics, and threat response

Key Features

SPiDER ExD is the most comprehensive SIEM solution that supports flexible expansion and integration of security functionalities. Through a container-centric platform and UI integration, it enables an eXtended Detection Investigation Response (XDIR) architecture.

A next-generation AI Security platform based on XDR (eXtended Detection & Response) that maximizes the efficiency of security operations, analytics, and threat response

System Structure

By organically integrating cast security data and internal/external threat intelligence
Commencement of the eXtended Detection Investigation Response framework

Expected Effect

With SPiDER ExD, experience Expanded Detection, Diversified Analysis, and Accelerated Response.

SPiDER ExD will secure integrated visibility covering the entire attack surface and proactively respond to the constantly changing IT environment through the collection of vast security data, highly accurate analysis, implementation of automated response processes, and broad integration and expansion of security functions.

A next-generation AI Security platform based on XDR (eXtended Detection & Response) that maximizes the efficiency of security operations, analytics, and threat response