<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Elastic、 Security、 SIEM 彙整 - 歐立威科技</title>
	<atom:link href="https://www.omniwaresoft.com.tw/tag/elastic%E3%80%81-security%E3%80%81-siem/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>歐立威科技 Omniwaresoft｜全方位企業級開源軟體解決方案</description>
	<lastBuildDate>Tue, 22 Apr 2025 03:24:14 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.7.4</generator>

<image>
	<url>https://www.omniwaresoft.com.tw/wp-content/uploads/2022/12/android-icon-192x192-1.png</url>
	<title>Elastic、 Security、 SIEM 彙整 - 歐立威科技</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">242464019</site>	<item>
		<title>Elastic Security – SIEM 資訊安全監控中心</title>
		<link>https://www.omniwaresoft.com.tw/product-news/elastic-news/elk-siem-soc/</link>
		
		<dc:creator><![CDATA[Peggy]]></dc:creator>
		<pubDate>Wed, 29 Dec 2021 07:03:56 +0000</pubDate>
				<category><![CDATA[Elastic 產品資訊]]></category>
		<category><![CDATA[產品資訊]]></category>
		<category><![CDATA[Elastic、 Security、 SIEM]]></category>
		<guid isPermaLink="false">http://www.omniwaresoft.com.tw/?p=16814</guid>

					<description><![CDATA[在當前資訊安全的挑戰中，SIEM（安全資訊與事件管理）系統成為企業防禦的關鍵。Elastic Security 提供雲端解決方案，能有效利用各種資料來源進行威脅偵測和回應，並提升企業的營運成熟度。

本篇將探討 Elastic Security 的功能與優勢，展示其如何透過高效資料處理和自動化管理，幫助企業在面對不斷變化的威脅時，保持競爭優勢。]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading" style="font-size: 24px;"><span style="font-size: 24px;"><b>SIEM for the modern SOC</b> <b>資訊安全監控中心</b></span></h2>



<p class="wp-block-heading"><span style="font-weight: 400; font-size: 12pt;">SIEM（Security Information and Event Management）能在雲端上利用任何資料源偵測、調查和回應不斷變化的威脅，並在主機層擁有更完善的管理。</span></p>
<p class="wp-block-heading"><span style="font-weight: 400; font-size: 12pt;">在現代安全使用案例下，透過免費且開放的 Elastic Security 提高營運成熟度並加速擴展。</span></p>



<h2 class="wp-block-heading" style="font-size: 24px;"><span style="font-size: 24px;"><b>以 Elasticsearch 的速度實現 SecOps</b></span></h2>



<p><span style="font-weight: 400; font-size: 12pt;">藉由分析和賦能多年的資料，在多雲的環境中擴展資料結構，Elasticsearch 統一分析師工作流程並與第三方技術整合。透過主動管理威脅和事件響應平台提高營運成熟度。</span></p>



<h3 class="wp-block-heading" style="font-size: 24px;"><strong><span style="font-size: 14pt;">以速度取勝</span></strong></h3>



<p><span style="font-size: 12pt;"><span style="font-weight: 400;">體驗</span> <a href="https://www.elastic.co/blog/schema-on-write-vs-schema-on-read" target="_blank" rel="noopener"><span style="font-weight: 400;">schema-on-write</span></a><span style="font-weight: 400;"> 的速度和</span> <a href="https://www.elastic.co/blog/introducing-elasticsearch-runtime-fields?elektra=organic&amp;storm=CLP&amp;rogue=free-and-open-gic" target="_blank" rel="noopener"><span style="font-weight: 400;">schema-on-read</span></a> <span style="font-weight: 400;">的靈活性。</span></span></p>
<p><span style="font-size: 12pt;"><span style="font-weight: 400;">探索自定義儀表板，深入了事件，並透過基礎資料進行透視。</span></span></p>



<h3 class="wp-block-heading" style="font-size: 24px;"><span style="font-size: 14pt;"><b>大規模運行</b></span></h3>



<p><span style="font-weight: 400; font-size: 12pt;">在 S3 等低成本物件儲存資料庫中保留的多年資料進行搜尋和偵查，並以 petabyte 處理資安資料，將您的搜尋帶入資料以進行全面分析。</span></p>



<h3 class="wp-block-heading"><span style="font-size: 14pt;"><b>收集時也保護資料</b></span></h3>



<p><span style="font-size: 12pt;"><span style="font-weight: 400;">透過 osquery 收集主機資料並阻止</span><a href="https://www.elastic.co/endpoint-security/" target="_blank" rel="noopener"><span style="font-weight: 400;">惡意程式和勒索軟體</span></a><span style="font-weight: 400;">，在整個環境範圍內部署免費且開源的</span> <a href="https://www.elastic.co/blog/introducing-elastic-agent-and-ingest-manager" target="_blank" rel="noopener"><span style="font-weight: 400;">Elastic Agent</span></a><span style="font-weight: 400;">， 只需點擊即可完成新用例。</span></span></p>



<h3 class="wp-block-heading"><span style="font-size: 14pt;"><b>資訊安全分析</b></span></h3>



<p><span style="font-size: 12pt;"><span style="font-weight: 400;">透過</span><a href="https://www.elastic.co/integrations?solution=security" target="_blank" rel="noopener"><span style="font-weight: 400;">預先建構的資料整合</span></a><span style="font-weight: 400;">，在攻擊面中實現安全分析。</span></span></p>



<h2 class="wp-block-heading"><span style="font-size: 24px;"><b>建立全面概觀</b></span></h2>



<p><span style="font-size: 12pt;"><span style="font-weight: 400;">使用 </span><a href="https://www.elastic.co/blog/introducing-the-elastic-common-schema" target="_blank" rel="noopener"><span style="font-weight: 400;">Elastic Common Schema（ECS）</span></a> <span style="font-weight: 400;">實現統一分析，並集中管理環境活動和內部與外部環境。</span></span></p>
<p><span style="font-size: 12pt;"><span style="font-weight: 400;">無論資料源如何，該解決方案可以輕鬆地分析來自數位網域內外的資訊。</span></span></p>



<figure class="wp-block-image size-large is-resized"><img data-recalc-dims="1" fetchpriority="high" width="1024" height="576" class="wp-image-31001" style="width: 636px; height: 357px;" src="https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/security-network.jpeg?resize=1024%2C576&#038;ssl=1" alt="security siem" srcset="https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/security-network.jpeg?resize=1024%2C576&amp;ssl=1 1024w, https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/security-network.jpeg?resize=300%2C169&amp;ssl=1 300w, https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/security-network.jpeg?resize=768%2C432&amp;ssl=1 768w, https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/security-network.jpeg?w=1487&amp;ssl=1 1487w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading"><span style="font-size: 14pt;"><b>環境分析</b></span></h3>



<p><span style="font-weight: 400; font-size: 12pt;">使用儀表板監控資料，並快速訪問幾乎任何領域的趨勢圖。</span></p>
<p><span style="font-weight: 400; font-size: 12pt;">探索任何類型的資訊，可搜尋的快照可以用很低的成本擴展資料可見性的廣度和持久度，這一切都足以讓分析師滿意。</span></p>



<figure class="wp-block-image size-large is-resized"><img data-recalc-dims="1" width="1024" height="576" class="wp-image-31002" style="width: 625px; height: 351px;" src="https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/gain-visibility-into-your-environment-1536x864-1.png?resize=1024%2C576&#038;ssl=1" alt="elastic security" srcset="https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/gain-visibility-into-your-environment-1536x864-1.png?resize=1024%2C576&amp;ssl=1 1024w, https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/gain-visibility-into-your-environment-1536x864-1.png?resize=300%2C169&amp;ssl=1 300w, https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/gain-visibility-into-your-environment-1536x864-1.png?resize=768%2C432&amp;ssl=1 768w, https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/gain-visibility-into-your-environment-1536x864-1.png?w=1536&amp;ssl=1 1536w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading"><span style="font-size: 14pt;"><b>高保真（high-fidelity）規則自動檢測</b></span></h3>



<p><span style="font-size: 12pt;"><span style="font-weight: 400;">利用基於行為的規則（behavior-based rules）持續保護環境，以偵測具有潛在威脅的行為和工具。</span></span></p>
<p><span style="font-size: 12pt;"><span style="font-weight: 400;">分析攻擊者的行為，評估風險和嚴重度，對潛在威脅進行相對應的優先排序。</span></span></p>
<p><span style="font-size: 12pt;"><span style="font-weight: 400;">這些檢測結果與 MITRE ATT&amp;CK® 保持一致，</span><a href="https://www.elastic.co/guide/en/security/current/prebuilt-rules-downloadable-updates.html" target="_blank" rel="noopener"><span style="font-weight: 400;">定期更新</span></a><span style="font-weight: 400;">並</span><a href="https://github.com/elastic/detection-rules" target="_blank" rel="noopener"><span style="font-weight: 400;">公開分享</span></a><span style="font-weight: 400;">。</span></span></p>



<figure class="wp-block-image size-large is-resized"><img data-recalc-dims="1" width="1024" height="570" class="wp-image-31003" style="width: 629px; height: 349px;" src="https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/siem-detection-alerts-ga.png?resize=1024%2C570&#038;ssl=1" alt="SIEM Detection Alert" srcset="https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/siem-detection-alerts-ga.png?resize=1024%2C570&amp;ssl=1 1024w, https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/siem-detection-alerts-ga.png?resize=300%2C167&amp;ssl=1 300w, https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/siem-detection-alerts-ga.png?resize=768%2C428&amp;ssl=1 768w, https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/siem-detection-alerts-ga.png?w=1536&amp;ssl=1 1536w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading"><span style="font-size: 14pt;"><b>使用機器學習和實體 (entity) 分析評估風險</b></span></h3>



<p><span style="font-weight: 400; font-size: 12pt;">透過由預先建構的 ML 作業提供支援偵測異常，預防未知威脅。</span></p>
<p><span style="font-weight: 400; font-size: 12pt;">基於證據的假設（evidence-based hypotheses）偵測不論是否在預期內的各種威脅，保護有更高風險的主機和其他實體。</span></p>



<figure class="wp-block-image size-large is-resized"><img data-recalc-dims="1" loading="lazy" width="1024" height="576" class="wp-image-31004" style="width: 633px; height: 355px;" src="https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/siem-host-anomaly-detail.png?resize=1024%2C576&#038;ssl=1" alt="siem-host-anomaly-detail" srcset="https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/siem-host-anomaly-detail.png?resize=1024%2C576&amp;ssl=1 1024w, https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/siem-host-anomaly-detail.png?resize=300%2C169&amp;ssl=1 300w, https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/siem-host-anomaly-detail.png?resize=768%2C432&amp;ssl=1 768w, https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/siem-host-anomaly-detail.png?w=1091&amp;ssl=1 1091w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading"><span style="font-size: 14pt;"><b>簡化調查、自動回應</b></span></h3>



<p><span style="font-weight: 400; font-size: 12pt;">透過威脅情報豐富告警並收集洞察，透過詳細的調查指南和內建的案例管理來標準化團隊流程，</span><span style="font-weight: 400; font-size: 12pt;">在交互式時間線上收集調查結果。</span></p>
<p><span style="font-weight: 400; font-size: 12pt;">檢查主機並在分散式端點上立即採取行動，並且透過 SOAR（資安協作自動化回應）和 ticketing 工作流程的整合保持動力。</span><br /><br />解更多 <a href="https://www.elastic.co/siem/" target="_blank" rel="noopener">Elastic SIEM </a>或 <a href="https://www.omniwaresoft.com.tw/elastic/" target="_blank" rel="noopener">Elasticsearch產品介紹</a>，或<a href="https://www.omniwaresoft.com.tw/contactus/" target="_blank" rel="noopener">聯絡我們</a>。</p>



<figure class="wp-block-image size-large is-resized"><img data-recalc-dims="1" loading="lazy" width="1024" height="576" class="wp-image-31005" style="width: 642px; height: 360px;" src="https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/screenshot-integrations-case-servicenow-secops.png?resize=1024%2C576&#038;ssl=1" alt="integrations-case-servicenow-secops" srcset="https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/screenshot-integrations-case-servicenow-secops.png?resize=1024%2C576&amp;ssl=1 1024w, https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/screenshot-integrations-case-servicenow-secops.png?resize=300%2C169&amp;ssl=1 300w, https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/screenshot-integrations-case-servicenow-secops.png?resize=768%2C432&amp;ssl=1 768w, https://i0.wp.com/www.omniwaresoft.com.tw/wp-content/uploads/2022/07/screenshot-integrations-case-servicenow-secops.png?w=1424&amp;ssl=1 1424w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p><strong>歐立威科技致力成為全方位開源軟體解決方案與資料分析專業建置商，我們提供 <a href="https://www.omniwaresoft.com.tw/elastic/" target="_blank" rel="noopener">Elastic </a>的規劃部署、架構整合、教育訓練與技術服務。</strong></p>
<p><strong>如果想要獲得更多資訊，歡迎與<a href="https://www.omniwaresoft.com.tw/contact/" target="_blank" rel="noopener">我們聯繫 </a>，或是<a href="https://page.line.me/870pcqyh?oat__id=4761625&amp;openQrModal=true" target="_blank" rel="noopener">加入歐立威 Line 好友</a>！</strong></p>



<div class="wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-1 wp-block-buttons-is-layout-flex">
<div class="wp-block-button has-custom-font-size has-medium-font-size">
  <a class="wp-block-button__link has-background wp-element-button" href="https://www.omniwaresoft.com.tw/contactus/" target="_blank" rel="noreferrer noopener" style="background-color:#ac2323; border-radius: 50px; padding: 10px 25px; display: flex; align-items: center; justify-content: center; font-size: 14px;">聯絡我們</a>
</div>

</div>



<p>&nbsp;</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">16814</post-id>	</item>
	</channel>
</rss>
