This page was machine-translated and may differ from the original. View original
Enhanced response capabilities by combining threat detection technology and machine learning.
Symantec announced 'Symantec Targeted Attack Analytics (TAA),' a high-difficulty targeted attack analysis technology that applies artificial intelligence.
Symantec TAA combines powerful threat detection technology and machine learning, which Symantec's targeted attack analysis team has used to analyze major cyber attacks, to intensively learn the attack techniques of cyber attack groups, providing outstanding response capabilities.
Targeted attacks are one of the most common threats threatening corporate security today. According to Symantec's Internet Security Threat Report (ISTR) Vol. 23, the number of targeted attack groups continues to grow. However, targeted attacks often go undetected amidst the numerous security alerts generated by security systems, giving attackers time to gain access to systems and secure critical data. Accordingly, the security industry has recently been focusing on Endpoint Detection and Response (EDR), which can secure visibility into intrusion attacks based on intelligence and even detect and identify unknown security threats.
Symantec TAA, provided by Symantec ATP (Advanced Threat Protection) solution, is a technology that dramatically improves the detection and response capabilities of EDR by specializing in the attack techniques of cyber attack groups. Previously, EDR could identify internal breaches through various indicators of compromise (IOC) information such as file hash values, malware distribution domains, registry values, and process names. In contrast, Symantec TAA is an innovative technology that not only detects attacks based on these IOCs, but also automatically detects attacks by specific attack groups by combining machine learning with intelligence information gathered by Symantec's specialized targeted attack analysis team over many years of tracking numerous attack groups, such as the infiltration methods used by attackers and the commands used for lateral movement.
Symantec TAA is the result of a collaboration between Symantec's dedicated targeted attack analysis team, which discovered Stuxnet, Regin, and Lazarus, and linked the SWIFT and WannaCry attacks, and Symantec's team of security data scientists who research cutting-edge machine learning. Symantec TAA, which leverages the processes, knowledge, and capabilities of world-class security experts through artificial intelligence, identifies targeted attack activity and provides breach incident reports that prioritize response. This allows companies to accurately identify attacks requiring response without spending significant time and resources on false positives.
Symantec TAA uses machine learning to analyze a wide range of data, including system and network telemetry data from Symantec customers, which has built the world's largest security threat big data collection. Furthermore, its cloud-based technology allows for continuous analysis retraining and updates, eliminating the need for product updates, enabling it to adapt to new attack methods. By automating targeted threat detection in this way, it can identify even sophisticated attacks that are difficult for other solutions to detect.
Symantec TAA is based on the same toolset that Symantec used to discover Dragonfly 2.0, which launched a large-scale attack targeting dozens of energy companies, aiming to gain access to their operational networks. Symantec TAA has proven its accuracy and excellence in attack detection by identifying security breaches in over 1,400 organizations during its internal development period.
Yoon Gwang-taek, CTO of Symantec Korea, said, “Symantec, which has built up extensive threat intelligence based on the Global Intelligence Network (GIN), has gone one step further and combined the unique characteristics and attribute information of attack groups acquired through analysis of cyber attack groups over a long period of time with machine learning to present Symantec TAA technology specialized in targeted attacks.” He added, “Now that general companies can also utilize the high-level targeted attack analysis technology of Symantec’s expert analysis team as a solution, we expect that it will enable them to respond to targeted attacks more effectively.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.














