Next-Gen SIEM: Converging Data, Security, IT, Workflow Automation & AI

RSA Conference 2024 · West Stage Keynote

Overview

In this compelling keynote at RSAC 2024, George Kurtz, CEO and Co-founder of Crowdstrike, laid bare the critical challenges facing modern cybersecurity operations and articulated a bold vision for the future: the Next-Gen SIEM and the AI-Native SOC. Kurtz, a veteran of the cybersecurity landscape with nearly three decades of experience, emphasized that the fundamental mission remains "stopping breaches," a goal increasingly difficult to achieve with traditional tools and approaches. He meticulously dissected the shortcomings of legacy Security Information and Event Management (SIEM) systems, particularly their inability to contend with the overwhelming volume of data and the accelerating speed of adversaries.

Watch on YouTube

Visual summary for Next-Gen SIEM: Converging Data, Security, IT, Workflow Automation & AI
Visual summary for Next-Gen SIEM: Converging Data, Security, IT, Workflow Automation & AI

Key moments

  1. 2:00 Crowdstrike's mission: stopping breaches, adversary speed.
  2. 3:20 The core security challenge: data overload and time.
  3. 4:35 Legacy SIEM limitations and the "data paradox".
  4. 6:30 Legacy SIEM's critical failure: inability to stop breaches.
  5. 7:40 Defining Next-Gen SIEM: integrated platform approach.
  6. 8:15 The future SOC: fusing data with AI automation.

Next-Gen SIEM: Converging Data, Security, IT, Workflow Automation & AI

Speakers: George Kurtz, CEO and Co-founder, Crowdstrike

Conference: RSAC 2024

YouTube: https://www.youtube.com/watch?v=jp3rzRhDyM4

Overview

In this compelling keynote at RSAC 2024, George Kurtz, CEO and Co-founder of Crowdstrike, laid bare the critical challenges facing modern cybersecurity operations and articulated a bold vision for the future: the Next-Gen SIEM and the AI-Native SOC. Kurtz, a veteran of the cybersecurity landscape with nearly three decades of experience, emphasized that the fundamental mission remains "stopping breaches," a goal increasingly difficult to achieve with traditional tools and approaches. He meticulously dissected the shortcomings of legacy Security Information and Event Management (SIEM) systems, particularly their inability to contend with the overwhelming volume of data and the accelerating speed of adversaries.

The core of Kurtz's argument centered on what he termed the "data paradox" – the inherent conflict between the desire to ingest and store all security-relevant data and the prohibitive costs associated with doing so. This paradox, coupled with the sluggish performance of outdated SIEM architectures, leaves defenders at a severe disadvantage against threat actors capable of lateral movement in mere minutes. The talk presented a transformative roadmap, highlighting how the convergence of data, security, IT operations, workflow automation, and artificial intelligence can "bend time in security," enabling organizations to move faster than the adversary and achieve a truly proactive defensive posture.

This article delves into Kurtz's insights, exploring the evolution of SIEM, the technical underpinnings of his proposed next-generation solutions, and the profound implications for security teams. It examines how AI is poised to revolutionize everything from data ingestion and normalization to predictive threat intelligence and automated response, ultimately elevating the role of the human analyst and fortifying the enterprise against an ever-evolving threat landscape.

Background

▶ Watch: Crowdstrike's mission: stopping breaches, adversary speed. (2:00)

The concept of Security Information and Event Management (SIEM) was first coined by Gartner in 2005. At its inception, SIEM was designed to aggregate low-fidelity signals and alerts from disparate systems across an enterprise, correlating them to identify patterns indicative of sophisticated threats, particularly Advanced Persistent Threats (APTs), which were notoriously difficult to detect at the time. The promise was clear: by centralizing and analyzing event data, organizations could gain unprecedented visibility into their security posture and improve incident response.

However, the cybersecurity landscape has undergone a dramatic transformation since 2005, evolving far beyond the capabilities of these foundational SIEM architectures. George Kurtz highlighted that today's Security Operations Centers (SOCs) have fundamentally outgrown legacy SIEMs due to several critical factors. The most pervasive issue is the data paradox: while organizations recognize the imperative to ingest and store vast quantities of security data for comprehensive threat detection and compliance, the exponential costs associated with storage, processing, and licensing often force them to make financially driven decisions over security-driven ones. This leads to critical data gaps and compromises in visibility.

Furthermore, the speed of modern adversaries has rendered legacy SIEMs dangerously slow. Kurtz cited alarming statistics from Crowdstrike’s observations: the fastest observed breakout time (the period from initial compromise to an adversary moving laterally within a network) was a mere two minutes and seven seconds. The average breakout time stands at 79 minutes. Even more concerning, an adversary was observed downloading their toolkit and initiating reconnaissance tools in just 31 seconds. In stark contrast, legacy SIEMs often take days to ingest data, process queries, or even triage an incident, creating a chasm between detection capabilities and the speed required for effective response. This temporal mismatch is a primary reason why many breaches continue to occur despite the presence of traditional SIEM solutions.

Another significant limitation Kurtz identified is the prevalent practice of "bolting on" Security Orchestration, Automation, and Response (SOAR) platforms to existing SIEMs. While SOAR aims to automate response actions, this architectural separation means data is shipped "out of band" from where breaches actually happen – typically at the endpoint or workload level. This creates latency and inefficiency, preventing rapid, in-line action "at the tip of the spear" and hindering the ability to react quickly and decisively when an incident unfolds. These systemic issues underline the urgent need for a paradigm shift in how security data is managed, analyzed, and acted upon.

Key Findings

▶ Watch: Legacy SIEM limitations and the "data paradox". (4:35)

George Kurtz's keynote delivered several critical findings and contributions that underscore the urgency for a new approach to cybersecurity operations. Foremost among these is the stark reality that legacy SIEMs are no longer fit for purpose in the face of modern, fast-moving adversaries and the overwhelming volume of security data. The "data paradox"—the conflict between the need to ingest all data for security and the prohibitive cost—is actively compromising organizational defenses, forcing decisions based on budget rather than risk.

A pivotal finding is the unacceptable speed gap between defenders and attackers. Kurtz highlighted Crowdstrike's observation of a fastest adversary breakout time of two minutes and seven seconds, with toolkit downloads and reconnaissance starting in just 31 seconds. This temporal reality makes the days-long data ingestion and query times of legacy SIEMs a critical vulnerability, directly contributing to their failure to stop breaches. This emphasizes that "bending time in security" is no longer an aspiration but a necessity.

The talk introduced the concept of Next-Gen SIEM as an integrated solution, fundamentally different from its predecessors. This next-generation platform must not merely aggregate data but be integrated directly into the security platform, living "where your SOC actually does the work." A key contribution is the assertion that AI and automation are indispensable for solving the data paradox and accelerating response. Specifically, AI is positioned to automatically ingest, parse, and normalize data from diverse sources, overcoming the "disaster" of manual schema mapping and disparate vendor definitions. This automated data management is crucial for efficient enrichment and turning low-fidelity alerts into actionable incidents.

Finally, Kurtz unveiled the vision of the AI-Native SOC, framed as the operating system for future security operations. This concept represents a shift from reactive, human-intensive processes to a proactive, intelligent, and highly automated defense. It promises not only to detect and respond to threats faster but also to introduce capabilities like predictive security and adaptive security posture, fundamentally transforming how organizations anticipate and mitigate risk. The overarching message is that AI is not just an enhancement but the foundational technology required to empower defenders and ultimately fulfill the mission of stopping breaches.

Technical Deep Dive

▶ Watch: Legacy SIEM's critical failure: inability to stop breaches. (6:30)

The technical foundation of George Kurtz's vision for Next-Gen SIEM and the AI-Native SOC represents a significant architectural departure from traditional security operations. At its core, the Next-Gen SIEM is not a standalone product but rather an integrated component of a broader security platform. This integration means it "lives where your SOC actually does the work," eliminating the costly and inefficient practice of shipping data out of band to separate SIEM and SOAR systems.

A fundamental aspect of this architecture is its approach to data ingestion and management. Kurtz noted that typically, 85% of data ingested into a SIEM originates from endpoint and cloud security tools like Endpoint Detection and Response (EDR). The Next-Gen SIEM leverages this by starting with endpoint and cloud data as its primary source, then intelligently ingesting the remaining 15% from other third-party security and non-security sources. The critical innovation here is the role of AI in data processing. Legacy systems struggle with the "disaster" of manual parsing and normalization due to varied schemas across different vendors. The Next-Gen SIEM employs AI to automatically understand, ingest, parse, and normalize data without prior knowledge of the schema. This capability tackles a long-standing pain point where "each schema from each vendor is a little bit different," and terms for common elements like an IP address might vary.

Once data is ingested and normalized, AI-driven data enrichment becomes paramount. The system automatically enriches raw alerts, adding context from various sources to transform them into actionable incidents, significantly reducing the time analysts spend on triage and false positive investigation. This leads directly to generative workflows, where analysts can "interrogate the data" using natural language queries, asking questions and receiving answers, rather than navigating complex user interfaces. This shifts the interaction model from manual clicking to intelligent conversation, accelerating investigation and response.

For organizations with specialized needs, the Next-Gen SIEM supports a "bring your own LLM" model. This allows customers to process their data and build custom machine learning and AI models directly within the platform, leveraging their existing data without the prohibitive cost and complexity of moving it to external data lakes. This also extends to automated log generation and management, where the system intelligently ages out irrelevant data, retains what's necessary for compliance, and ensures efficient searchability over long periods, breaking the traditional "cost productivity curve" of SIEM by shifting from an exponential cost model to a more predictable, "unlimited plan" type of expenditure.

The ultimate manifestation of this integrated platform is the AI-Native SOC, characterized by several key attributes:

  1. Advanced Threat Detection & Automated Response: This is a prerequisite. The AI-Native SOC analyzes massive datasets in real-time, detecting complex, never-before-seen threats, including zero-days, by identifying intricate dependencies. It drives automated responses such as system isolation, patching, and remediation, fundamentally "compressing and bending time in security."
  2. Predictive Security: Leveraging AI, the SOC can identify potential attack paths within an environment by analyzing threat intelligence, actor profiles, asset vulnerabilities, and configurations. This generates a "graph" of potential exploitation, allowing IT and security teams to prioritize fixes based on the most probable and impactful attack vectors.
  3. Workflow Automation: Beyond simple orchestration, AI facilitates generative automation. Analysts can, for example, ask the system to identify vulnerable assets and then instruct it to "create a PowerShell script and deploy that PowerShell script" for remediation. Kurtz highlighted the urgency of this, noting that adversaries are already using generative AI to disassemble patches, create exploits, and deploy them rapidly, shrinking the exploitation window from days to hours.
  4. Adaptive Security Posture: The AI-Native SOC is self-learning. It continuously adapts to an organization's unique environment, understanding patterns of malicious insider behavior, specific threat exploitation techniques, and evolving attack surfaces. This adaptive retraining ensures the system's intelligence remains highly relevant and effective over time.
  5. Contextual Security Intelligence: AI contextualizes diverse alerts, tying together low-fidelity signals to create comprehensive incidents and insights that might otherwise be missed. Kurtz shared an anecdote where a SOC analyst manually added context to a low-fidelity alert, correlating IP addresses, users, and other data, leading to the containment of an adversary within a 10-minute window. The AI-Native SOC automates this arduous contextualization, providing deeper insights into the "why," "cause," and "potential impact" of security events.

Finally, a particularly exciting application of generative AI within the Next-Gen SIEM is compliance reporting. The system can take all the rich security data and, upon request, generate reports tailored to specific frameworks like PCI, HIPAA, or NIST. This capability promises to cut out an "incredible" amount of manual effort currently spent mapping frameworks and compiling reports, transforming a historically "disaster" area into an automated process.

This comprehensive technical overhaul, driven by AI, aims to converge people, workflow automation, data, and artificial intelligence into a cohesive operating system for the modern SOC, fundamentally revolutionizing security operations and empowering defenders.

Demo / Proof of Concept

▶ Watch: Defining Next-Gen SIEM: integrated platform approach. (7:40)

While George Kurtz’s keynote at RSAC 2024 was a visionary presentation focused on strategic concepts and architectural shifts, it did not include a live technical demonstration or proof of concept. The talk primarily served to outline the problems with legacy SIEMs and present the theoretical framework for Next-Gen SIEM and the AI-Native SOC. However, Kurtz did allude to the existence of these capabilities, stating, "If you haven't seen some of this stuff and you haven't actually played with it, it's incredibly powerful," suggesting that such demonstrations are available elsewhere, likely in product showcases or private briefings.

Defensive Implications

▶ Watch: The future SOC: fusing data with AI automation. (8:15)

The implications of George Kurtz's vision for Next-Gen SIEM and the AI-Native SOC are profound for security defenders, demanding a strategic re-evaluation of current practices and a proactive embrace of emerging technologies. The core message is clear: legacy approaches are failing, and a fundamental shift is required to effectively "stop breaches" in an era of rapidly accelerating threats.

Firstly, defenders must prioritize the integration of security platforms over disparate point solutions. The concept of an integrated Next-Gen SIEM that lives "where your SOC actually does the work" emphasizes the need to converge data, security, IT operations, and automation into a unified ecosystem. This means moving away from the costly and inefficient practice of shipping data between isolated tools, which only exacerbates the "data paradox" and slows response times.

Secondly, embracing AI and generative automation is no longer optional but a strategic imperative. Defenders should actively seek out and implement solutions that leverage AI for automated data ingestion, parsing, and normalization, thereby eliminating the manual "disaster" of schema mapping and freeing up valuable analyst time. Generative AI's ability to create intelligent workflows, answer complex queries, and even generate remediation scripts (like PowerShell scripts for deploying patches) will be crucial for compressing the adversary's window of opportunity. As Kurtz noted, adversaries are already using AI to accelerate exploit development, making AI-driven defense a necessity to keep pace.

Thirdly, security teams need to shift towards a predictive and adaptive security posture. Leveraging AI to identify potential attack paths based on an organization's unique threat environment, assets, and vulnerabilities allows for proactive prioritization of fixes, moving beyond reactive patching. Furthermore, investing in self-learning systems that adapt to an organization's specific threat landscape and internal user behaviors will build a more resilient and context-aware defense. This adaptive capability helps identify unique threats like malicious insiders more effectively.

Finally, the role of the SOC analyst is poised for a significant transformation. Instead of being bogged down by mundane, repetitive tasks and manual triage, analysts will be empowered by AI to focus on higher-level threat hunting, strategic analysis, and incident response. Kurtz confidently asserted that "the only SOC analysts that are going to be out of business are the ones that don't actually embrace AI." This highlights the need for continuous skill development, encouraging analysts to learn how to effectively leverage AI tools to elevate their capabilities, turning "Tier 1 analysts into Tier 3" and making their work more impactful and less tedious. Adopting AI for compliance reporting (PCI, HIPAA, NIST) also offers a massive time-saving opportunity, freeing up resources for core security tasks.

Key Takeaways

  • Legacy SIEMs are Obsolete: Traditional SIEM architectures are failing to keep pace with modern adversaries, exemplified by a fastest breakout time of 2 minutes and 7 seconds, and are crippled by the "data paradox" of prohibitive costs versus the need for comprehensive data ingestion.
  • AI-Driven Data Management is Critical: Next-Gen SIEMs must integrate AI for automatic ingestion, parsing, and normalization of data from diverse sources, overcoming the manual complexities of disparate vendor schemas and enabling efficient data enrichment.
  • The AI-Native SOC is the Future: This new operational model leverages AI for advanced, real-time threat detection, automated response, predictive security (identifying attack paths), and an adaptive security posture that self-learns from an organization's unique environment.
  • Generative AI Transforms Workflows and Compliance: AI enables natural language querying for investigations, automates complex workflows (e.g., generating and deploying remediation scripts), and drastically streamlines compliance reporting for frameworks like PCI, HIPAA, and NIST.
  • Defenders Must Embrace AI: The future of security operations requires SOC analysts to actively adopt and leverage AI tools, transforming their roles from manual triage to strategic threat analysis and incident response, thereby "bending time in security" to outpace adversaries.
  • Cost Model Innovation: Next-Gen SIEM aims to break the traditional exponential cost curve of data ingestion, moving towards more predictable, "unlimited plan" like pricing models that encourage comprehensive data collection without financial penalty.

About the Speaker(s)

George Kurtz is the CEO and Co-founder of Crowdstrike, a leading cybersecurity technology company. With a distinguished career spanning nearly three decades in the cybersecurity industry, Kurtz is a highly respected voice in the field, having attended RSA Conference almost 30 times. His professional mission, and that of Crowdstrike, is singularly focused on "stopping breaches." Throughout his career, he has consistently emphasized the critical importance of speed and addressing the fundamental "data problem" in security, advocating for innovative architectural solutions to empower defenders against evolving threats. Kurtz is known for his forward-thinking perspectives on leveraging advanced technologies, particularly artificial intelligence, to revolutionize security operations.

All talks from RSA Conference 2024