AI Security AI安全 6h ago Updated 2h ago 更新于 2小时前 42

Abstract Raises $25 Million to Expand Composable Security Operations Platform Abstract融资2500万美元以扩展组合式安全运营平台

Abstract Security raised $25 million to accelerate its streaming-first security operations platform, bringing total funding to nearly $50 million. The platform utilizes a "composable" architecture that decouples data sources from destinations, allowing organizations to mix and match security stack components. Detection capabilities analyze data in motion rather than post-indexing, with automated schema conversion (OCSF, ECS, CIM) to reduce storage costs. AI is embedded into every stage of the se Abstract Security 完成 2500 万美元融资,总融资额近 5000 万美元,估值较上一轮翻三倍。 推出“可组合安全运营”平台,采用流式优先架构,实现数据源与目的地的解耦。 支持在数据流动过程中进行实时检测,而非仅依赖索引后的存储数据分析。 通过自动将数据转换为 OCSF、ECS 和 CIM 等标准模式,优化下游工具兼容性并降低存储成本。 创始团队来自 ArcSight、Palo Alto Networks 等知名安全厂商,旨在打造嵌入 AI 的全流程安全运营体系。

60
Hot 热度
65
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • Abstract Security raised $25 million to accelerate its streaming-first security operations platform, bringing total funding to nearly $50 million.
  • The platform utilizes a "composable" architecture that decouples data sources from destinations, allowing organizations to mix and match security stack components.
  • Detection capabilities analyze data in motion rather than post-indexing, with automated schema conversion (OCSF, ECS, CIM) to reduce storage costs.
  • AI is embedded into every stage of the security workflow, including detection, triage, investigation, and response, marking a shift toward "AI-Gen Security Operations."

Why It Matters

This funding highlights a significant industry pivot away from monolithic SIEM architectures toward flexible, composable security operations that leverage real-time processing. For practitioners, it underscores the growing importance of streaming analytics and standardized data schemas in reducing latency and storage overhead. The integration of AI as a foundational layer rather than an add-on feature signals a new standard for modern security operations centers (SOCs).

Technical Details

  • Composable Architecture: Separates data ingestion from storage and processing, enabling vendors to integrate best-of-breed tools for collection, detection, and retention instead of relying on a single vendor's suite.
  • Streaming-First Detection: Performs analysis on data while it is still in motion within the pipeline, significantly reducing the time between event occurrence and threat identification compared to traditional batch-processing SIEMs.
  • Automated Schema Conversion: Automatically tiers and routes data to appropriate storage destinations, converting formats into industry standards like OCSF, ECS, and CIM to ensure compatibility with downstream tools.
  • AI-Embedded Workflow: Integrates artificial intelligence directly into the core layers of security operations, enhancing automation across detection, triage, investigation, and response phases.

Industry Insight

  • Shift from Monolith to Mosaic: Security leaders should evaluate moving away from rigid SIEM structures toward modular platforms that offer greater flexibility and cost-efficiency through selective component integration.
  • Value of Real-Time Analytics: Investing in streaming-first technologies can drastically improve mean time to detect (MTTD) and respond (MTTR), making real-time processing a critical differentiator in future security stacks.
  • Standardization Drives Efficiency: Adoption of universal schemas like OCSF and ECS will become increasingly vital for interoperability, reducing the friction associated with integrating diverse security tools and data sources.

TL;DR

  • Abstract Security 完成 2500 万美元融资,总融资额近 5000 万美元,估值较上一轮翻三倍。
  • 推出“可组合安全运营”平台,采用流式优先架构,实现数据源与目的地的解耦。
  • 支持在数据流动过程中进行实时检测,而非仅依赖索引后的存储数据分析。
  • 通过自动将数据转换为 OCSF、ECS 和 CIM 等标准模式,优化下游工具兼容性并降低存储成本。
  • 创始团队来自 ArcSight、Palo Alto Networks 等知名安全厂商,旨在打造嵌入 AI 的全流程安全运营体系。

为什么值得看

本文揭示了网络安全领域从传统单体 SIEM 向模块化、可组合架构转型的关键趋势,展示了“流式处理”在提升检测实时性和降低存储成本方面的技术价值。对于关注安全运营自动化及 AI 原生安全基础设施的从业者而言,Abstract 的实践提供了关于如何重构 SOC 工作流的最新参考案例。

技术解析

  • 可组合架构设计:平台核心在于分离安全数据的来源与目的地,允许组织自由混合搭配收集、检测、保留和 AI 驱动的操作组件,摆脱单一供应商的单体 SIEM 锁定。
  • 流式实时检测:区别于传统事后分析,Abstract 在数据仍在管道中流动时即执行检测逻辑,显著缩短了威胁发现的时间窗口。
  • 智能数据路由与标准化:数据流出管道时,系统根据用途进行分层和路由,并自动转换为 OCSF、ECS、CIM 等通用模式,既提高了下游工具的互操作性,又通过优化存储格式降低了成本。
  • AI 深度集成:CEO 强调 AI 并非附加功能,而是编织在检测、分类、调查和响应的每一个层级中,推动“AI 生成式安全运营”的发展。

行业启示

  • SIEM 架构正在经历范式转移:市场正从封闭、昂贵的单体解决方案转向开放、模块化的可组合架构,企业应评估现有堆栈的灵活性和互操作性。
  • 实时数据处理成为安全运营新标准:随着攻击速度加快,基于流式的实时检测能力将成为区分现代安全平台与传统工具的关键指标。
  • 数据标准化与成本控制并重:通过自动转换数据模式(如 OCSF)来优化存储和兼容性,表明未来的安全平台需在提升效能的同时,显著解决数据爆炸带来的成本痛点。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Funding 融资