Media Fusion Inc. (Headquarters: Kita-ku, Osaka City) will officially release the 'MF Self-Defense Type Server Integrated Monitoring System' on August 31, 2026.
This system is an operational platform that automatically executes initial responses such as blocking, service suspension, and notifications based on predefined rules when a server anomaly is detected, without waiting for the operator to log in and check the situation. Based on the de facto standard open-source integrated monitoring application 'Zabbix', it combines Azure OpenAI's log analysis and Microsoft SharePoint's operational knowledge sharing to enable monitoring, vulnerability management, incident initial response, AI analysis, and knowledge sharing on a single platform.
▶ For inquiries, please contact us here
● Background (Not just detection - How to change the initial response for public server operations)
In recent years, the operation of Internet public servers has faced challenges such as responding to cyber attacks and concentrated access, as well as increased operational load due to the increase in servers and cloud environments. In particular, many organizations face the following challenges:
Rapid response to cyber attacks and concentrated access is required Server increases lead to variations in monitoring settings and operational quality The process of 'first logging in to check the situation' when an anomaly is detected becomes a bottleneck Cause investigation and information sharing depend on the operator's experience, leading to variations in response quality Response history and know-how remain with individuals and are not easily accumulated as organizational assets
The MF Self-Defense Type Server Integrated Monitoring System is an integrated operational platform developed to solve these challenges. Based on the de facto standard open-source integrated monitoring application 'Zabbix', it integrates the following to provide an environment where operators can grasp the situation before accessing the server. This achieves the speeding up of initial response and the standardization of operational quality.
Anomaly detection Automatic defense AI-based log analysis Knowledge sharing
※ 'Zabbix' is an open-source integrated monitoring software with over 300,000 implementations in more than 190 countries and regions (Source: ▶ Zabbix official website)
● Integrating server operation and maintenance workflows into a single platform
In conventional server operations, monitoring, troubleshooting, vulnerability management, log analysis, and information sharing were handled by separate tools or personnel, leading to time-consuming situation awareness and handover. This system integrates the functions necessary for server operation and maintenance into a single platform.
Integrated Monitoring (Zabbix) Monitor the status of servers, networks, and middleware centrally and manage alerts.
Vulnerability Management Automatically detect vulnerabilities affected by JVN published information and server configuration information.
Automatic Defense and Initial Response When unauthorized access or abnormal behavior is detected, automatically execute initial responses such as IP blocking or service suspension based on predefined rules.
Automatic Log Collection and Sharing Automatically collect related logs when a failure occurs and save and share them on SharePoint.
AI Log Analysis Analyze the cause candidates, scope of impact, and recommended responses using Azure OpenAI.
Knowledge Accumulation and Reuse Accumulate trouble response history and analysis results as knowledge and support rapid problem solving using past cases.
Since anomaly detection, automatic initial defense, AI-based cause investigation, and knowledge accumulation on SharePoint are all connected on the same platform, operators can consistently perform situation awareness, response, recording, and sharing without crossing multiple tools.
● Features and Benefits (Speed of Introduction, Speed of Initial Response, Standardization of Operational Quality)
This system is based on Zabbix's standard monitoring and notification, combined with our proprietary extensions, to achieve monitoring, analysis, defense, and information sharing on a single operational platform.
Rapid Introduction and Configuration of Zabbix Deploy Zabbix Agent on each server and perform centralized monitoring with Zabbix Server using standardized monitoring templates and Docker provisioning to start up in a short time.
Standardization of Monitoring Design (Templates): Standardize monitoring items, thresholds, notification destinations, and log transmission. After applying the common template, only adjust the differences for each application, reducing individual configuration work.
Short-Time Introduction (Docker): Provide Zabbix and our extended functions with Docker. Shorten the setup time from environment preparation to operation start and make version upgrades during operation easier.
Zabbix Introduction Flow Differences between Conventional Procedures and This Product
Integrated Operational Functions Based on Zabbix
This system integrates security measures, automatic defense, AI log analysis, knowledge sharing, and other functions based on the open-source integrated monitoring application 'Zabbix'. The following are our proprietary functions realized in collaboration with Zabbix.
Automatic Access Overload Countermeasures: Based on CPU or communication volume triggers, automatically block IP addresses with excessive access for a certain period and send necessary logs. Temporarily suppress concentrated access by poorly behaving bots.
Abnormal Behavior Detection and Emergency Measures: When excessive file system access is detected as assumed in ransomware attacks, issue an alert. If it continues for a certain period, automatically execute emergency measures such as service suspension.
Alert Management and Time-Series Confirmation: Manage generated alerts centrally and display them in a list with importance and response status. You can confirm the history of trouble responses in chronological order, supporting the prevention of response omissions and the standardization of operational quality.
Vulnerability and Configuration Central Management: Centrally manage OS/middleware versions and automatically obtain vulnerability information published in JVN via API. Extract the scope of impact at an early stage and issue alerts according to the degree of seriousness.
Important Software and Security Measures Software Monitoring: Continuously monitor the operation status of important software such as web servers, databases, and Java execution environments, as well as virus countermeasures software (ESET, etc.). When service suspension or abnormalities are detected, issue an alert and support the early detection of system suspension and security risks.
Automatic Log Collection and Sharing: When a failure or security incident is detected, automatically collect CPU, memory, disk usage, service status, and related event logs. The collected logs are automatically sent to SharePoint or our support system, allowing operators to grasp the situation before logging into the server, supporting rapid cause investigation and initial response.
AI Log Analysis (Azure OpenAI/RAG): Analyze the collected logs with AI and, using RAG, refer to past trouble response history and operational knowledge to present candidates for causes, scope of impact, and next action plans. AI analysis uses Azure OpenAI operating in the Azure tenant of the monitoring server introducer, and personal information included in the logs is handled anonymously.
Operational Knowledge Sharing (SharePoint Integration): Accumulate and share analysis results and response history on Microsoft SharePoint. You can reuse trouble response know-how as organizational assets, eliminating personalization and standardizing operational quality.
FACT BOX
- Source: PR TIMES
- Category: New Product