CAMBRIDGE, Mass., Nov. 28, 2018 /PRNewswire/ -- IBM (NYSE:
IBM) Security today announced new capabilities for the
company's AI-based security platform, QRadar Advisor with Watson, which expand
the platform's knowledge of cybercriminal behavior and allow it to learn from security response activities within an
organization. IBM Security also is embracing the open-source MITRE ATT&CK framework, a playbook to help analysts understand
how an attack has evolved and what might happen next based on real-world observations from the security community.
With some estimates predicting as many as 3.5 million cybersecurity vacancies by 20211, security teams today are
struggling with the capacity and skills needed to effectively analyze and respond to a massive amount of cybersecurity incidents
and alerts. The use of AI and machine learning technologies like QRadar Advisor with Watson, which learns from the latest
research available in the external security community as well as activities happening within an organization, can equip analysts
with the knowledge and automation needed to help them escalate critical threats faster and more effectively.
As part of the latest release, IBM has developed new analytic and learning models which enable QRadar Advisor to identify long
and slow attack patterns and adapt to the local client environment. This learning loop gets smarter with time based on additional
interactions and engagement with analysts, allowing the tool to provide stronger recommendations on how to respond, as well
confidence ratings based on how incidents align with historical data.
"Standards like MITRE ATT&CK, which take advantage of the collective knowledge of the security community, are crucial to
advancing the industry and helping security teams stay ahead of increasingly sophisticated threats," said Chris Meenan, Director of Security Intelligence Offering Management and Strategy, IBM Security. "Combining the
ATT&CK framework of known adversary tactics with Watson for Cyber Security's ability to stay current on the latest security
research, QRadar Advisor can help arm analysts of all levels with the knowledge needed to better respond to the threats they're
facing."
Connecting the Dots for More Decisive Threat Escalation
MITRE ATT&CK is an open-source playbook of cybercriminal behavior developed with real-world examples and insights from
cybersecurity experts across the industry, which defines step-by-step patterns and actions that a threat can take as it evolves.
Using the ATT&CK framework, QRadar Advisor with Watson is moving beyond identifying the threat and providing external
research on it, to now also shedding light on how external attacks and internal threats have progressed within the client
infrastructure – for instance, whether a malware has just landed within an organization, or if it has collected data such as
passwords or credit card information. This added context also includes a confidence level as well as the relevant evidence for
each stage of the attack. By helping analysts visualize how an attack has evolved, this capability allows analysts to understand
immediately where an incident stands in a threat lifecycle and what it might do next, which can significantly improve response
times and effectiveness.
These additional insights from QRadar Advisor can augment the skills of analysts and help them connect the dots to see the
full scope of an attack in a way that a higher-level analyst or threat hunter could do. Advisor can also use ATT&CK to
recommend a more decisive incident escalation process to analysts, helping them understand the immediate next steps to take based
on where the threat falls in its lifecycle. Leveraging the ATT&CK framework allows QRadar Advisor to provide this context in
an industry standard that maps to company's incident response playbooks.
Applying New Learning Models to Threats within an Organization
IBM Security is also deepening the intelligence of QRadar Advisor with Watson by enabling it to learn and
contextualize behavior of threats and security response actions happening inside an organization.
The initial release of QRadar Advisor with Watson enabled Watson to gather, read, and understand structured and unstructured
security data from external sources, and bring the most relevant information to analysts' fingertips to help them understand what
was already known and published on a specific threat. Now, QRadar Advisor is also learning from the actions being taken within
customers' environments – both events happening in real time, as well as what has happened with certain types of events
historically. Two new capabilities IBM is introducing for QRadar Advisor include:
- Threat Disposition Models: QRadar Advisor uses new algorithms to build a model for specific types of threats, based
on the actions and outcome of previous similar events that have happened within an organization. When a new investigation comes
in, this model can be used to help rule out false positives, or help the analyst decide whether the threat should be escalated
as malware, data exfiltration, or other specific types of threats. This capability becomes increasingly intelligent the more
it's used, learning and adapting based on interactions with analysts.
- Cross-Investigation Analytics: Within a company's Security Operation Center (SOC), multiple analysts may be working
on different offenses which are related to each other, or alerts over many months might be part of a long-term adversarial
campaign. This capability allows QRadar Advisor to find commonalities across investigations using cognitive reasoning, and
automatically group together investigations that are related to avoid duplication of efforts, as well as provide fuller context
to aid in the investigation.
Combining these new learning models, which add context to activities within the network, with Watson for Cyber Security's
investigative capabilities and ability to digest current research being published in the security community, analysts can now use
QRadar Advisor to help drive deeper, more consistent investigations and respond faster and more efficiently.
About IBM Security
IBM Security offers one of the most advanced and integrated portfolios of enterprise security products and services.
The portfolio, supported by world-renowned IBM X-Force® research, enables organizations to effectively manage risk and defend
against emerging threats. IBM operates one of the world's broadest security research, development and delivery organizations,
monitors 60 billion security events per day in more than 130 countries, and has been granted more than 8,000 security patents
worldwide. For more information, please check www.ibm.com/security, follow @IBMSecurity on Twitter or visit the IBM
Security Intelligence blog.
Media Contact
Cassy Lalan
IBM Security Media Relations
319-230-2232
cllalan@us.ibm.com
1 Source: Cyber Security
Ventures
View original content to download multimedia:http://www.prnewswire.com/news-releases/ibm-qradar-advisor-with-watson-expands-knowledge-of-cybercriminal-techniques-300756453.html
SOURCE IBM