IBM Launches Generative AI Cybersecurity Assistant

Sep 02, 2024 Leave a message

On August 13, IBM recently announced the introduction of generative AI capabilities in its managed threat detection and response service for analysts at IBM Consulting to collaborate with customers to advance and simplify security operations.

 

The new IBM Consulting Cybersecurity Assistant is built on WATSONX, IBM's data and AI platform, to accelerate and improve the identification, investigation and response to critical security threats.

 

In addition to being included in IBM Consulting's threat detection and response services, Cybersecurity Assistant will become part of IBM Consulting Advantage, an AI services platform that includes AI assets tailored for IBM consultants.

 

"As cyber incidents evolve from immediate crises to multidimensional events that last for months, security teams are facing persistent challenges: more attacks and not enough time or people to defend against them," says Mark Hughes, global managing partner of cybersecurity services at IBM Consulting. By augmenting threat detection and response services with generative AI, we can reduce the manual investigative and operational tasks of security analysts, enabling them to be more proactive and accurate in responding to critical threats, helping customers improve their overall security posture. 

 

Specifically, generative AI capabilities are claimed to have helped customers reduce alert investigation time by 48%. IT Home summarizes the features offered by the new Cybersecurity Assistant as follows:

 

1. Accelerate threat investigation and remediation through historical correlation analysis

 

Cybersecurity Assistant accelerates complex threat investigations by performing historical correlation analysis of similar threats. Built into IBM's TDR service, this new capability provides a threat management approach by cross-correlating alerts and deepening insights from SIEM, networking, EDR, vulnerabilities and telemetry.

 

By analyzing the history of customer-specific threat activity and its patterns, security analysts will have more precise analytical capabilities, such as a deeper understanding of critical threats by accessing a timeline view of the attack sequence, which can provide more context for investigations. Based on historical patterns and preset confidence levels of analysis, Cybersecurity Assistant can automatically recommend relevant actions, speeding up customer response times and reducing attacker dwell time. In addition, it continuously learns from surveys and continuously improves speed and accuracy.

 

2. Use the conversational engine to simplify operational tasks

 

Cybersecurity Assistant includes a generative AI conversational engine that provides real-time insights and support to clients and IBM security analysts on operational tasks. In addition to responding to requests, such as creating or aggregating tickets, the feature automatically triggers actions such as running queries, extracting logs, interpreting commands, or enriching threat intelligence. By interpreting complex security events and commands, IBM's TDR services help clients reduce noise and improve overall SOC efficiency.

 

Developed in partnership with IBM Research, IBM Consulting Cybersecurity Assistant makes extensive use of IBM's generative AI capabilities. Its key features are built on the Granite foundation model, optimized for production with IBM watsonx.ai, and the IBM watsonx Assistant in the conversational chat interface.

 

news-400-300