Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    IBM Brings Enhanced Data Models to QRadar Advisor With Watson 2.0

    Written by

    Sean Michael Kerner
    Published November 28, 2018
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      IBM announced on Nov. 28 that it is expanding the capabilities of its QRadar Advisor with Watson platform to help organizations more rapidly understand attacker behaviors.

      The IBM QRadar Advisor with Watson 2.0 release is an artificial intelligence (AI) platform that enables organizations to collect and make sense of security data. With the 2.0 update, IBM is now supporting the MITRE ATT&CK framework, which is an open-source playbook that details cyber-criminal behaviors. The platform is also set to benefit from several new learning models that help to provide additional context to security data.

      “QRadar does a great job taking event and flow data and running correlation to generate a meaningful alert and offense for the SOC [Security Operations Center] to investigate,” Chris Meenan, director of security intelligence offering management and strategy at IBM, told eWEEK. “The learning models for threat disposition and cross investigation analytics are brand new capabilities being added to QRadar Advisor with this release.”

      IBM announced the QRadar Advisor with Watson platform in February 2017. Meenan said the original release focused on bringing external knowledge on threats and security research to analysts to help speed their investigations with less manual, time-intensive research.

      Since the initial 2017 release, IBM has added new features that improved the efficiency of the SOC and expanded how Watson for Cyber Security has augmented threat investigations. In 2018, IBM added integrations through its Security Operations and Response portfolio by allowing investigations to start from User Behavior Analytics and Resilient.

      “Additionally, Watson for Cyber Security’s knowledge base continues to grow and gets smarter with time, increasing its understanding of the security landscape as it is continually gathering and digesting data that is being published in the security community,” he said.

      QRadar Advisor With Watson 2.0

      Meenan said QRadar Advisor 2.0 uses its new data algorithms to get an accurate perspective on relationships between investigations. 

      Among the new data models is a threat disposition one that is able to make a determination based on the outcome of previous similar events. Additionally, the new Cross-Investigation Analytics enables security analysts to find similarities across different investigations using cognitive reasoning.

      “QRadar Advisor 2.0 uses these new data algorithms to get a pinpoint perspective on relationships between investigations—not only those that are discovered using QRadar alerts, but also our ‘Search Watson’ capability and through those investigations that begin from investigation entry points such as User Behavior Analytics and even Resilient,” Meenan said. “Additionally, this analysis is looking at historical security analysts’ behavior to help give the SOC a jump-start into the types of actions that were taken previously on similar investigations so they know the potential outcome at a glance.”

      MITRE ATT&CK Framework

      The open-source MITRE ATT&CK Framework is now also being supported by IBM. Meenan said that security analysts often tell IBM that once an incident occurs, one of the first things they want to know is what stages of the attack have occurred, so they can respond more quickly and understand what might happen next. 

      “By aligning Advisor with Watson’s automated incident investigation output to the MITRE ATT&CK framework, users can now visualize what stages of the attack have occurred, how it is progressing [and] uncover what tactics could possibly still occur,” he explained. “Using the MITRE ATT&CK framework also allows customers to benefit from the collective knowledge of the security community that is contributing to the framework to understand how an attack may evolve.”

      What’s Next

      Looking forward, Meenan said IBM will continue to focus on using Watson as a “force multiplier” for security analysts, helping alleviate the skills shortage by allowing analysts to do their jobs more effectively and increasing their ability to respond quickly and reducing dwell times for attacks. 

      “We are actively working on new AI models that will help the SOC determine which investigations are ones that need the most attention and ones that are false positive and don’t need focus immediately,” he said. “Additionally, we are working to simplify the investigation workflow from start to finish with a deeper, more integrated experience into QRadar.”

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.