day? Investigate threats faster Automatically triage incidents 60x faster with Watson for Cyber Security Interpret unstructured data Draw from millions of security documents Be more accurate Eliminate 98% of false positives The future of security is Cognitive
response time Remediation Investigation and Impact Assessment Incident Triage Manual threat analysis Remediation Investigation and Impact Assessment Incident Triage IBM Watson for Cyber Security assisted threat analysis Quick and accurate analysis of security threats, saving precious time and resources Days to Weeks Minutes to Hours
sources IBM Watson for cyber security Corpus of Knowledge Threat databases Research reports Security textbooks Vulnerability disclosures Popular websites Blogs and social activity Other Security events User activity Configuration information Vulnerability results System and app logs Security policies Other TEST LEARN EXPERIENCE INGEST Human Generated Security Knowledge Sourced by available IBM Security and IBM Research Enterprise Security Analytics Correlated enterprise data
and interpret the language of security Rich dictionaries enable Watson to link all entity representations Machine learning enables Watson for Cyber Security to teach itself over time Watson Creates Knowledge Graph Watson Applies Annotators to Text Annotator Logic TEST INGEST EXPERIENCE LEARN Hash IoC Artifact Infection Methods Threat Name
Extract Evidence Search Corpus Question • Quantity • Proximity • Relationship • Domain truths / business rules What vulnerabilities are relevant to this type of infection? • Research reports • Security websites • Publications • Threat intelligence • Internal scans • Asset information INGEST EXPERIENCE LEARN TEST
Research results Knowledge graph 4. Performs threat research and develops expertise 3. Observables 2. Gains local context and forms threat research strategy Offense context Device activities Equivalency relationships 6. Applies the intelligence gathered to investigate and qualify the incident QRadar SIEM Security Analytics Data Correlation
set of discrete elements that are collected from an offense and related events that are used by QRadar Watson Advisor for local analysis and external research. Only a subset are sent to Watson for Cyber Security as observations of a potential threat Observable Type Description Sent to W4CS Source IP External Source IPs that appear in an offense – enforced by respecting the Network Hierarchy defined in QRadar Yes Destination IP External Destination IPs that appear in an offense – enforced by respecting the Network Hierarchy defined in QRadar Yes File Hash Hash value of a file that is deemed suspicious Yes URL External URLs that appear in an offense Yes Domain External Domains that appear in an offense Yes Destination Port Destination Ports belonging to Destination IPs No User Agent The user agent identified by a browser or HTTP application No AV Signature Malware signatures identified by antivirus solutions No Email Address Email addresses associated with suspicious emails No Observable Type Description Sent to W4CS Source Port Source Ports belonging to Source IPs No Destination ASN Autonomous System Number of a destination IP address (from a DNS) No Source ASN Autonomous System Number of a source IP address (from a DNS) No Destination Country Name of the destination country of outbound communications No Source Country Name of source country of inbound communications No Low Level Category Low level QRadar offense category No High Level Category High level QRadar offense category No Direction Direction of communication No User name Aliases that may attempt to access critical internal infrastructure No File Name Names of suspicious files No
• QRadar fired an offense on a user attempting to connect to a botnet IP ̶ Analyst found 5 correlated indicators manually while we ran Watson • Watson showed the extent of the threat with 50+ useful indicators ̶ Email hashes ̶ File hashes ̶ IP addresses ̶ Domains
• Client attempted Malware download ̶ Malware was blocked ̶ How much time do you spend on a blocked threat? • Watson enriched ̶ Malware was part of a larger campaign ̶ Analysts used additional Indicators to search for compromise
All rights reserved. The information contained in these materials is provided for informational purposes only, and is provided AS IS without warranty of any kind, express or implied. Any statement of direction represents IBM's current intent, is subject to change or withdrawal, and represent only goals and objectives. IBM, the IBM logo, and other IBM products and services are trademarks of the International Business Machines Corporation, in the United States, other countries or both. Other company, product, or service names may be trademarks or service marks of others. Statement of Good Security Practices: IT system security involves protecting systems and information through prevention, detection and response to improper access from within and outside your enterprise. Improper access can result in information being altered, destroyed, misappropriated or misused or can result in damage to or misuse of your systems, including for use in attacks on others. No IT system or product should be considered completely secure and no single product, service or security measure can be completely effective in preventing improper use or access. IBM systems, products and services are designed to be part of a lawful, comprehensive security approach, which will necessarily involve additional operational procedures, and may require other systems, products or services to be most effective. IBM does not warrant that any systems, products or services are immune from, or will make your enterprise immune from, the malicious or illegal conduct of any party. FOLLOW US ON: THANK YOU