{"id":89077,"date":"2023-04-27T06:38:03","date_gmt":"2023-04-27T06:38:03","guid":{"rendered":"https:\/\/www.techrepublic.com\/?p=4074636"},"modified":"2023-04-27T06:38:03","modified_gmt":"2023-04-27T06:38:03","slug":"ibm-launches-qradar-security-suite-for-accelerated-threat-detection-and-response","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=89077","title":{"rendered":"IBM launches QRadar Security Suite for accelerated threat detection and response"},"content":{"rendered":"<figure id=\"attachment_4004070\" aria-describedby=\"caption-attachment-4004070\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-4004070\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2023\/04\/ibm-launches-qradar-security-suite-for-accelerated-threat-detection-and-response.jpg\" alt=\"Exterior view of IBM sign at IBM Canada Head Office on May 16, 2018 in Markham, Ontario, Canada.\" width=\"1000\" height=\"667\"><figcaption id=\"caption-attachment-4004070\" class=\"wp-caption-text\">Image: JHVEPhoto\/Adobe Stock<\/figcaption><\/figure>\n<p>At the RSA Conference, IBM launched a platform-centric expansion to its <a href=\"https:\/\/www.techrepublic.com\/article\/ibm-qradar-vs-logrhythm\/\">QRadar security product,<\/a> designed as a one-stop shop to accelerate response and offer a unified framework for security operations centers. Called QRadar Suite, the cloud native service expands capabilities across threat detection, investigation and response technologies, according to the company.<\/p>\n<p>The service has an integrated dashboard user experience and artificial intelligence automation for parsing threats and responses. It\u2019s designed to address the ongoing bad arithmetic around security operations centers: a threat landscape that is only expanding; more sophisticated attackers; plus an endemic shortage of human sentries to guard enterprise perimeters and kill chains.<\/p>\n<p>\u201cToday\u2019s Security Operation Center teams are protecting a fast-expanding digital footprint that extends across hybrid cloud environments \u2013 creating complexity and making it hard to keep pace with accelerating attack speeds,\u201d according to IBM, which also said the products are specifically meant to help buttress security operations center teams facing labor-intensive alert investigations and response processes, manual analysis and the proliferation of tools, data, points of engagement, APIs and other potential vulnerabilities.<\/p>\n<h2>XDR, SIEM and SOAR<\/h2>\n<p>Keeping pace with one of the pied pipers of RSA 2023 \u2014 unified platforms over multi-vendor security \u2014 IBM said QRadar Suite includes extended detection and response, or XDR, as well as security information and event management, and security orchestration, automation and response, or SOAR. It also includes a new cloud-native log management capability \u2014 all built around a common user interface, shared insights and connected workflows.<\/p>\n<p>Emily Mossburg, Deloitte\u2019s global cyber leader, said SOAR is about automating the workflow, while <a href=\"https:\/\/www.techrepublic.com\/article\/siem-tools\/\">SIEM <\/a>is the collection of security logs and events, and rules and policies to define analysis on top of that. \u201cI would consider SOAR to be security worldflow management. The vendors are sort of pushing it to help simplify the whole security operation and drive down the level of effort associated with working through incident and researching,\u201d she said.<\/p>\n<p>She said it comes down to dealing with a perennial shortage of security analysts.\u201cThere\u2019s an element of balancing out the talent gap and I think the reality is that there\u2019s a cost element to this. Organizations can\u2019t spend more on protecting themselves than the revenue they bring in. If you had human eyes on glass on everything all the time you couldn\u2019t afford security.\u201d<\/p>\n<p>IBM said its QRadar SIEM has a new unified analyst interface that provides shared insights and workflows with broader security operations toolsets. IBM said it plans to make QRadar SIEM available as a service on Amazon Web Services by the end of Q2 2023.<\/p>\n<h2>AI, the sine qua non of security?<\/h2>\n<p>During RSA, many companies talked about the virtues of AI in security, particularly with the increase in alerts into SOCs and the paucity of human agents, particularly in mid-sized businesses that are perhaps more vulnerable to phishing attacks.<\/p>\n<p>IBM Managed Security Services said it is using AI to automate more than 70% of alert closures and reduce its alert triage timelines by 55% on average within the first year of implementation, according to the company.<\/p>\n<p>IBM said QRadar uses AI to:<\/p>\n<ul>\n<li>Triage: The company said that to prioritize and respond to alerts, QRadar includes AI trained on prior analyst response patterns, along with external threat intelligence from IBM X-Force and broader contextual insights from across detection toolsets.<\/li>\n<li>Investigation: AI models identify high-priority incidents and automatically begin investigating and generate a timeline and attack graph of the incident based on the <a href=\"https:\/\/attack.mitre.org\/\">MITRE ATT&amp;CK<\/a> framework, and recommend actions to speed response.<\/li>\n<li>Hunting: QRadar uses open-source threat hunting language and federated search capabilities to ID attacks and indicators of compromise across environments, without moving data from its original source.<\/li>\n<\/ul>\n<p>The design elements of the system include a UX across products meant to make it easier to increase analyst speed and efficiency across the kill chain and AI capabilities. It is cloud-based and delivered on AWS and includes cloud-native log management capability.<\/p>\n<p>\u201cIn the face of a growing attack surface and shrinking attack timelines, speed and efficiency are fundamental to the success of resource-constrained security teams,\u201d said Mary O\u2019Brien, general manager, IBM Security, in a statement. \u201cIBM has engineered the new QRadar Suite around a singular, modernized user experience, embedded with sophisticated AI and automation to maximize security analysts\u2019 productivity and accelerate their response across each step of the attack chain,\u201d she added.<\/p>\n<p>Matt Olney, director, threat intelligence and interdiction at Cisco\u2019s Talos threat intelligence unit, said it\u2019s indeed an exciting time in AI and a system that supports human analysts is ideal. But he worries that, while AI will be faster, it may not be better, and suggests AI in the service of security poses a paradoxical conundrum. \u201cWe are training AI on internet, so we are creating things that can solve all these solved problems, but if we haven\u2019t bothered to solve the problems we won\u2019t be able to use the AI to do it,\u201d he said.<\/p>\n<p>Cisco showcased an early conceptual version of its AMES AI model for security, which will move toward a natural language interface. Olney voiced concerns that security AI systems could eventually eliminate lower level or Tier 1 security jobs, potentially hobbling enterprises\u2019 ability to fill higher level SOC analyst positions where problems get solved creatively, generating data that would improve AI. \u201cSo when we start training AI, what are we going to train it on that\u2019s new, if we\u2019ve ended up eliminating these people?\u201d<\/p>\n<h2>Platforms versus single vendors: a false dichotomy?<\/h2>\n<p>Mossburg said the platforming trend follows an inflection point in the industry on full display at RSA. \u201cFor a long time, we have focused on best-of-breed, the best mousetrap and it has gotten complex and hard to manage. Does it make sense to have 100 of the best mouse traps if you don\u2019t have time to set them? We need to move to some level of simplicity so we can actually manage this thing that we have. We will see more of this for the next five years. We will see significant consolidation,\u201d she predicted.<\/p>\n<p>Olney said there are advantages to having a unified environment. \u201cThere are a lot of things to think about when making decisions about what to invest in, so really you want to look for what gives you the most visibility and what integrates well with the current level of sophistication your security staff has. Ultimately the tools are super important and useful and necessary, but ultimately it\u2019s the people that are going to define the success of your security program,\u201d he said.<\/p>\n<p>He enumerated the advantages of having a unified environment. \u201cYou have a better relationship with vendors, a lot of sway when you are negotiating, and it\u2019s easier to train people. Also, your support contracts are usually unified and that helps with financing,\u201d Olney said.<\/p>\n<p>A drawback: how likely is it for one company to excel at all toolsets? \u201cIf I\u2019m advising a customer, I\u2019ll say you have to have a really solid understanding of what your security needs are before you go looking for a security product,\u201d said Olney, adding that enterprises should find a solution that gives them maximum visibility and the most secure controls they can apply to secure their network when they are actively engaging with their adversary.<\/p>\n<p>The bottom line is security is hard, he said.<\/p>\n<p>\u201cYou can\u2019t just buy something from a vendor, plug it in and say I\u2019m secure now. That\u2019s not how this game works. It has to be complementary between right people with right skills sets combined with right tools and capabilities and put those together,\u201d he added.<\/p>\n<p> <!-- default newsletter at the end --> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Image: JHVEPhoto\/Adobe Stock At the RSA Conference, IBM launched a platform-centric expansion to its QRadar security product, designed as a one-stop shop to accelerate response and offer a unified framework for security operations centers. Called QRadar Suite, the cloud native service expands capabilities across threat detection, investigation and response technologies, according to the company. The [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":89078,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[40,788,783,79,296,287],"tags":[],"class_list":["post-89077","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud","category-cloud-security","category-cloudsync","category-ibm","category-qradar","category-security"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/89077","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=89077"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/89077\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/89078"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=89077"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=89077"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=89077"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}