• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • IBM To Add Generative AI To QRadar

    November 13, 2023 Alex Woodie

    If you feel that cyber crooks are getting the upper hand, you’re not alone. Studies show cybercrime volume booming while security professionals struggle to connect the dots and keep up. One possible route forward was presented last week by IBM, which announced that it will add generative AI capabilities to its QRadar SIEM tool.

    Security information and event management (SIEM) tools are the sharp end of the stick for security-loving organizations, as they are where the hard work of assembling security data from all of the various components in the modern IT stack (including IBM i) and then trying to make sense of the apparent chaos occurs. QRadar, which IBM obtained with its acquisition of Q1 Labs back in 2011, is one of the top products in this category.

    Machine learning has long been de rigueur in SIEM work, as it can spot anomalies buried in data that would otherwise fly right by human eyes. Among the ML capabilities QRadar offers is User Behavior Analytics (UBA), which enables the product to combine system and network events with data about user behavior to identify complex interactions that could signal a potential compromise.

    But even with ML doing the hard work of scanning through billions of event logs in search of correlations, security professionals are falling behind. As we told you last month, a study by Vectra AI found that security analysts must manually comb thorough about 4,500 alerts per day, which is better than billions but still too much.

    Nearly all of the analysts surveyed (97 percent) worry about missing something important, Vectra AI found. Security analysts suffer from “alert overload” because security tool vendors are afraid of not flagging something important, the company says. “The current approach to threat detection is broken,” said Kevin Kennedy, Vectra AI’s senior vice president of products.

    IBM came to a similar conclusion in its Global Security Operations Center Study Results report, which it published in March. The study found that, on average, security operations center (SOC) workers spend one-third of their typical workday investigating incidents that are not a real threat. What’s more, four out of five SOC workers say the need to manually investigate threats slows down their response time.

    Clearly, there’s a need for better tools that can automate more of the work and take the burden off the SOC’s shoulders. That’s what IBM says it’s doing by adding generative AI capabilities to its QRadar suite.

    The GenAI capabilities that IBM announced last week are based on its watsonx product line and will be used to help automate several tasks, including reporting, threat hunting, data interpretation, and data curation. The GenAI capabilities in QRadar will be available in the first quarter of 2024, IBM says.

    IBM says handing some of the more mundane tasks over to GenAI will free security analysts to focus on more important work. For example, instead of requiring the security analyst to build reports, the watsonx GenAI capabilities will do it for them. Similarly, QRadar will leverage watsonx’s natural language processing (NLP) capability to automatically generate searches designed to identify the bad guys. The flip side of that is using NLP to generate plain English descriptions of analyses of log data. Finally, the NLP will be used to “interpret and summarize” threat intelligence, which could give SOC workers another leg up on cyber crooks.

    “Instead of forcing analysts to work around the complexity of security technologies, we’re designing technology to remove the complexity – weeding out the noise, simplifying the user experience, and empowering analysts to tackle urgent threats with greater speed and confidence,” Kevin Skapinetz, IBM’s vice president of strategy and product management, says in a press release.

    IBM says it’s planning a push to apply GenAI across its broad security software and services portfolio. It says it could eventually use GenAI for tasks such as helping security teams find similar incidents, updating affected systems, and even patching vulnerable code.

    IBM says it overhauled QRadar with the latest release, and that it’s now “cloud native.” It redesigned the product to run on its own Red Hat OpenShift distribution of Kubernetes. The cloud-based version of the new QRadar suite will be available this quarter, while the on-prem and multi-cloud version will ship next year, IBM says.

    Among the capabilities IBM is touting with the new QRadar suite are: support for industry-standard SIGMA security detection rules; federated search and threat hunting capabilities that span cloud and on-prem data sources and integrate with the MITRE ATT&CK knowledgebase; Attack Surface Management (ASM) capabilities; support for industry-standard Security, Orchestration, Automation, and Response (SOAR) playbooks; and a deep partner network composed of 700 pre-built integrations.

    Among those integrations, of course, is the IBM i, which is delivered via an IBM-supplied Device Support Module (DSM) called the QRadar DSM for IBM i. IBM i users have an array of options for pushing security event data from the IBM i into QRadar, including manually scraping the security journal, importing security events automatically using Syslog, or using a third-party tool to convert IBM i security events into Common Event Format (CEF) or Log Event Extended Format (LEEF), the customized event format used exclusively by QRadar.

    The IBM i server is no longer a computing island protected by a moat of obscurity. As recent cyberattacks have shown, nobody is safe anymore. Better security training and better security tools won’t stop the cyber crooks, but they’re the only things slowing them down.

    RELATED STORIES

    Four Cybercrime Trends for Security Pros to Watch Now

    Why You Should Be Concerned About the MGM ‘Vishing’ Attack

    One IBM i Shop’s Close Call With Ransomware

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags: Tags: cyberattack, GenAI, IBM i, QRadar, SIEM, watsonx

    Sponsored by
    WorksRight Software

    Do you need area code information?
    Do you need ZIP Code information?
    Do you need ZIP+4 information?
    Do you need city name information?
    Do you need county information?
    Do you need a nearest dealer locator system?

    We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

    The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

    PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

    Just call us and we’ll arrange for 30 days FREE use of either ZIP/CITY or PER/ZIP4.

    WorksRight Software, Inc.
    Phone: 601-856-8337
    Fax: 601-856-9432
    Email: software@worksright.com
    Website: www.worksright.com

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    IDC Boosts IT Spending Forecasts For 2023 And Beyond IBM Finally Comments On Db2 Web Query For i Withdrawal

    Leave a Reply Cancel reply

TFH Volume: 33 Issue: 71

This Issue Sponsored By

  • Fresche Solutions
  • LANSA
  • WorksRight Software
  • ARCAD Software
  • Raz-Lee Security

Table of Contents

  • New GM Wants To Push IBM Power With Hybrid Cloud And AI
  • IBM Finally Comments On Db2 Web Query For i Withdrawal
  • IBM To Add Generative AI To QRadar
  • IDC Boosts IT Spending Forecasts For 2023 And Beyond
  • IBM i PTF Guide, Volume 25, Number 46

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Positive News From The Kyndryl Mainframe Modernization Report
  • NAViGATE, inPower 2025 On Tap for September 2025
  • Guru: WCA4i And Granite – Because You’ve Got Bigger Things To Build
  • As I See It: Digital Coup
  • IBM i PTF Guide, Volume 27, Number 37
  • AI Is Coming for ERP. How Will IBM i Respond?
  • The Power And Storage Price Wiggling Continues – Again
  • LaserVault Adds Multi-Path Support To ViTL
  • As I See It: Spacing Out
  • IBM i PTF Guide, Volume 27, Numbers 34, 35, And 36

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle