Threat Management
We’re building the next wave of tools and methodologies to help security and operations teams detect, understand, and respond to advanced cybersecurity threats and attacks on their infrastructure and in the cloud, with automated threat detection, investigation, and deflection capabilities.
Our work
IBM’s new AI-infused security technologies help defenders speed response to cyber attacks
ReleaseMarc Stoecklin, Ian Molloy, and Yaron Wolfsthal8 minute readThe thrill of cyber threat hunting with Kestrel Threat Hunting Language
ReleaseXiaokui Shu, Paul Coccoli, Jiyong Jang, and Ian Molloy7 minute readSysFlow: Scalable system telemetry for improved security analytics
ReleaseFrederico Araujo and Teryl Taylor5 minute read
Projects
SysFlow
Tech Preview: IBM Security Threat Investigator
Our team's work has been developed into a beta capability for the IBM Cloud Pak for Security. Threat Investigator finds cases that warrant an investigation and automatically starts investigating. It fetches artifacts that are attached to the cases, completes several rounds of data mining and then generates a timeline and MITRE ATT&CK chain graph of the incident.
Publications
- 2024
- SYSTOR 2024
- Limin Yang
- Zhi Chen
- et al.
- 2024
- USENIX Security 2024
- Will Blair
- Fred Araujo
- et al.
- 2024
- S&P 2024
- Zhang-wei Hong
- Idan Shenfeld
- et al.
- 2024
- ICLR 2024
- Simone Magnani
- Stefano Braghin
- et al.
- 2023
- Big Data 2023
- Zhikun Yuen
- Paula Branco
- et al.
- 2023
- DSAA 2023
IBM Solution: IBM QRadar Network Insights
Our innovations in real-time network traffic analysis are regularly incorporated into new capabilities for IBM QRadar Network Insights.