Threat Management
We’re building the next wave of tools and methodologies to help security and operations teams detect, understand, and respond to advanced cybersecurity threats and attacks on their infrastructure and in the cloud, with automated threat detection, investigation, and deflection capabilities.
Our work
IBM’s new AI-infused security technologies help defenders speed response to cyber attacks
ReleaseMarc Stoecklin, Ian Molloy, and Yaron Wolfsthal8 minute readThe thrill of cyber threat hunting with Kestrel Threat Hunting Language
ReleaseXiaokui Shu, Paul Coccoli, Jiyong Jang, and Ian Molloy7 minute readSysFlow: Scalable system telemetry for improved security analytics
ReleaseFrederico Araujo and Teryl Taylor5 minute read
Projects
A cloud-native system telemetry framework that enables the creation of security analytics on a scalable, pluggable open-source platform.
Tech Preview: IBM Security Threat Investigator
Our team's work has been developed into a beta capability for the IBM Cloud Pak for Security. Threat Investigator finds cases that warrant an investigation and automatically starts investigating. It fetches artifacts that are attached to the cases, completes several rounds of data mining and then generates a timeline and MITRE ATT&CK chain graph of the incident.
Publications
WannaLaugh: A Configurable Ransomware Simulator, Learning to Mimic Malicious Storage Traces
- 2024
- SYSTOR 2024
True Attacks, Attack Attempts, or Benign Triggers? An Empirical Measurement of Network Alerts in a Security Operations Center
- Limin Yang
- Zhi Chen
- et al.
- 2024
- USENIX Security 2024
Automated Synthesis of Effect Graph Policies for Microservice-Aware Stateful System Call Specialization
- Will Blair
- Fred Araujo
- et al.
- 2024
- S&P 2024
Curiosity-driven Red-teaming for Large Language Models
- Zhang-wei Hong
- Idan Shenfeld
- et al.
- 2024
- ICLR 2024
Pruning Federated Learning Models for Anomaly Detection in Resource-Constrained Environments
- Simone Magnani
- Stefano Braghin
- et al.
- 2023
- Big Data 2023
Are GNNs the Right Tool to Mine the Blockchain? The Case of the Bitcoin Generator Scam
- Zhikun Yuen
- Paula Branco
- et al.
- 2023
- DSAA 2023
IBM Solution: IBM QRadar Network Insights
Our innovations in real-time network traffic analysis are regularly incorporated into new capabilities for IBM QRadar Network Insights.