In a world full of threat actors, from cybercriminals to state-sponsored agencies, it’s clear that risks are increasing. The global cost of cybercrime is expected to hit $2 trillion by 2019, a threefold increase from the 2015 estimate of $500 billion.

As a result, securing data is becoming a more complex endeavor — one that can only be accomplished with the help of augmented intelligence. Over 2.5 quintillion bytes of data is generated every day worldwide, and 80 percent of it is unstructured. Humans alone simply can’t handle all that information.

A Brief History of Threat Intelligence

Organizations began with perimeter defense, which built a strong moat around data. However, the perimeter defense was eventually rendered inadequate as cybercrime techniques became more sophisticated.

Companies began purchasing a variety of security products to counteract the risk. They used analytics from security information and event management (SIEM) systems to collect and assess the event data. But cybercriminals are well organized and well-funded. To stay ahead of the good guys, criminals on the Dark Web collaborated and shared techniques that led to cybercrime for hire.

Augmented Intelligence Is the Answer

Augmented intelligence, or cognitive augmentation, is the answer. This technology elevates analysts’ performance by providing them with richly focused threat knowledge. It mitigates the shortage of skilled security analysts by increasing their effectiveness.

Security analysts are limited to consuming a fraction of available threat data, while security systems are effective in consuming structured data from fully instrumented enterprises. Unfortunately, the vast amount of security content is both human-generated and unstructured.

The average organization captures over 17,000 malware alerts per day, and some are spending as much as $1.3 million responding to erroneous or inaccurate malware alerts, according to the Ponemon Institute report, “The Cost of Malware Containment.” Only 19 percent of malware alerts are considered reliable and just 4 percent are ever investigated. Additionally, the cost of breach and incident mitigation is daunting as companies continue to assess methods to augment the limited number of security personnel.

The only way to digest, comprehend, analyze and leverage that much data is to utilize cognitive systems. The following number prove it:

  • There are over 75,000 known software vulnerabilities reported in the National Vulnerability Database.
  • More than 15,000 security blogs are published every month.
  • Approximately 10,000 security research papers are published each year, all as unstructured content.

Cognitive analytics is the strongest way to consume and prioritize a large collection of security data by providing predictive analytics. IBM is one of the first companies to offer this kind of capability with Watson for Cyber Security. It is training a new generation of systems to understand, reason and learn about rapidly evolving security threats. Watson can quickly analyze and index research, web text, video and threat data at an unprecedented speed and scale.

Watson Works Side by Side With Human Analysts

Watson does not replace the security analyst, but rather augments the analyst’s capability by providing analytics from datasets too large for human consumption. Understanding context and using reasoning, Watson provides insights into large security datasets, allowing it to become more proficient at proactively identifying risks. The following trends from IBM’s “Cybersecurity in the Cognitive Era: Priming Your Digital Immune System” report demonstrated the need for this new paradigm:

Companies must examine how to supercharge their existing security analysts by providing them access to focus analytics and threat research. Watson seeks hidden patterns in data and recognizes anomalous behaviors to expand its understanding of the global threat environment. It also produces rich contextual information key to threat detection and triage.

The economics of cybercrime will change as this intelligent augmentation expands. Cybercriminals relying on obscurity in a vast array of event data are exposed earlier in the process. Cognitive security represents a huge leap forward, even in its infancy, with its ability to effectively leverage unstructured data to find complex patterns of anomalies. Watson can significantly shorten the timeline from alert to action by applying advanced data analytics and natural language processing.

A Learning Process

How is cognitive security any different than an experienced analyst with Google? The key is cognitive systems understand context and natural language. Watson can correlate unstructured security data from multiple language sources, whereas Google’s search engine does not understand context. For example, consider the search, “Don’t show me a cat.” The engine shows you plenty of cats as a result.

Watson, however, understands natural language and can provide more powerful analytics. Its growth continues with instruction from IBM staff as well as faculty and students from eight universities. The system utilizes learning processes to generate suggestions, hypotheses and evidence-based recommendations. This capability will help address the current skills gap, accelerate threat identification and reduce the overall complexity of security analytics.

The economics of cybercrime will be transformed as companies move from being reactive to proactive. Global security companies handle over a trillion security events per month from inside corporate firewalls. Cognitive systems like Watson consider threats in the wild and leverage the rich dataset from instrumented enterprises to drastically cut down on this noise. This capability will evolve, allowing for proactive threat alerting.

For example, a specific exploit found in Eastern Europe is identified via a security alert, blog or event by a monitored system. Companies who combine the power of cognitive analytics with managed security services would be alerted in advance so that they might implement preventative action before the threat materializes.

Learn More

Cognitive systems do not replace security analysts. Instead, they enable analysts to be more effective by providing contextual threat information. Applying cognitive systems to global threat datasets can reveal patterns so complex and nuanced that they are easily missed by an analyst.

Interested in learning more about how IBM’s Watson and augmented intelligence are changing the threat landscape to stay ahead of the most advanced threats? Watch the “60 Minutes” Watson special and check out our video, “What’s So Revolutionary About the Cognitive Revolution?

Read the IBM Executive Report: Cybersecurity in the cognitive era

More from Artificial Intelligence

Generative AI security requires a solid framework

4 min read - How many companies intentionally refuse to use AI to get their work done faster and more efficiently? Probably none: the advantages of AI are too great to deny.The benefits AI models offer to organizations are undeniable, especially for optimizing critical operations and outputs. However, generative AI also comes with risk. According to the IBM Institute for Business Value, 96% of executives say adopting generative AI makes a security breach likely in their organization within the next three years.CISA Director Jen…

Self-replicating Morris II worm targets AI email assistants

4 min read - The proliferation of generative artificial intelligence (gen AI) email assistants such as OpenAI’s GPT-3 and Google’s Smart Compose has revolutionized communication workflows. Unfortunately, it has also introduced novel attack vectors for cyber criminals. Leveraging recent advancements in AI and natural language processing, malicious actors can exploit vulnerabilities in gen AI systems to orchestrate sophisticated cyberattacks with far-reaching consequences. Recent studies have uncovered the insidious capabilities of self-replicating malware, exemplified by the “Morris II” strain created by researchers. How the Morris…

Open source, open risks: The growing dangers of unregulated generative AI

3 min read - While mainstream generative AI models have built-in safety barriers, open-source alternatives have no such restrictions. Here’s what that means for cyber crime.There’s little doubt that open-source is the future of software. According to the 2024 State of Open Source Report, over two-thirds of businesses increased their use of open-source software in the last year.Generative AI is no exception. The number of developers contributing to open-source projects on GitHub and other platforms is soaring. Organizations are investing billions in generative AI…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today