April 13, 2017 By Christopher Kalamaras 3 min read

This weekend, Sergio Garcia won his first Major at the Masters, finally earning himself the coveted Green Jacket after 74 starts at a major. But while Sergio was making strides on the course, IBM’s Watson was hard at work behind the scenes, helping the Masters digital team defend against cybersecurity threats.

During the 20 years that IBM has been helping the Masters manage its digital platforms, the cybersecurity landscape has changed dramatically. Attacks have become more sophisticated as hackers collaborate across geographies and use increasingly advanced infrastructure and techniques. So it goes without saying that the tools that we use to defend against them must also adapt to keep pace. Enter Watson for Cyber Security.

A team of IBM analysts monitor the Masters digital platforms around the clock and are faced with the daunting task of analyzing tens of thousands of potential security threats per day. As with most high-profile events, the prominence of the Masters makes it a target for hackers seeking fame or fortune. Nearly every year, Masters.com is threatened by outside forces, and it’s up to our team to ensure that Masters.com remains up and running for the millions of fans who use it to view the latest scores on the leader board, watch live video, view highlights, and read articles.

What goes on behind the scenes to protect Masters.com? Using their unique skills and experience, our team of analysts must comb through vast amounts of security data to prioritize and respond to the most pressing threats, separating them from a sea of potential incidents. During the week of the Masters, that volume of data increases significantly.

This year, for the first time ever, our analysts had a new teammate in their corner: Watson for Cyber Security. Watson is a cognitive technology that has been trained to understand the language of security by reading and interpreting over a million cybersecurity-related documents. This not only allows Watson to stay up to date on the latest security research that is being published every day, but also to make unique correlations between current threat research and security events happening within the Masters cloud environment.

For example, during the Masters, our team was analyzing a denial-of-service (DoS) attempt where the attacker was using an outdated method of attack that is, in most cases, no longer relevant. So why would a criminal even bother attempting this type of outdated attack? Our lead security analyst, Johnathan Van Houten, explained it best, saying, “The denial-of-service attempt was a cover for the malware, spam and minimal port scanning that they were also doing in secret. The idea is misdirection — by attempting to distract our team with a noisy DoS attempt, they’re hoping we don’t look to find the man behind the curtain.”

Now, even with Johnathan’s 20+ years of experience in IT security, it would have been difficult and time-consuming for him to see beyond that initial attack attempt. In this case, it was the insights generated by Watson that expanded on the initial attack with the click of the button, bringing to light the man behind the curtain.

This is just one of many examples throughout the event where Watson gave us the power of cognitive insights to see beyond what our analysts would see, and in a much shorter amount of time. In events such as these, speed is our most critical resource — even a few minutes of downtime can mean a negative experience for Masters.com users. Our team used Watson for Cyber Security to investigate these incidents in a matter of minutes.

Essentially, Watson helps bring the power of man and machine together to prioritize the most critical threats and investigate them more quickly, allowing our team of specialists to focus on what matters most — the user experience. With the help of Watson for Cyber Security, we rounded off yet another successful year for the Masters, keeping all IT assets running smoothly so that fans around the world could focus on what matters most to them: the golf.

More from

Hive0137 and AI-supplemented malware distribution

12 min read - IBM X-Force tracks dozens of threat actor groups. One group in particular, tracked by X-Force as Hive0137, has been a highly active malware distributor since at least October 2023. Nominated by X-Force as having the “Most Complex Infection Chain” in a campaign in 2023, Hive0137 campaigns deliver DarkGate, NetSupport, T34-Loader and Pikabot malware payloads, some of which are likely used for initial access in ransomware attacks. The crypters used in the infection chains also suggest a close relationship with former…

Unveiling the latest banking trojan threats in LATAM

9 min read - This post was made possible through the research contributions of Amir Gendler.In our most recent research in the Latin American (LATAM) region, we at IBM Security Lab have observed a surge in campaigns linked with malicious Chrome extensions. These campaigns primarily target Latin America, with a particular emphasis on its financial institutions.In this blog post, we’ll shed light on the group responsible for disseminating this campaign. We’ll delve into the method of web injects and Man in the Browser, and…

Crisis communication: What NOT to do

4 min read - Read the 1st blog in this series, Cybersecurity crisis communication: What to doWhen an organization experiences a cyberattack, tensions are high, customers are concerned and the business is typically not operating at full capacity. Every move you make at this point makes a difference to your company’s future, and even a seemingly small mistake can cause permanent reputational damage.Because of the stress and many moving parts that are involved, businesses often fall short when it comes to communication in a crisis.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today