IBM QRadar SIEM Turns Cloud Native – Chris Meenan, IBM
Chris Meenan, vice president of product management at IBM Security, discusses IBM’s recently announced evolution of QRadar SIEM to a new cloud-native foundation. The move is an investment in the underlying data architecture and a modernized UX design that empowers security analysts and AI to work together more seamlessly. As part of the news, IBM is also previewing plans to introduce generative AI for security using IBM watsonx.
Transcript
This is Textron tv. Well, the great pleasure of being joined by Chris Mena. Chris is Vice President, excuse me, vice President Product management, IBM, security at IBM.
Of course. Welcome Chris. Hi.
Yeah, thank you. Thanks for having me today. Good to have you back on.
I know you've talked with Alan, you've been on with us before. It's always good to have our security chats. Yeah, absolutely.
What's happening at, at IBM? Um, and we're coming up towards the end of the year. I don't know, are you going on the road anymore?
I've, I've just come off of a couple trips, have one more plan, but hopefully not too many more before we hit 2024. I'm actually just off of a, a red eye where I've done a whistle stop tour of North America for our border advisors, our IBM Security summit, and then out into Houston to see a customer, and then next week off to Saudi Arabia for black hats. So, um, yeah, we're in the midst of it right now and we threw in a new, big new product announcement as well.
So. Well, let's get to that. I mean, that's part of why I ask is I know you've had a big announcement and it's the season for, you know, for events as well as customer events and things like that.
So tell us about what's going on. Yeah, actually last week was super big announcement for IBM security. Um, uh, and honestly, my, me personally as well, I've been with IBM security 12 years.
I spent all that time, um, growing up with the QRadar business, uh, which is, you know, founded in our SIM technology, you know, going from, you know, several hundreds of customers up to, you know, multiple thousands of customers that we have today. And last week was actually the announcement about the, the effectively the next generation of our Q sim, um, sim, uh, offering, which we're calling our, our cloud native edition of, of QRadar, uh, sim. And it's really represents the, you know, uh, uh, the architectural evolution of our QRadar, uh, SIM offering now is now running natively on a cloud native architecture that gives improved scalability, resiliency, um, elasticity, et cetera, um, built on a cloud native architecture that can, uh, run obviously natively in cloud PLA for cloud environments, but is also, also can run on, on, on premise because it is all running on Red Hat OpenShift.
So as a big part of, um, you know, the announcement there, but it's not just the lift and shift. We've also been introducing a lot of new innovations, um, into the SIM offering, uh, that specifically are targeted at some of the challenges that organizations face in, in a hybrid multi-cloud environment. Um, and at the same time as that we have, you know, also had our eye very closely on our Q Suite portfolio.
So our QRadar suite is really the evolution of not, um, not only our SIM offering, but our SOAR offering and our EDR offering and the new cloud cloud native security log management capability. We announced at, at RSA earlier this year where all of these capabilities now are just delivered on a single platform, single cloud native platform with a single user experience where we're fussing all of those SOC elements into one analyst experience that is fused with automation and AI to drive higher productivity. So it, it's, it, it's a really exciting release because of that core architectural evolution, but also what we're doing to introduce more automation and AI and, and a, a completely integrated threat detection and response solution for, um, for our customers.
It, it's amazing how much our world in the security world has changed in the last five to 10 years thinking about cloud native architecture and MO moving our own software, our own tools, our own mm-Hmm. Products in your case, which is no, no big deal. I mean, you mentioned it's a lot of work, right?
Yeah. And I, and I always, I'd like, I feel so great for people to get to do a big launch like this 'cause I have at least some idea, you know, what, it's, what, what the effort is to put into that more release a product, more or less re-architect tactic and release it. And I, and I assume maybe one of the drivers behind doing that was to get some of the advantage of a cloud native architecture to try to do more of these innovations more quickly in smaller bites or whatever it might be to give you more nimbleness in how you, you release capabilities to the market.
Yeah, absolutely. So there's a couple of, I would say probably three drivers, well, I might add another one on when I talk, go through it. But I think definitely the new architecture helps, um, obviously with scale and elasticity, you know, obviously move to the cloud, attack surface growing, there's ever more data volumes.
People have got less time they want ev you know, everything needs to be easier and more elastic. You know, just like, give, give me this capacity on demand and just like have it happen. So the big, big, big part of that is enabled by this architecture.
Um, the, the second thing that the cloud native does is, um, you know, very much is, uh, is is around that, um, that on demand side of things. So I I, I, I want things now and I need them, I need it. I, I need not only the scale, but the functionality now.
So being able to deliver that, um, much more quickly. And then I think the third thing that, um, importantly is, you know, we don't see sim obviously, you know, organizations today still buy SIM and SOAR and EDR, et cetera, but they're very much looking for a platform play, like a platform solution. They want to reduce the number of moving parts.
They want to streamline the user experience. So actually a cloud native architecture has let us bring together our SIM capability with our Soar, with our EDR, with our core log analytics into one, one, you know, essentially one experience and one offering for, um, for the user. Uh, and then fuse the insights across all of those into that experience as well.
And Cloud Native really helps with that because now feed things that we're separate products or in separate stacks are now just features in the one experience that can just be switched on and off like any sort of cloud service can today. So that's, that's what I'm really excited about. Now, the fact that delivering that, you know, that on demand, that scale, but also what we're able to do from an outcome perspective by fussing together, you know, all the, the core fi core capabilities in our q our suite offering.
You know, we've done, uh, kind of modular software architectures forever, right? Kinda, yeah. But it seems like cloud native is a really the first, ca first real time where we can point to this directly and say, here's how we can deliver that capability on top of what we already have without changing everything exactly to a new functionality.
Have it show up in the goby, and maybe you're doing an API first kind of architecture to make it all easier to plug together, and you're not, you know, trying to reassemble a big application. It, it, if done, done well, and it sounds like you have, it really can make a huge difference going to market. Yeah, I think it's the inve, you know, the investment side of it is the, the strategy is really important.
And I think, and you, you'll see this different vendors adopt different strategies. You can have individual products that are sort of loosely coupled together. So they're sort of URL linked.
There's an awful lot of exchanging of information between one and the other and, and wiring things together. And that is one approach, and it tends to be like we can get sort of something out faster. Um, the approach we took was, okay, look, we, we have those individual offerings, they are integrated.
What, but what organizations really need is a, a unified platform where all of that wiring and URL linking and different management stacks and different user management, different configs, et cetera, all of that just goes away and gets collapsed into one mm-Hmm. And then suddenly products turn into features and capabilities on a single, you know, SOC platform, integrated threat detection response solution, whatever you want to call it, that that's been, that's been what we have been focused on. Wonderful.
I mean, you mentioned some of the elements of that around SIM and other capabilities, and also you mentioned innovation, you know, AI's on the top of, so we have to ask, how about, oh no, absolutely. How does that fit in the picture? A big driver for us has been, um, and we put out, like there's a big headline in the, in the, in the press release, was this is all about making our teams maximizing their potential.
Um, you know, um, focusing on the analyst workflow, making them them easier. And there's two big things we've done as well. Actually, again, three things.
I would say, first of all, um, that in order to drive that analyst productivity, one, we've made the solution really open. And what does that mean? It means that our, our unified workflow can connect to third party tools.
So not only bringing together the workflow in our products, it can actually connect to third party products in, uh, third party sims and third party EDRs. Um, and leveraging open technologies and federated search, um, uh, enable analysts to get that same productivity output by focusing on one unified workflow. Um, the second thing we've done is embedded a ton of automation into that workflow.
So things like, um, uh, alert and, um, Intel, uh, alert enrichment, um, automated investigation, recommended response actions. Um, and obviously with SOAR being just part of the, you know, part of the functionality, you can now infuse additional, uh, custom automation for the organization into any part of the analyst workflow. And the third and the most important really is, is AI and artificial intelligence.
So, um, we've embedded that into the workflow as well in a couple of different forms. We've not, we've got the classical AI and then also we announced our intention to introduce generative AI capabilities. So on the classical AI side of things, you know, we've embedded classical AI is really that sort of, that type of AI that's, you know, very well proven around like, um, classifying things as, you know, this looks good or this looks bad, um, this looks abnormal, or this looks normal.
That kind of ai. And we've got that embedded in our, embedded in our q our suite and our q our sim analyst workflow that really help with alerts, triage. So when alerts come in, we immediately pass it through our AI there.
And we have different AI for different types of alerts and models Mm-Hmm. Um, with ai that's very good at, that's really tuned around endpoint based alerts and with ai that's really good around your more sim based alerts. And they help, like I, that they help, um, really focus the analysts on like, on the top 5% of things that they, that are really high priority.
And we've, we've been testing this AI and, and, and leveraging it in our own SOCs, um, our own, in our own net managed services. So over the years, and now we've embedded that and made that just, uh, part of the standard workflow. So we're really excited to see that come in.
Um, and we also have AI that, that is in, in ingesting like threat intelligence, um, feeds and making sense of that and prioritizing that intelligence that's also feeding in into the new SIM offering as well. But the generative AI is the bit we're coming onto next. And that's a, that's a different class of ai.
It's, it's sort of, it's, it's complimenting the existing AI that we've put in, um, from the analyst workflow. The new generative AI is much more about like, you know, helping analysts with this task of I've got all of this data, um, how do I, and I, I'm a junior analyst, I've got all of this data, I've got all of these alerts coming in. They've all been prioritized.
I've got a set of recommended actions, now I need to, but I want a quick overview of an incident or I need to communicate to my manager or other stakeholders like, what's happening? Like what and what has happened, what's gonna happen next? Who are the threat actors?
What sort of other things should we be looking for? And with that, that is where generative AI is really great at taking a whole bunch of like, insights and turning it into something easily consumable, you know, um, by the user, but then also for other stakeholders as well. And what we have found is our approach with openness and the analyst workflow is, is making that AI really even more powerful for the user and the organization because now the generative AI has more inputs.
'cause it's not just coming from data we've got, it's coming from their entire environment. And it's, and we've embedded it into the analyst workflow so that it's just always there assisting them. So we have other use cases of, for our generative AI that we're, um, planning for, um, uh, early next year as well, um, around, uh, query generation as well.
Um, and other use cases, um, that really, really looking at assisting, removing redundant, sorry, repetitive, like quite high cognitive load, um, use cases from the analyst and helping them, um, with that. And that's, this is all leveraging our Watson X, which is all built on the IBM Watson X AI platform as well, that has a high degree of governance, um, transparency, um, that explainability built into it as well. 'cause as we talked in security leaders, they're concerned about data leakage with AI models, especially with security.
Like I give, if I put my security data into your AI model, how do I know that other people aren't gonna, that that data's not gonna be leaked out? Mm-Hmm. Um, um, how do I know what data, what data this model's being trained on that's, that's now going to do this interpretation for me and can I trust that data?
Um, so all of the, those sorts of aspects are really inherent in, in our Watson X AI platform. Um, so it's ideally suited to deliver that AI security AI use cases. Yeah, it is, it is a, in, it is a particular use case using AI and generative AI within a security context and sensitivity around that information.
But also to, to your point, the complexity of it, right? If I have to go write a big, big report and try to explain that in, you know, normal speak to someone, maybe I need to do it as a, as an incident report. But it's, something's gonna be shared with legal or communications or senior management, right?
How do I Totally, uh, absolutely. And we actually see, you know, different, so there's the SOC persona, but we actually see are building out UX as the support, you know, non soc personas to ask those kind of questions. Like, okay, what are my, what are my top incidents today that, um, haven't had automated actions?
Right. That's okay. Yeah.
That's one of the key things that security leaders are really looking, 'cause they're looking at driving automation and they wanna understand like, why are we not automating everything, right? So tell me the top things that I'm not automating or where the response time took more than 10 minutes. Right.
Um, because that's where my risk is. That's where I wanna look at what I wanna get a better understanding of what's going on. And generative AI is really good at really, really got a lot of potential to help get that level of visibility without adding even more work to the team.
Mm-Hmm. So like we see a lot of, well we see a lot of potential, um, there, and that's the, the areas we're exploring. But it all always now is coming back to, okay, I need, I need to trust the, the models, I need to understand the data sovereignty side of things and the, um, and uh, I, I always forget the, the words, the provenance of the underlying models.
I, you know, I can, can I trust it? We've had some experience of this already with our classic a classical AI that's doing the like alert prioritization and triage down to the level where, you know, in our offerings we actually provide like the ability for users to switch on and off different attributes that go to the ai Mm-Hmm. So that they are comfortable with that level of data going, you know, into the AI models for assessment.
Um, some say no, I don't want any PII data going in there, no usernames. So you can switch that off now. And that has certain implications then on what, how the val you know, how much the model can help, but they can start making that sort of risk trade off.
So, um, risk versus value and outcome trade off. Um, so these are the kinds of things that back in the security, in the AI security space that we see enterprises needing, um, wanting visibility and control over. Very good.
So I cut back to the um, cloud native re-architected version of the actual radar, uh, SIM product. Is that generally available now? Is that coming out in the coming weeks or so?
I know the generative AI stuff you talked about was kind of looking into 2024, but how about the, the newly architected, uh, qa? Oh yeah. So the newly architect says the 5th of December, that's when g as a SaaS first.
So our approach with our cloud native architecture in the same, and the QAR suite has been, um, is a hybrid, you know, hybrid cloud approach. Mm-Hmm. So it's all based on Red Hat OpenShift.
So it can run in the cloud as a SaaS and be available to on-premise customers. 'cause that is important. It's still a large portion of it.
Certainly the IBM customer base and the market is still running on-prem and will do for a long time, be it for regulatory requirements, um, you know, business requirements, et cetera. Yeah, exactly. There's, there's a, there's a portion we're not going to move there.
And um, so, um, but we have a SaaS first approach, so all our new offerings and capabilities come outta SaaS and then, you know, you know, anywhere from three to six months or so later we rule 'em into the on-prem software. Um, you know, once we rule them into the SaaS environment, got that initial feedback, then we rolled it out to the software. So yeah, SaaS, SaaS first, 5th of December, uh, software sort of middle of next year.
Very good. Well congratulations on the announcement. Thank you.
Uh, the upcoming SaaS release of QRadar. Yeah. Very, very excited about it.
Um, yeah, to the wild and get you cut new customers using it. That's fantastic. Yeah.
And we look forward to the additional generative AI and other things I'm sure that are coming down the Yeah, there's a whole actual, you know, the whole bunch of other, uh, things we've added you from a SIM perspective to, um, help with just even implementing a SIM better, like things like adopting like the open, we really leaned into openness as well. Not just open in terms of I'm going to connect to things, but open standards. So things like Sigma mm-Hmm.
So we've moved to the Sigma rule support way of defining use cases and why have we done that? Well, 'cause there's a massive community there now. There's skills developed there, there's content.
So we've said, okay, instead of doing something proprietary, let's just use that. That's what actually what that helps. It really helps organizations accelerate.
And even things like our search language, you know, we have a new cloud native backend. We didn't go and create a new proprietary search language. We said, okay, we will adopt KQL.
Lots of people out there are learning KQL now. Mm-Hmm. So we adopted that.
Um, you know, and that again helps, that open approach helps a ton with skills, it helps a ton with content. And these are all real challenges for the security market in general. And, you know, SIM is no exception to that.
So, you know, in, in addition to all the highlight, you know, the AI stuff and, you know, cloud native architecture, there's all also some other just like stuff we've done that, um, you know, just to really help with customers on that skills and content side of things that again, they're really appreciative of all almost as much as some of the new, you know, more headline grabbing. Well, you know, if you make the fundamental things even easier, more productive. Exactly.
Yeah. So now, yes, and then all the, the other things on top of that, you know, all the better, but use those other things all the time. So, yeah.
Well, good. com, SA security, um, where, uh, cloud first SaaS first company really leaning in. So it's all on our webpages now.
Um, um, yeah, all there we can, you can get, have a look at the clickthrough demos, you can see the features, you can sign up for trials, further information, et cetera. So. Excellent.
Very good. We'll check it out. IBM do com slash security, right?
Yeah. All good. Okay, well thank you very much.
It's been a, a privilege, fun, A lot of ti uh, fun talking with you, Chris. Get a little bit of rest, uh, coming off the road 'cause it sounds like you're hitting, hitting things a little bit more. Yeah.
Rocking up my, uh, racking up my air miles at the minute for sure. Yeah, it's been great talking to you, Mitch. And, um, and, um, yeah, looking forward to giving you more updates in the future as we roll this out, grace.
Great. Great. Uh, Chris, uh, mean and Meum from IBM, we'll talk to you again soon, Chris.