aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • Platforms
  • Solutions
  • Technology

Introducing AI-Powered Insights In Threat Intelligence

  • aster.cloud
  • April 30, 2023
  • 6 minute read

Our new Security AI WorkKbench, announced today at RSA Conference in San Francisco, uses the recent advancement in Large Language Models (LLMs) to address three of the biggest challenges in cybersecurity: threat overload, toilsome tools, and the talent gap. Threat intelligence is an area that suffers from all three problems, and LLMs have the capability to transform how it is operationalized to help secure businesses.

At Google Cloud, our threat intelligence offerings are grounded in three core principles:


Partner with aster.cloud
for your next big idea.
Let us know here.



From our partners:

CITI.IO :: Business. Institutions. Society. Global Political Economy.
CYBERPOGO.COM :: For the Arts, Sciences, and Technology.
DADAHACKS.COM :: Parenting For The Rest Of Us.
ZEDISTA.COM :: Entertainment. Sports. Culture. Escape.
TAKUMAKU.COM :: For The Hearth And Home.
ASTER.CLOUD :: From The Cloud And Beyond.
LIWAIWAI.COM :: Intelligence, Inside and Outside.
GLOBALCLOUDPLATFORMS.COM :: For The World's Computing Needs.
FIREGULAMAN.COM :: For The Fire In The Belly Of The Coder.
ASTERCASTER.COM :: Supra Astra. Beyond The Stars.
BARTDAY.COM :: Prosperity For Everyone.

  1. Trusted: Our customers can trust Mandiant Threat Intelligence to have industry-leading breadth, depth, and timeliness to deliver information that matters.
  2. Relevant: We personalize the threat landscape so it’s relevant for each customer, enabling them to prioritize threats that are likely to affect them.
  3. Actionable: Our threat intelligence is more actionable because we automate the end-to-end pipeline from raw data to security controls.

Deliver the most trusted threat intel

AI is as valuable as the data it operates on. Using LLMs to summarize irrelevant, open-source intelligence provides no more value to a customer than a manual review of that data. Doing so can even add more noise to an already-overwhelming flood of information.

That’s why the combination of Mandiant’s frontline intelligence, garnered from a team of expert researchers and over 1,000 breaches each year, and Google’s exceptional visibility on internet-wide threats, provides a powerful foundation for our AI solutions. We have been applying many natural language processing (NLP) and machine learning (ML) approaches to convert raw threat data into actionable intel for years. Recent developments in LLMs allow us to significantly improve our already market-leading intel operations. Some of the areas we are working on include:

  • Increasing the breadth of our coverage by implementing more effective tracking of digital threats across languages and modalities. Global threat actors use many methods to hide their tracks across forums, messaging services, and the deep/dark web. LLM-based approaches, which are particularly good at handling multiple modalities and languages across discussion forums, messaging services, and websites hidden from traditional search engines, help our analysts peer through this obfuscation at scale.
  • Providing greater depth to our threat intel by combining visibility across data sources. LLMs can eliminate data silos that previously prevented broad analysis by identifying relevant information across multiple sources. This will allow us to combine threat information encountered during Mandiant incident response engagements, Google’s visibility into Internet-wide threats, public information, and Mandiant research to produce a more complete and contextual picture of our threat intelligence.
  • Converting raw threat data into finished threat intelligence in machine-readable and human-readable forms. LLMs enable us to take this automation to the next level where every step in the conversion from raw threat data to finished intel to new detection rules can now be automated — with expert human supervision. In many cases, this will allow customers to see late-breaking developments in near-finished form in minutes versus days or weeks, then operationalize those insights instantly.
Read More  IBM And AT&T Bring Open Hybrid Cloud Services To Enterprise Clients For The 5G Era

Personalizing the threat landscape to focus on the most relevant threats

The vast majority of the threat landscape is irrelevant to most organizations. Therefore, it’s vital for every customer to focus on the threat landscape that is relevant for them. Personalizing the threat landscape is made possible in two ways:

  1. Automatically creating a personalized threat profile
  2. Simplifying augmentation of that threat profile by giving analysts AI based natural language search

Imagine automatically deriving a personalized and detailed threat landscape for your organization that evolves as new internal and external information becomes available. With the power of LLMs, this is becoming a reality:

  • A personalized threat profile for your organization could be automatically created, and quickly queried using a simple conversational interface to ask questions such as “Why is this threat important? What impact did this actor have on my industry counterparts? How recent has this actor’s activity been? What tactics, techniques, and procedures do they use? Why is my environment uniquely at risk? What actions should I take to mitigate the risk due to this campaign, tool, or actor?”
  • Daily recommendations could be shared on what security actions to take today based on any changes over the last 24 hours. For example, if a threat actor was seen targeting your industry using a new technique that you have exposure to, you would be notified so mitigations can be quickly put in place.
  • When there’s a significant change in your threat landscape or environment, you would be automatically provided with actionable next steps.

In the past, this kind of personalization was only available to the largest and most sophisticated organizations. LLMs will enable Mandiant to make this level of personalization available to all our customers, at scale.

Read More  The Next Step For Istio And Cloud-Native Open Source

LLMs can make search significantly more efficient. While there is a plethora of information available about threats, sorting through it and making those insights actionable requires a lot of work. The summarization capabilities of LLMs make obtaining a complete understanding of a threat topic an issue of the past. Figure 1 illustrates LLM-based summarization of various threat intelligence artifacts relevant to a query. Note that the flexibility of LLMs allow us to provide a summary of the finished intel reports alongside structured intelligence, and customize the scope and technical depth of the summary to different audiences.

Figure 1: LLM-based summarization capabilities in action on the Mandiant Threat Intelligence platform.

As we continue to leverage LLMs in search, we will be supporting a conversational interface to reduce the toil and lower the skills bar for exploring the threat landscape. These iterative searches will be stateful and shareable, making it easier to collaborate with other analysts.

Make threat intelligence more actionable

Traditionally, taking action on threat intelligence has been a burdensome manual task, limiting the value of the threat intelligence to any business. A recent global survey on threat intelligence showed that nearly half of respondents cited applying threat intelligence as their greatest challenge. At Mandiant, we have been focused on making it easier for customers to act on personalized threat intelligence in their security products and workflows.

One of the most powerful combinations we offer is our ability to apply our world-class threat intelligence to event data in Chronicle Security Operations, using AI-based models to curate and prioritize indicators of compromise (IOCs) that Mandiant tracks through active breach investigations. Mandiant Breach Analytics for Chronicle provides a prioritized set of undiscovered events that could be indicative of an active breach, as seen in Figure 2.

Read More  Cloud Functions 2nd Gen Is GA, Delivering More Events, Compute And Control

Breach Analytics for Chronicle allows customers to readily find bad actors using novel techniques and contain them before becoming the next victim. The AI based models curate and prioritize the matches to assign an Indicator Confidence Score (IC-Score), which indicates our confidence in their use in malicious activity.

Recently, we have leveraged the power of LLMs to summarize indicator/actor/malware context pulled from our vast repository of proprietary research to provide trusted threat intel to the security analysts in the SOC. This reduces toil and the reliance on expertise, eliminating the need to scour through hundreds of reports and structured data sources to understand the context of the IOC. Mandiant plans to release this feature soon.

Figure 2: LLMs providing AI summary of malware and threat actors used in a current breach

The road ahead

Taken together, applying LLMs to the trusted, relevant, and actionable pillars will help our customers reduce threat overload, eliminate manual and tiresome toil, and close the talent gap in security. We are at the beginning of a massive transformation of how threat intel delivers value to businesses of all sizes. The examples above span capabilities we will add in the short-, medium-, and long-term, and we will continue to have our product, AI research, and engineering teams collaborate to transform security for our customers.

To learn more about the use of AI in our Threat Intelligence, visit us at RSA Conference, booth N6058 or go to cloud.google.com/security/ai

By: Vijay Ganti (Head of PM Threat Intelligence, Detections & Analytics Google Cloud Security) and Scott Coull (Head of Data Science Research, Mandiant)
Originally published at: Google Cloud Blog

Source: Cyberpogo


For enquiries, product placements, sponsorships, and collaborations, connect with us at [email protected]. We'd love to hear from you!

Our humans need coffee too! Your support is highly appreciated, thank you!

aster.cloud

Related Topics
  • AI
  • Artificial Intelligence
  • Google Cloud
  • Large Language Models
  • LLM
  • Security
  • Security AI Workbench
You May Also Like
oracle-ibm
View Post
  • Hybrid Cloud
  • Technology

IBM and Oracle Expand Partnership to Advance Agentic AI and Hybrid Cloud

  • May 6, 2025
Getting things done makes her feel amazing
View Post
  • Computing
  • Data
  • Featured
  • Learning
  • Tech
  • Technology

Nurturing Minds in the Digital Revolution

  • April 25, 2025
View Post
  • People
  • Technology

AI is automating our jobs – but values need to change if we are to be liberated by it

  • April 17, 2025
View Post
  • Software
  • Technology

Canonical Releases Ubuntu 25.04 Plucky Puffin

  • April 17, 2025
View Post
  • Computing
  • Public Cloud
  • Technology

United States Army Enterprise Cloud Management Agency Expands its Oracle Defense Cloud Services

  • April 15, 2025
View Post
  • Technology

Tokyo Electron and IBM Renew Collaboration for Advanced Semiconductor Technology

  • April 2, 2025
View Post
  • Software
  • Technology

IBM Accelerates Momentum in the as a Service Space with Growing Portfolio of Tools Simplifying Infrastructure Management

  • March 27, 2025
View Post
  • Technology

IBM contributes key open-source projects to Linux Foundation to advance AI community participation

  • March 22, 2025

Stay Connected!
LATEST
  • college-of-cardinals-2025 1
    The Definitive Who’s Who of the 2025 Papal Conclave
    • May 7, 2025
  • conclave-poster-black-smoke 2
    The World Is Revalidating Itself
    • May 6, 2025
  • oracle-ibm 3
    IBM and Oracle Expand Partnership to Advance Agentic AI and Hybrid Cloud
    • May 6, 2025
  • 4
    Conclave: How A New Pope Is Chosen
    • April 25, 2025
  • Getting things done makes her feel amazing 5
    Nurturing Minds in the Digital Revolution
    • April 25, 2025
  • 6
    AI is automating our jobs – but values need to change if we are to be liberated by it
    • April 17, 2025
  • 7
    Canonical Releases Ubuntu 25.04 Plucky Puffin
    • April 17, 2025
  • 8
    United States Army Enterprise Cloud Management Agency Expands its Oracle Defense Cloud Services
    • April 15, 2025
  • 9
    Tokyo Electron and IBM Renew Collaboration for Advanced Semiconductor Technology
    • April 2, 2025
  • 10
    IBM Accelerates Momentum in the as a Service Space with Growing Portfolio of Tools Simplifying Infrastructure Management
    • March 27, 2025
about
Hello World!

We are aster.cloud. We’re created by programmers for programmers.

Our site aims to provide guides, programming tips, reviews, and interesting materials for tech people and those who want to learn in general.

We would like to hear from you.

If you have any feedback, enquiries, or sponsorship request, kindly reach out to us at:

[email protected]
Most Popular
  • 1
    Tariffs, Trump, and Other Things That Start With T – They’re Not The Problem, It’s How We Use Them
    • March 25, 2025
  • 2
    IBM contributes key open-source projects to Linux Foundation to advance AI community participation
    • March 22, 2025
  • 3
    Co-op mode: New partners driving the future of gaming with AI
    • March 22, 2025
  • 4
    Mitsubishi Motors Canada Launches AI-Powered “Intelligent Companion” to Transform the 2025 Outlander Buying Experience
    • March 10, 2025
  • PiPiPi 5
    The Unexpected Pi-Fect Deals This March 14
    • March 13, 2025
  • /
  • Technology
  • Tools
  • About
  • Contact Us

Input your search keywords and press Enter.