New AI Technology Promises to Transform Security Operations Centers
A Detailed Look at Agentic AI: The Next Step in SOC Automation
Security Orchestration, Automation, and Response (SOAR) was introduced in the mid-2010s with high expectations. Innovators like PhantomCyber, Demisto, and Swimlane promised to revolutionise Security Operations Centers (SOCs) by automating routine tasks, minimising manual efforts, and improving overall efficiency. Yet, despite three generations of advancements, SOAR has failed to fully deliver on its core promise, leaving SOCs struggling with many of the same issues they faced a decade ago.
Now, a new approach known as Agentic AI could transform SOC operations, finally realising the vision that SOAR initially set out to achieve.
The Evolution of SOAR Technologies
Over the past decade, SOAR has evolved through three primary generations:
Gen 1 (Mid-2010s): The initial wave of SOAR featured static, code-heavy playbooks that were complex to implement and maintain. This led to limited adoption, primarily focused on basic tasks like phishing triage.
Gen 2 (2018–2020): The second generation introduced no-code, drag-and-drop editors along with extensive playbook libraries. This lowered the barrier for adoption and reduced the need for heavy engineering resources.
Gen 3 (2022–present): The current generation leverages generative AI to automate playbook creation, further simplifying the implementation process.
Despite these advancements, SOAR's promise of comprehensive SOC automation has remained out of reach. Instead, each iteration of SOAR has primarily improved operational ease but failed to address the fundamental challenges of automating SOC workflows.
Challenges That Hindered SOAR
The core difficulty lies in the complexity of SOC tasks, which can be broadly divided into two categories:
- Thinking tasks: These include analysing if an alert is real, understanding its scope, and planning a response.
- Doing tasks: These entail executing response actions, notifying stakeholders, and updating records.
SOAR excels in automating "doing" tasks but falls short on "thinking" tasks. Key issues include:
- Complexity: Thinking tasks require a deep understanding of security contexts, data synthesis, and decision-making, which are difficult to encode into static playbooks.
- Unpredictable Inputs: Security incidents often involve unpredictable elements, making it challenging to create playbooks capable of handling all scenarios.
- Customization Needs: Pre-defined playbooks often require significant customization, increasing the maintenance burden.
The Unfulfilled Promise of SOAR
Efficiently automating the "thinking" tasks is crucial for achieving the original vision of SOAR—to significantly enhance SOC speed, scale, and productivity. Manual triage and investigation processes create bottlenecks, preventing SOCs from becoming truly automated environments. These phases are labour-intensive, limiting the SOC's ability to swiftly respond to threats.
Enter Agentic AI
Recent advancements in AI, particularly large language models (LLMs) and generative AI, offer new possibilities for addressing these challenges. Agentic AI has emerged as a potent solution, mimicking human cognitive processes to automate alert triage and investigation tasks.
What is Agentic AI?
Agentic AI represents a shift from traditional AI implementations. It functions as an autonomous SOC analyst capable of completing entire investigative workflows, from interpreting alerts to making decisions. Unlike other AI solutions that mainly assist human analysts, Agentic AI autonomously handles the decisional aspects of SOC operations, delivering fully executed work units that humans can review.
How Agentic AI Works
When a security alert is generated, it first goes to the Agentic AI rather than directly to human analysts. The AI conducts a comprehensive investigation by:
- Interpreting Alerts: Using LLMs to understand the alert, creating possible security hypotheses.
- Data Enrichment: Pulling data from external sources such as threat intelligence feeds, and analytic models to add context to the alert.
- Dynamic Testing: Running specific tests to validate or invalidate hypotheses.
- Synthesising Findings: Producing a detailed report that includes the alert's verdict, summary, root cause analysis, and an action plan.
This automation allows SOC teams to focus on higher-level decision-making rather than operational tasks. Further, Agentic AI can integrate with security tools to automate response actions either semi-automatically or entirely without human intervention.
Trust in Agentic AI
Concerns about the accuracy and reliability of AI in SOC operations are prevalent. However, Agentic AI offers several assurances:
- Thoroughness: The AI conducts exhaustive investigations, leveraging a broad range of techniques.
- Accuracy: By using specialised mini-agent LLMs for distinct domains, Agentic AI achieves high accuracy rates, often surpassing human capabilities.
- Behavioural Analysis: The AI consistently learns and updates normal patterns, enhancing its investigative precision.
- Transparency: Every action performed by the AI is meticulously documented, providing an audit trail that human analysts can review.
Benefits of Agentic AI
The adoption of Agentic AI brings several key benefits to SOCs:
- Increased Detection Capability: By thoroughly investigating every alert, SOCs can identify real threats that might have been missed.
- Reduced Mean Time to Respond (MTTR): Automating triage and investigation accelerates the entire response process.
- Enhanced Productivity: Freeing analysts from repetitive tasks allows them to focus on complex security projects.
- Improved Analyst Morale: With less monotonous work, analysts can engage in more satisfying and strategic activities.
About Radiant Security
Radiant Security is at the forefront of Agentic AI, providing AI-driven SOC analysts capable of delivering detailed, decision-ready reports quickly. By automating investigative tasks, Radiant's solutions enable SOCs to operate more efficiently, reducing response times and improving overall security operations.
This transformative approach finally promises to fulfil the original vision of SOC automation, long sought after through previous generations of SOAR technology.
Source: Noah Wire Services