AiR, Security-Focused Autonomous AI Agents

Autonomous AI Agents integrated
with a Security Operations Center (SOC)

AiR (AI Road) is a security-specialized 'AI Agent' that makes decisions by combining Large Language Models (LLMs) with natural language understanding capabilities and workflows optimized for the security domain. AiR can perform tasks such as detection, analysis, and search that influence security operators' judgment and operational execution.

  • Needs for
    Security-Focused
    Autonomous AI Agents

  • Establishing an “AI-based automated security response system”
    can significantly increase operational efficiency and
    alleviate the fatigue of security teams.
    At the heart of this system are ‘AI Agents.’

    What are AI Agents?

    They are AI systems that combine Large Language Models (LLMs) with natural language understanding capabilities and
    workflows optimized for specific domains, enabling them to make informed decisions.

    Security-specialized AI Agents can be utilized
    for resolving complex security issues.

  • Key Features

  • ‘AiR’ is a ‘hybrid detection model’ service that provides the basis for the AI model’s decision-making on specific security data through the IGLOO detection model, descriptive AI, and generative AI.
    Users can evaluate the reliability of AI answers by checking the criteria by which AI model made specific predictions and improve their understanding of AI answers with the given descriptions in natural language.

    • 1

      IGLOO's Classification AI detection model

      It is based on a technology that can classify abnormal and normal security-related behavior through AI data learning.

      The model, which learns high-quality learning data developed by IGLOO using its own system data, establishes its own decision-making criteria to determine whether there is an attack or not.

    • 2

      IGLOO's explainable AI model

      It is based on a technology that informs what criteria AI uses to detect specific behavior as abnormal or normal.

      It describes AI predictions based on algorithms(e.g. SHAP) or existing patterns.

      It Identifies the reason why the Classification AI detection model has produced such results on the basis of the importance of attack features that has affected the model’s prediction process.

    • 3

      Generative AI model

      It is based on AI technology that creates new content based on learning about existing content.

      It provides descriptions in natural language, determined by ChatGPT based on its own data.

      There are plans to link multiple generative AI models and to apply the own generative AI model.

  • Advantages

  • Expected Effect

  • AiR is a security-specialized AI assistant that integrates IGLOO Corporation’s own AI technologies.

    AiR bridges knowledge gaps across security organizations by increasing reliability and understanding of AI-detected attacks, helping to ensure the best action is always implemented quickly.

    1

    Upgrading the security organization's analysis capabilities

    By comparing and checking the answers provided by the three AI models, you can increase your organization’s analysis capabilities.

    Predictions made by Classification AI detection model
    (results produced by the Classification model)

    Importance of attack characteristics (features) that has influenced the predictions
    (results produced by the descriptive model )

    Results in “natural language” form provided by the generative model.

    2

    Enhancing response efficiency by linking with various security devices

    We support integration with our own products and third-party products (SIEM, SOAR, portal, existing data protection products, etc.)

    It is possible to improve the playbook creation efficiency and reinforcement effect of SPiDER SOAR.