Google introduced its next-generation large language model (LLM) — PaLM 2 at this week’s I/O conference and, during last month’s RSA conference, launched Security AI Workbench that leverages generative artificial intelligence models to gain better visibility into the threat landscape. Those AI moves along with the Mandiant acquisition are designed to strengthened the hyperscaler’s cloud security strategy.

The Security AI Workbench suite is powered by Sec-PaLM, which is an LLM fine-tuned for security use cases, integrating Google's security intelligence and Mandiant’s intelligence on vulnerabilities, malware, threat indicators, and behavioral threat actor profiles. The integration enables new AI tools such as VirusTotal Code Insight and Mandiant Breach Analytics for Chronicle, which analyze potentially malicious scripts and alert customers of active breaches in their environments, according to Google.

The LLM adds “unique value” to cloud security and Google Cloud has structured it around three key areas: reducing the tedious and repetitive workload of security professionals, addressing the talent gap in the security industry, and improving the speed at which threats can be identified and stopped, Jeff Reed, VP of product-cloud security at Google, told SDxCentral.

To reduce the toil, LLM can be used to summarize large volumes of information, such as combing through thousands of Mandiant reports for quick analysis by security professionals, as well as generate attack path simulation, and offer potential mitigation strategies.

On the talent side, Reed noted the LLM can assist in rule creation for Chronicle's detection engine based on the technical language YARA-L. The LLM can convert simple queries into YARA-L rules, which upskill security professionals who may not be familiar with the language.

As for threat detection, the suite features the VirusTotal Code Insights, which uses the LLM for code analysis. This includes identifying bad hygiene practices, identifying malicious code not yet flagged by antivirus (AV) engines and even flagging code incorrectly deemed malicious by some AV engines. “It's a great example of the power of LLMs to help you provide better scale, quicker response to threat detection,” he said.

Google’s edge in using LLM

Google’s differentiation in the LLM arena lies in its ability to externalize, vast expertise and a full-stack approach, Reed said.

He noted as a pioneer in AI, Google laid the groundwork for the current AI revolution with years of expertise, research and development. Additionally, Google Cloud takes a full-stack approach including custom-designed chips engineered for speed, scale, cost, and power efficiency in AI applications.

Reed added normal LLM doesn't have a deep understanding of security jargon, rule creation, and other niche areas. That’s why Google had made substantial investments in training its Sec-PaLM models with all the data and threat information from sources like VirusTotal, Mandiant and Chronicle.

In addition to using this LLM for Google Cloud’s own projects like VirusTotal Code Insight, it has also externalized it, making it accessible to partners and customers via its Vertex AI platform.

Google Cloud, Mandiant integration in AI, cloud security

Mandiant is complementary to Google Cloud’s security strategy, especially in consulting incident response and threat intelligence areas, Reed pointed out.

Google completed its Mandiant acquisition for $23 per share in an all-cash deal valued at around $5.4 billion last October. Mandiant has more than 600 cybersecurity consultants and over 300 intelligence analysts powering Mandiant Advantage, its managed multi-vendor extended detection and response (XDR) platform.

Mandiant’s frontline intelligence combined with Google's intelligence from Gmail, Chrome, Android, reCAPTCHA, Chronicle, and VirusTotal enhances the threat landscape visibility and analytics. And this is now being applied to security operations, offering new capabilities like curated threat detection and Mandiant Breach Analytics, Reed said.

“What we're doing is bringing all that data together on the SecOps platform side,” he added.