Fortinet is joining the generative artificial intelligence (AI) era with a new service called Fortinet Advisor that’s designed to bring natural language queries and improved operations to network security.
Like many vendors in the network security market, Fortinet has had machine learning technologies as part of its solution stack for a number of years to help with threat identification and other common tasks. Generative AI (genAI) brings a new set of capabilities that can help to improve access and the speed of response to potential incidents.
Fortinet Advisor blends the company's own threat intelligence and knowledge base with the power of large language models (LLMs) to provide security analysts with rapid incident analysis and guidance for investigations and remediation. The technology is initially being made available within Fortinet's security information and event management (SIEM) tool called FortiSIEM and its FortiSOAR security orchestration automation and response (SOAR) security operations tools. Fortinet Advisor can generate easy-to-understand incident summaries, build complex queries, suggest response plans and help create playbooks.
"This is really the first step in a journey towards an AI-driven unified SOC [security operations center], from endpoint to the SOC, to the email to whatever threat vector that is needed to provide a really complete solution for the customer," John Maddison, CMO at Fortinet, told SDxCentral.
Taking a RAG approach to genAI to improve cybersecurity accuracyFortinet is following a pattern for generative AI deployment known as retrieval augmented generation (RAG).
In the RAG approach, queries are first sent to Fortinet's own threat intelligence database before being sent to an LLM to generate responses. The AI is able to integrate information from Fortinet's global network of products to provide accurate, contextual responses.
Maddison noted that the way the Fortinet Advisor is integrated into different services will vary. The integration will change by product and where the user is in the graphical user interface (GUI) and what function they are looking at. It could be integrated as a simple pop-up or as part of a button. Over time, the plan is to have it more fully embedded across the entire GUI.
Accelerating SIEM and SOAR operations with Fortinet AdvisorThe Fortinet Advisor will help users of the company’s technologies in a number of ways.
For FortiSIEM, Maddison said that it helps filter alerts and prioritize incidents to reduce noise and determine severity and it will assist analysts with case management tasks like following alerts and cases. He also noted that the goal is to have generative AI technology integrate seamlessly into the workflow within FortiSIEM's GUI rather than being a separate assistant.
[caption id="attachment_136665" align="alignnone" width="1158"] Fortinet Advisor in FortiSIEM:.
Courtesy of Fortinet[/caption]
Within FortiSOAR, the Fortinet Advisor can be used to help analysts investigate incidents, determine the severity of threats, and provide the best playbooks for remediation.
"We're automatically evaluating the various threat intelligence sources looking to see if the threat is known and what's the severity of the malware," Kevin Faulkner, Director of Product Marketing SIEM and SOAR at Fortinet told SDxCentral.
Faulkner noted that the Fortinet Advisor makes queries and report generation easier than ever before.
"Instead of creating complex queries and getting the syntax right, figuring out how to generate a report, these are things that are typically more complex and painful to do that you can do now in natural language," Faulkner said.
Comments