AIセキュリティ懸念高まる中、IBMが自律型セキュリティサービスを発表
IBMが自律型セキュリティサービスを導入し、サイバー攻撃を加速させるAIモデルに対応するセキュリティ市場の対策を強化した。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
2分間の読書
IBMは水曜日、自律型エージェントセキュリティプログラムをリリースした。これは、より多くの企業がAnthropicのMythosモデルの影響に対応する準備を整えるために急いでいる中での発表である。
同ベンダーはまた、IBM Consulting部門からの評価サービスも導入した。このサービスでは人間のコンサルタントが企業を支援し、セキュリティギャップ、ポリシーの弱点、AIによる露出に関する可視性を提供することで、エージェント型脅威に対処する準備状況を評価するのを助ける。
IBM Autonomous Securityは、AIエージェントを使用してソフトウェアの露出とランタイム環境を分析する別のサービスである。これらのエージェントは、企業のセキュリティ環境で悪用される可能性のあるパスを特定し、サイバー衛生状態を改善し、セキュリティポリシーを適用する。
IBMのこれらのサービスは、AnthropicがサイバーセキュリティモデルMythosと、防御的なサイバーセキュリティタスクを支援するための専用モデルであるGPT-5.4-Cyberをリリースした後に、企業が自らの環境を整備しようとしている時期に登場した。
関連記事:OpenAI、エージェントSDKを更新し、安全なエージェントの構築を目指す
ベンダーはモデルのリリースを制限したものの、Anthropicのモデルは多くの企業にセキュリティ上の弱点を認識させた。Mythosは、ベンダーや開発者が認識しておらず、ハッカーに悪用される可能性のあるソフトウェアの欠陥である数千ものゼロデイ脆弱性を発見できるからである。Mythosは単に脆弱性を特定しただけでなく、悪意のある行為者がそれらをどのように悪用できるかという方法も特定した。
脆弱性への対応の必要性
「現在、これらの発見を機械的な速度で利用する悪意のあるユーザー……犯罪者が存在します」とCloud Security Allianceの最高戦略責任者であるTroy Leachは語った。「今後、企業内のセキュリティ運用は、敵対者の量と速度に追いつくために自律型セキュリティ機能を採用しなければならない。」
彼はさらに、AIモデルがサイバー攻撃を生み出すために必要な専門知識のレベルを低下させるにつれて、セキュリティ製品は「自律的な応答のある特定のレベルで速度に対抗し、エージェントの行動が逸脱していないことを確認するために人間のセキュリティスタッフにエスカレーションする必要がある」と述べた。
IBM Autonomous Securityは、悪意のある行為者がAIモデルを悪用したり、検知されずに済むような奇妙なIT行動を正常化することを防ぐために設計された製品の例である。
「AIが[IT]アーキテクトを支援し、CISOおよびそのセキュリティチームとのより一貫した理解を持ち、現在のセキュリティ姿勢に対する真の可視性を提供するという楽観論があります」とLeachは述べた。
しかし、企業はこれらのシステムを正しく実装し、AIエージェントが正しい軌道を保つことを確保するために、AIに関する専門知識を有していなければならない。またコストの問題もある。Leachは、「AIリソースの使用に要する支出が、セキュリティ投資に見合うものであることを確認しなければならない」と述べた。
関連記事:Anthropicのツール、企業向けAIエージェント開発を加速
「処理コストは非常に高くなる可能性があり、これはクラウドコンピューティングの初期時代や、リソースの自動スケーリングに対するガードレールがなかったためにサービスプロバイダーから高額な月次請求書が届いた状況に似ています」と彼は語った。
原文を表示
2 Min ReadIBM on Wednesday released an autonomous agentic security program, as more enterprises scramble to ensure they are ready for the impact of Anthropic's Mythos model.The vendor also introduced an assessment service from the vendor's IBM Consulting unit that uses human consultants to help enterprises assess their readiness to address agentic threats by providing visibility into security gaps, policy weaknesses and AI exposures. IBM Autonomous Security is a separate service that uses AI agents to analyze software exposures and runtime environments. The agents identify paths in an enterprise security environment that can be exploited, improve cyber hygiene and enforce security policies.The IBM services come as enterprises are trying to tidy up their environments following Anthropic's release of cybersecurity model Mythos and OpenAI's GPT-5.4-Cyber, a specialized model to support defensive cybersecurity tasks. Related:OpenAI Updates Agents SDK, Aims at Building Secure AgentsWhile the vendors limited the release of their models, Anthropic's model has led many enterprises to become aware of their security weaknesses, as Mythos can find thousands of zero-day vulnerabilities, software flaws that a vendor or developer is unaware of and can be exploited by hackers. Not only did Mythos identify the vulnerabilities, but it also identified ways bad actors could exploit them.A Need to Respond to Vulnerabilities"We now have malicious users … criminals, who can take advantage of these discoveries in machine speed time," said Troy Leach, chief strategy officer at the Cloud Security Alliance. "Moving forward, security operations within the enterprise must adopt autonomous security capabilities to match the volume and speed of adversaries."He added that, as AI models reduce the level of expertise needed to produce cyberattacks, security products must "combat the speed with certain levels of autonomous responses and escalate to human security staff to confirm the actions of the agents do not drift."IBM Autonomous Security is an example of a product designed to prevent bad actors from exploiting AI models and normalizing strange IT behaviors, so they go undetected. "There is optimism that AI may help [IT] architects …have a more cohesive understanding of CISOs and their security teams, with true visibility into their current security posture," Leach said. However, enterprises must have AI expertise to implement the systems correctly and ensure AI agents stay on the right track. There is also the challenge of cost. Enterprises must make "sure the expenditure to burn AI resources is commensurate to the security investment," Leach said.Related:Anthropic Tool Speeds up AI Agent Development for Enterprises"The processing cost can be very expensive, similar to the early days of cloud computing and not having guardrails for automated scaling of resources only to find expensive monthly bills from the service provider," he said.About the AuthorNews Writer, AI BusinessEsther Shittu brings four years of expertise covering artificial intelligence technologies and industry trends. As co-host of the "Targeting AI" podcast, she talks to thought leaders and practitioners exploring critical AI developments. Previous to AI Business, she wrote for several publications including the New York Daily News, Bklyner and the Brooklyn Daily Eagle. When she's not diving deep into the world of AI, she spends her time on passion projects and raising her three daughters.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み