DeepSeek do the Seeking: Introduction “SOAR+AIng"
AI for Data Insights and Decision Making

DeepSeek do the Seeking: Introduction “SOAR+AIng"

In today’s fast-evolving cybersecurity landscape, automation is no longer just about employing workflows or integrations but it’s also about reimagining the entire decision making process to minimise human effort.

I do agree that Security Orchestration, Automation and Response (SOAR) has moved Incident Response (IR) to another level by enabling the use of workflows and integrations but then what..?

Automation, with room to grow!

It still falls short of eliminating noise, often functioning just as middleware primarily for ticket assignment and memo keeping, these tickets are then passed on to analysts for further triage and escalation.


Ahh..that ..hurts!

In December 2022, I began working on several proof-of-concepts (POCs) focused on automating detection rules using OpenAI. I even wrote an article titled ‘Detection Engineering Automation.’ Obviously, upsetting a few people hehe..but let’s move on to the next section.


Let’s enter the word of latest AI thing in market DeepSeek AI , a family of large language models (LLMs) similar to OpenAI’s GPT or Google’s Gemini. It is designed for various natural language processing (NLP) tasks such as text generation, summarisation and reasoning.

Some variants of DeepSeek are fine-tuned for specific domains, like coding or security analysis and can run locally using Ollama i.e. a free, open-source tool that allows users to run large language models (LLMs) on your local systems.

DeepSeek

Ollama creates an isolated environment to run LLMs locally on your system that includes all the necessary components for deploying AI models, for example: LLM Model weights it’s configurations and etc.

Examples of DeepSeek Models: Refer to this link

  1. deepseek-r1
  2. deepseek-coder-v2

I’ll be using a smaller version of the DeepSeek model with 1.5b parameters that my Intel-chip MacBook can handle :( for this demo.But you can try bigger models with upto 671b parameters.        

Steps to perform:

  1. Install Ollama https://ollama.com/download
  2. Open Terminal and download DeepSeek Model in Ollama with following command.

Download: "ollama pull deepseek-r1:1.5b"

To run: "ollama run deepseek-r1:1.5b"        
Ollama - DeepSeek

3. You can use terminal to interact with model via prompts and can also view the installed model with `ollama list`

Ollama list

Using LLM DeepSeek can enable SIEM/SOAR solutions not just to react, but proactively seek, analyse, triage and respond the threat alerts.

Posting Part-2 soon, with all the required hands on

Ofcourse, it's not a magic bullet and requires proper tuning but let's 
explore what we can achieve in my next article in the "SOAR-ING" series!        

Medium Blog for deeper insights: https://medium.com/@ashishsecdev/deepseek-do-the-seeking-introduction-soar-aing-3a5cf3493101

If you need any recommendations, don’t hesitate to reach out to me.

~AshishSecDev

Akshay Khanna

Kredivo Group | OSCP | CRTP | eWPTXv2 | SRT

1 个月

Very helpful

Zeeshan Ali

Senior Security Engineer at Vonage | Ericsson

1 个月

Very helpful and insightful ??

要查看或添加评论,请登录

Ashish Bansal的更多文章

  • A peep into the world of SOAR (Security Orchestration, Automation and Response)

    A peep into the world of SOAR (Security Orchestration, Automation and Response)

    Information Security has become one of the top priorities for most organizations today as they are now expected to rise…

    4 条评论
  • Cloud Security: Considerations, Challenges and Solutions

    Cloud Security: Considerations, Challenges and Solutions

    Cloud computing has been around for almost three decades, and offers obvious advantages to its users, such as…

    3 条评论
  • COVID: An Opportunity to Change

    COVID: An Opportunity to Change

    The pandemic has given rise to new perspectives for both individuals and enterprises owing to the current social…

    4 条评论
  • Cheese Your Dream ;)

    Cheese Your Dream ;)

    Dreams are not what we see in sleep, dreams are what do not let us sleep. (Abdul Kalam, the Missile Man of India.

    6 条评论