Exploring the cutting edge of AI in cybersecurity

3 min read
Curated from zdnet.com →

With the number of cybersecurity threats increasing daily, the ability of today’s cybersecurity tools and human cybersecurity teams to keep pace is being overwhelmed by an avalanche of malware.

According to Cap Gemini’s 2019 Reinventing Cybersecurity with Artificial Intelligence: The new frontier in digital security report, 56% of survey respondents said their cybersecurity analysts cannot keep pace with the increasing number and sophistication of attacks; 23% said they cannot properly investigate all the incidents that impact their organization; and 42% said they are seeing an increase in attacks against “time-sensitive” applications like control systems for cars and airplanes.

“In the Internet Age, with hackers’ ability to commit theft or cause harm remotely, shielding assets and operations from those who intend harm has become more difficult than ever,” the report states. “The numbers are staggering — Cisco alone reported that, in 2018, they blocked seven trillion threats on behalf of their customers. With such ever-increasing threats, organizations need help. Some organizations are turning to AI [artificial intelligence], not so much to completely solve their problems (yet), but rather to shore up the defenses.”

Even though AI and machine learning (ML) have been used for years to reduce the noise from myriad cybersecurity tools and platforms, at first glance the cutting edge of AI has not progressed very far from this seemingly basic functionality. It is still focused on reducing false positives and filtering out unnecessary alerts, and other distractions that hamper cyber security teams’ effectiveness. 

“It’s a bit tongue in cheek for people to talk about AI and cybersecurity when we’re not there yet,” said Chase Cunningham, vice president and principal analyst, Security & Risk at Forrester. “AI is good at looking at large chunks of data and then figuring out what the anomalies are and then suggesting a remediation action to those anomalies. That’s the crux of it kind of in totality.”

What has changed over the past decade or so is the enormity of this deceptively simple undertaking, said Frank Dickson, IDC’s program vice president, Security & Trust. 

“You’re under-appreciating the complexity of the task,” he said. “When you think of any particular infrastructure, I have 10 million end points. I have thousands of applications …I have a potpourri of environments, whether they be SaaS, PaaS, IaaS. I have IoT [internet of things] devices all over the place. I’ve got contractors coming in …working on my networks. And, in the middle of this, I’ve got business people launching new services that I don’t know about. The sea of complexity is just so extreme; that’s the task at hand.” 

According to Eric Chien, a fellow at Symantec (now a division of Broadcom), there are one million new malware samples generated everyday. There is no way a human could even begin to analyze this tsunami of malicious code to see if their organization is at risk. But, fortunately, this is what today’s AI is particularly good at. It can spot, and help stop, 99.9% of these threats because they are often variations on existing malware.

This frees up human analysts to focus on the remaining .001% of malware that can be some of the most damaging because it is net-new; it is part of a larger, multi-layered attack designed to obfuscate and confuse; a highly targeted attack; or, perhaps, a combination of all of these elements. 

“The real advancements are, how do we go after that last remaining gap?,” said Chien. “That last remaining gap tends to be some of the most impactful threats; the ones that are going to cause the most damage.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at zdnet.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.