How to use machine learning and AI in cyber security

3 min read
Curated from itpro.co.uk →

Cyber criminals are constantly seeking new ways to perpetrate a breach but thanks to artificial intelligence (AI) and its subset machine learning, it’s becoming possible to fight off these attacks automatically.

The secret is in machine learning‘s ability to monitor network traffic and learn what’s normal within a system, using this information to flag up any suspicious activity. As the technology’s name suggests, it’s able to use the vast amounts of security data collected by businesses every day to become more effective over time.

At the moment, when the machine spots an anomaly, it sends an alert to a human – usually a security analyst – to decide if an action needs to be taken. But some machine learning systems are already able to respond themselves, by restricting access for certain users, for example.

While talk of AI and automation often brings with it fears of mass redundancy, in the sphere of security machine learning is being used within several different areas of to complement, rather than replace, traditional measures such as firewalls.

Despite their increasing ability to perform without human intervention, the systems aren’t meant to replace security analysts. On the contrary, they’re intended to crunch vast amounts of data to free up analysts for more complex tasks.

Dave Palmer, director of technology at Darktrace, says: “Having machine learning allows companies to prioritise more effectively. We don’t take human risk decision making out, but we allow tactical fire-fighting so security teams can do the work on their own timescales.”

Stuart Laidlaw, CEO of UK cyber security startup Cyberlytic, also advocates using machine learning to reduce a security analyst’s workload. “It’s about cutting through the noise: these guys are swamped in their day jobs and they can’t respond to everything. We use machine learning to do the triage.”

Where machine learning shows the greatest potential is in interpreting the output of many different expert systems and pulling it all together, says Gene Stevens, co-founder of cloud security firm ProtectWise. “Humans spend a lot of time trying to rationalise it. Machine learning is good at taking these patterns and organising the data so a human can get a highly consolidated view into the traffic moving across the network.”

Machine learning can also be useful for user behaviour analysis. For example, Jamal Elmellas, CTO at Auriga Consulting, says: “If someone logs in every day at 08:55 and that changes to 01:00, the system will flag this as suspicious behaviour.”

As the range of use cases continues to grow, how can companies start to introduce the technology? It’s relatively simple: when used for anomaly detection, it’s not necessary to train the machine learning system to a great extent initially.

“You provide it with a stream of data and flag up things that look unusual,” says Steven Murdoch, a security architect at the VASCO Innovation Centre in Cambridge. “This can then be used for intrusion protection.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at itpro.co.uk →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.