The value of data science in security

Data science is no longer just another business domain that security needs to harden and protect: it is becoming a core function of security itself.
This is a major change compared to even two years ago.
Consider the Australian government’s 2016 cyber security strategy, which pointed to the role that security would play in helping businesses properly harness big data.
To “fully realise” big data – and hence data science – opportunities, “these technologies and the infrastructure on which they operate must be trusted”, the government noted. “Strong cyber security will enable this.”
Likewise, Data61 – whose mission is “to create Australia’s data driven future” – indicated around the same time that it would not be able to achieve that vision without addressing “national challenges around cyber security.”
In both cases, security was seen as an input or ingredient needed to allow businesses to step towards a data-driven future.
This is true – but the tables can also be turned. Security has a data-driven future of its own to achieve, in which data science is the essential ingredient needed to enable security organisations to achieve success in this domain.
One of the most commonly-cited examples of data science for security purposes comes from the banking and insurance industry. There, data science brings together a combination of analytics and machine learning to detect fraudulent transactions.
By scanning various datasets relating to user and network behaviour, companies can detect anomalies and either respond or generate an alert – prioritised according to threat level – for security professionals to investigate further. This basic premise can be put to work for countless security applications: detecting attempted intrusions on a company network, identifying users acting against corporate policies, or managing risk.
Thanks to machine learning, models and algorithms can be refined further over their lifetime – reflecting changes in staff behaviour, alterations in the technology using the network, or evolution in the threat landscape – to reduce the number of unnecessary alerts that staff are called on to look into. However, as with any data science project, those in security can only advance with the right fuel – the appropriate data.


