{"id":23829,"date":"2018-08-13T11:21:02","date_gmt":"2018-08-13T11:21:02","guid":{"rendered":"http:\/\/www.intelligentcio.com\/eu\/2018\/08\/13\/artificial-intelligence-friend-and-foe-for-it-security\/"},"modified":"2020-10-29T12:03:46","modified_gmt":"2020-10-29T12:03:46","slug":"artificial-intelligence-friend-and-foe-for-it-security","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2018\/08\/13\/artificial-intelligence-friend-and-foe-for-it-security\/","title":{"rendered":"Artificial Intelligence: Friend and foe for IT security"},"content":{"rendered":"<p style=\"text-align: left\"><em><strong>Bharat Mistry, Principal Security Strategist, Trend Micro, outlines how Artificial Intelligence and Machine Learning are shaking up the threatscape for both attackers and defenders.<\/strong><\/em><\/p>\n<p>Everyone\u2019s talking about AI and Machine Learning (ML). At the Infosecurity Europe event this year it was hard to spot a vendor not touting its own capabilities as the latest and greatest to hit the market. In these terms it\u2019s difficult not to view the technologies as merely the latest industry buzzwords to add to a lengthy list that includes UTM, IDS, EDR, sandboxing and more. But they\u2019re far more than that. AI and ML are not only transforming the cybersecurity industry but also the threat landscape.<\/p>\n<p>There\u2019s a storm coming and we\u2019ll need the best that AI can offer to fend off an increasingly sophisticated and effective range of attacks.<\/p>\n<p><strong>Speed and skill<\/strong><\/p>\n<p>AI is a classic double-edged sword, a technology that can be used by both attacker and defender to improve success rates. Research from last year revealed that 87% of US cybersecurity professionals are currently using some form of AI but that 91% are concerned that hackers will turn the tech against them. At Trend Micro we\u2019ve been using Machine Learning in our products for over a decade, to improve spam detection, calculate web reputation and more.<\/p>\n<p>So what can AI offer the white hats?<\/p>\n<p>Fundamentally, it\u2019s the ability to learn normal behaviour and then spot patterns in network data and threat intelligence feeds that human eyes might miss, enabling analysts to take action or automating threat detection and response. This is particularly important given the security skills shortages facing firms. It was claimed last year that the UK is heading for a skills \u2018cliff edge\u2019 as older professionals retire without newer talent coming through to replace them. The shortfall globally is predicted to reach 1.8m professionals by 2021.<\/p>\n<p>Security analysts are expensive and hard to come by, so by automating the discovery of threats with AI, you free up their time to focus on more strategic tasks, whilst improving the effectiveness of your cybersecurity posture. Speed is also of the essence when it comes to threat detection. The longer you leave a threat actor inside the network, the more data they can exfiltrate and the more expensive the resulting breach. Costs are estimated in the UK at an average of \u00a32.7m today, with the mean time to identify a breach standing at an unacceptable 163 days. AI can shorten this dwell time significantly.<\/p>\n<p>Speed is also important in spotting ransomware, which works even faster to encrypt an organisation\u2019s most mission-critical files. Machine Learning can spot inconsistencies and subtle changes in the way the malware works to encrypt your files, which would otherwise be lost in the noise.<\/p>\n<p>Pre-execution Machine Learning can even help firms to block malicious files before they\u2019ve had a chance to infect the organisation. False positives are sometimes a challenge, which is why such tools are often run in combination with run-time analysis to ensure that what you\u2019re blocking is definitely unwanted.<\/p>\n<p>The goal is to have a cybersecurity system featuring AI tools which can learn over time, much as a child does as it grows and matures. They build up patterns, incorporating feedback from threat analysis in a virtuous feedback loop that ensures continuous improvement as it goes on.<\/p>\n<p><strong>The dark side<\/strong><\/p>\n<p>But on the flipside, there\u2019s huge potential in AI for malicious use. In fact, it could have made historic cyberattacks and breaches far more impactful than they were. Take WannaCry \u2013 it might have caused headlines around the world and disrupted a third of the NHS, but as a piece of malware it failed. It was too noisy, attracting the attention of security researchers soon after launch and failed to provide its masters with a decent ROI.<\/p>\n<p>AI could correct this. By installing learning tools on a target\u2019s network, attackers could listen in and baseline user behaviour, understand network traffic and communications protocols and map the enterprise. This would make it child\u2019s play to move laterally inside the organisation to the targeted data or user \u2013 all without raising the alarm.<\/p>\n<p>Social engineering is also much easier if you use AI tools to understand users\u2019 writing style and the context of their communications. Just think about a document review process. A hacker could monitor communications between remote employees and then insert a malware-laden document at just the right time, using an email with just the perfect tone and language to convince a user to open it. This is spear-phishing like you\u2019ve never seen it \u2013 attacks that even the experts would have a hard time spotting.<\/p>\n<p>More importantly, it could be done at scale, in a highly automated fashion \u2013 as could the use of AI to help cybercriminals engineer malware to outwit current tools.<\/p>\n<p><strong>Should we be worried?<\/strong><\/p>\n<p>Off-the-shelf technology is already available that could be used for malicious purposes. Think of Google\u2019s speech-to-text AI tools used in a cybersurveillance attack on a boardroom. Secondary AI could then be used to go through the text and pick out key sections of interest for the attackers. We\u2019re not seeing any bespoke AI hacking tools as of yet \u2013 although this will change in time. Expect the as-a-service model to democratise such tools on the dark web when they do finally appear.<\/p>\n<p>AI is in many ways the cyberarms race writ small. The only way we can manage the inevitable wave of black hat tools designed to circumvent security filters and increase the sophistication of phishing is to fight back in kind. It\u2019s going to be a bumpy ride.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Bharat Mistry, Principal Security Strategist, Trend Micro, outlines how Artificial Intelligence and Machine Learning are shaking up the threatscape for both attackers and defenders. Everyone\u2019s talking about AI and Machine Learning (ML). At the Infosecurity Europe event this year it was hard to spot a vendor not touting its own capabilities as the latest and [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":41562,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,14],"tags":[158,577,8552,183,564,7327,3881,1844,8553,1268,701,7198,2075],"class_list":["post-23829","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-more-news","tag-ai","tag-artificial-intelligence","tag-bharat-mistry","tag-cyberattacks","tag-cybersecurity","tag-infosecurity-europe","tag-machine-learning","tag-malware","tag-principal-security-strategist","tag-ransomware","tag-roi","tag-trend-micro","tag-wannacry"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/23829","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=23829"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/23829\/revisions"}],"predecessor-version":[{"id":23851,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/23829\/revisions\/23851"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/41562"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=23829"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=23829"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=23829"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}