Artificial Intelligence: a new milestone for Cybersecurity
Ryan Michael Wilson · Zenodo (CERN European Organization for Nuclear Research) · 2021
The combination of computing power and the availability of vast amounts of information has allowed the development of an ancient human ambition to delegate tasks to machines that were only limited to him: the elaboration of predictions in environments complexes and decision making. With Artificial Intelligence (AI), we can interpret an image and detect disease, establish a conversation or anticipate risks much faster than before, such as the risk of default or fraud when collecting insurance. In Cybersecurity, which consists of avoiding risks around our digital assets, AI also has a wide field of action. Artificial Intelligence, as a set of predictive and self-learning techniques, is helping to improve Cybersecurity. This resorts to the continuous calibration of the algorithms as they are exposed to new information. The degree of complexity and dispersion of the systems companies currently work on means that the traditional and manual means of surveillance, supervision and risk control have proven insufficient. Furthermore, the very use of AI by cybercriminals makes our systems much weaker. How can you improve Cybersecurity with Artificial Intelligence? Current applications of AI to Cybersecurity are broad: Threat hunting: identification of threats and neutralization of cyberattacks. Traditional techniques that rely on the identity or commitment indicators (indicators of compromise) can be seen improved, closing the security gaps to manage and interpret behavioral indicators. Vulnerability Management. The number of vulnerabilities grows every year, and it is not enough to wait for cybercriminals to exploit them to react to them. User and Event Behavioral Analytics (UEBA) allows you to identify abnormal behaviors that signal cyber-attack activity even before patches are available to correct vulnerabilities. Data centers. As in other areas in which it operates, AI facilitates the optimization and monitoring of critical data processing centers and helps detect threats of abnormal behavior. It improves the use of these resources and their evolution, with the consequent cost savings and risk reduction, such as the failure of services or the execution of malicious software. Network security. Both in the field of policies for action against user behavior and in the more topographic area when it comes to identifying which processes correspond to each application, AI allows learning the behavior patterns of traffic on the network and recommending grouping of workloads, as well as the application of security policies. Secure user identification. Both for the protection of users who access our services and the set of elements that they use, AI can identify the use of false identities or brute force attacks, conferring an additional barrier to fraudulent access to our services beyond user authentication the use of captcha. Information privacy and compliance. AI helps to automatically classify information by its criticality level in the face of different regulations such as the GDPR. This implies savings concerning the efforts that are currently made manually, avoiding the risks that this entails. They are blocking bots based on their behavior. Without being malicious, the bot activity consumes the bandwidth of our servers, damaging the user experience of our current clients. AI allows classifying the activity of these visitors to limit their actions. These cases are a reality for the most advanced players in the digital world, such as Google that introduced AI in Cybersecurity in its Gmail service, or IBM/Watson that includes this combination among its security tools. Other notable cases are those of Juniper Networks or Balbix. Also, new businesses and fresh startups should always think of adopting AI technologies from the start. For example, startups like Sypwai and many others signed up to https://www.incubator-tech.com/ admitted, that using AI in their cybersecurity was one of the main points on their development plan. Both because cybercriminals rely on AI to carry out their attacks and the advantages it provides for the management of different cybersecurity systems and services, the implementation of security solutions that use Artificial Intelligence has become a necessity. We will improve at detecting the bad guys, lower costs for our current levels of security, and improve the experience for our customers and users.