ITENFRDEESCA
vertigosuisse.ch ↗
Home / Blog
BLOG DICEMBRE 2022

Machine Learning and Artificial Intelligence: focus on cyber security!

In today's complex digital environments, machines fight against machines and skilled attackers and criminal organizations invent new and sophisticated methods to carry out their missions.

V
Vertigo Consulting · Lettura 4 min

Machine Learning and Artificial Intelligence:
focus on cyber security!

A new era has begun in cybersecurity.

In today's complex digital environments, machines battle against machines, and expert attackers and criminal organizations invent new and sophisticated methods to perpetrate their missions. The corporate network has become a battlefield.

The danger today is not just the classic data theft or website compromise scenarios, but the silent threat that lurks beneath the surface, "kill switches" ready to be activated, threats that are nearly impossible to detect.

Against this new reality, legacy security systems are failing because the traditional approach to cybersecurity relies on the ability to define the threat in advance.

From new and rapidly spreading attacks to the most skilled insiders, from hacked IoT devices to compromised supply chains, the threat landscape evolves unpredictably and a new approach to cyber defense is badly needed.

AI/AI and ML

L'Artificial intelligence can identify and neutralize cyberthreats never seen before. 

The Machine Learning it has the power to transform cyber defense by meeting the challenge of making it work at scale in a variety of dynamic data environments, detecting genuine threats in real time without human intervention, which is certainly not a trivial task.

By pioneering artificial intelligence for cyber defense and successfully applying it in different digital contexts, Darktrace has proven to be a world leader in autonomously detecting and responding to cyberthreats that legacy systems miss. Powered by machine learning and artificial intelligence algorithms, Darktrace's "immune system" technology is used by thousands of organizations around the world.

Different types of Machine Learning

According to the traditional paradigm, firewalls, endpoint security methods, and other tools such as SIEMs and sandboxes are implemented to enforce specific policies and provide protection against recognized threats.

Although these tools still have a defensive role, they are not enough.

Legacy systems have been overtaken by modern business complexity and attacker innovation due to a few key limitations:

Mostly, legacy tools require victims before they can provide solutions.

The Supervised Machine Learning it works by using previously classified data, from which the machine learns the classification system.

The proliferation of data in the modern world means that it is not only unproductive, but impossible for humans to sift through the vast amount of information generated every minute within a typical corporate network.

Machine learning, when applied correctly, can help machines make logical decisions based on probability, augmenting the capabilities of human teams and uncovering previously unimaginable insights.

Today, supervised machine learning is used in many commercial and industrial fields for classification purposes. For instance:

However, overfitting is a common problem in supervised machine learning, where model parameters are too tuned to the training data. Instead of learning the essence of a category, the machine learns a particular example: for example, it may learn to recognize a German shepherd, but it cannot understand "dogs" as a category, and the characteristics that make that German shepherd part of the group.

Systems that rely solely on supervised machine learning have weaknesses fundamentals:

While supervised machine learning can be powerful, there are those who have the vision to build the first self-learning cyber defense platform in their DNA: new machine learning methods can dramatically improve the accuracy of threat detection and improve network visibility due to the greater amount of computational analysis they can handle.

Data relating to historical attacks does not necessarily protect against future ones: it is mandatory to also be able to use deep learning techniques to integrate the artificial intelligence engine with the specialized skills of expert cyber-analysts, further strengthening the power of "Unsupervised" Machine Learning.

Unlike “supervised” approaches, the “Unsupervised” Machine Learning it does not require labeled training data and does not need human input. Unsupervised learning can then take computer processing beyond what programmers already know or can imagine and uncover previously unknown relationships: instead of relying on knowledge of past threats, it independently classifies data and detects valid patterns . From this, it forms an understanding of “normal” behaviors across the network, relating to devices, users or groups of both, and detects deviations from this evolving “pattern of behavior” that could indicate a developing threat.

So in a nutshell: Machine Learning can detect things that we humanly cannot predict or define. Figuratively speaking, it's like finding the classic needle in a huge haystack.

If this haystack were the security of your data, your business, your privacy and the needle was a lit cigarette… how long and with what methods would you like to find it!?

← All articles

More articles

Blog →
BLOG
From "midnight vigils" to zero downtime
The transformation of FIDIM
BLOG
Cyber Threat Intelligence
Chronicle of a success in Milan.
BLOG
Christmas Team Building!
A wonderful way to close the year, together. 🎄✨