More on "AI for cybersecurity" - Augusto Barros

#artificialintelligence 

There is a very important point to understand about the vendors using ML for threat detection. Usually ML is used to identify known behavior, but with variable parameters. It means that many times we know what bad looks like, but not how exactly it looks like. For example, we know that data exfiltration attempts will usually exploit certain protocols, such as DNS. But data exfiltration via DNS can be done in multiple ways.