dark reading
Dark Reading
The Internet has enhanced communications, increased commerce, and brought people together socially. Unfortunately, it has also enabled malicious activity with data breaches, ransomware, destroyed systems, and the Dark Web. Cyberattacks have become so common that only the large ones make the news now. The United States is arguably the most "wired" country in the world, with everything from cars to refrigerators to security cameras connected online, making us also the most vulnerable. Because the open Internet is driven by cost and speed and not by security, continual cyberattacks have pushed us into a new kind of Cold War -- with artificial intelligence (AI) serving as the basis of this arms race. From Moonlight Maze in the late 1990s to the recent SolarWinds attack, we have seen malware and ransomware planted in our infrastructure and systems.
Dark Reading
For the past couple of years, renowned technologist and researcher Bruce Schneier has been researching how societal systems can be hacked, specifically the rules of financial markets, laws, and the tax code. That led him to his latest examination of the potential unintended consequences of artificial intelligence on society: how AI systems themselves, which he refers to as "AIs," could evolve such that they automatically - and inadvertently - actually abuse societal systems. "It's AIs as the hacker," he says, rather than hackers hacking AI systems. Schneier will discuss his AI hacker research in a keynote address on Monday at the 2021 RSA Conference, which, due to the pandemic, is being held online rather than in person in San Francisco. The AI topic is based on a recent essay he wrote for the Cyber Project and Council for the Responsible Use of AI at the Belfer Center for Science and International Affairs at Harvard Kennedy School.
Dark Reading
A new report from AI research firm Adversa looked at a number of measurements of the adoption of AI systems, from the number and types of research papers on the topic, to government initiatives that aim to provide policy frameworks for the technology. They found that AI is being rapidly adopted but often without the necessary defenses needed to protect AI systems from targeted attacks. So-called adversarial AI attacks include bypassing AI systems, manipulating results, and exfiltrating the data that the model is based on. These sorts of attacks are not yet numerous, but have happened, and will happen with greater frequency, says Eugene Neelou, co-founder and chief technology officer of Adversa. "Although our research corpus is mostly collected from academia, they have attack cases against AI systems such as smart devices, online services, or tech giant's APIs," he says.
Artificial Intelligence & the Security Market
Machine learning, advanced heuristics, or artificial intelligence: the language is shifting but the idea that computers are taking a greater role in automating security functions is moving straight ahead. Two new product announcements demonstrate that direction in very different ways. Aella Data and Senzing each brings a product based on AI technology to market, and in some ways the products could not be more different in purpose, intended audience, or business model. But both share a critical similarity: Each uses AI to correlate data from many different sources to present information that assists humans in doing their jobs. Aella Data came out of stealth mode just before this year's RSA Conference.
Can Machine Learning Outsmart Malware? - Dark Reading
Fighting malware is a modern arms race. Not only has malware evolved to be more evasive and harder to detect, but their vast numbers make it even more difficult to handle. As a result, detecting a malware has become a big data problem which requires the help of self-learning machines to scale the knowledge of analysts, handle the complexity beyond human capabilities, and improve the accuracy of threat detection. There are number of approaches to this problem; choosing the right algorithm to serve the security engine's purpose is not an easy task. In this article, we will refer to machine learning (ML) as an application of artificial intelligence (AI) where computers learn without being explicitly programmed.
Machine-Learning Project Sifts Through Big Security Data
As an information-security consultant, Alexandre Pinto spent 12 years helping companies set up difficult-to-configure systems to cull security intelligence from logs and security events. Yet configuring the systems required months of work and even then needed constant maintenance to enable them to detect the latest threats and pinpoint likely malicious traffic. He realized that while companies may want to monitor their networks for threats, they typically have too few security people to work through data from far too many logs -- a problem that will only get worse as companies seek to sift through more operational data to detect threats. Big data could be the downfall of security if companies don't find better ways of dealing with the growing volumes, he says. "What chance do we have: We can't find the needle in the haystack as it is now, and now the haystack is 100,000 times larger," he says.