Goto

Collaborating Authors

 security defense


Microsoft open-sources tool to use AI in simulated attacks

#artificialintelligence

The Transform Technology Summits start October 13th with Low-Code/No Code: Enabling Enterprise Agility. As part of Microsoft's research into ways to use machine learning and AI to improve security defenses, the company has released an open source attack toolkit to let researchers create simulated network environments and see how they fare against attacks. Microsoft 365 Defender Research released CyberBattleSim, which creates a network simulation and models how threat actors can move laterally through the network looking for weak points. When building the attack simulation, enterprise defenders and researchers create various nodes on the network and indicate which services are running, which vulnerabilities are present, and what type of security controls are in place. Automated agents, representing threat actors, are deployed in the attack simulation to randomly execute actions as they try to take over the nodes. "The simulated attacker's goal is to take ownership of some portion of the network by exploiting these planted vulnerabilities.


Global Big Data Conference

#artificialintelligence

As part of Microsoft's research into ways to use machine learning and AI to improve security defenses, the company has released an open source attack toolkit to let researchers create simulated network environments and see how they fare against attacks. Microsoft 365 Defender Research released CyberBattleSim, which creates a network simulation and models how threat actors can move laterally through the network looking for weak points. When building the attack simulation, enterprise defenders and researchers create various nodes on the network and indicate which services are running, which vulnerabilities are present, and what type of security controls are in place. Automated agents, representing threat actors, are deployed in the attack simulation to randomly execute actions as they try to take over the nodes. "The simulated attacker's goal is to take ownership of some portion of the network by exploiting these planted vulnerabilities. While the simulated attacker moves through the network, a defender agent watches the network activity to detect the presence of the attacker and contain the attack," the Microsoft 365 Defender Research Team wrote in a post discussing the project.


IBM, AI And The Battle For Cybersecurity

#artificialintelligence

As Artificial Intelligence (AI) becomes a bigger part of the IT landscape, cybersecurity is becoming an AI battlefield. The latest and most aggressive attacks in cybersecurity are now leveraging AI to evade traditional security defenses and to counter adversarial responses. The cat and mouse game between attacker and defender is moving to a different level where AI is augmenting the human element. The future of cybersecurity will likely be AI versus AI. Attackers can use AI in cybersecurity attacks to evade detection (evasive), hide in many locations without detection (pervasive) and automatically adapt to counter measures (adaptive).IBM Research is using its expertise to help build the tools to defend against attacks of all kinds and protect data privacy. As enterprises experiment with AI services, machine learning models that power AI have become so important that the models themselves are the target of intrusion attacks.


Cybersecurity pros are using artificial intelligence but still prefer the human touch

#artificialintelligence

Security professionals need a varied bag of tricks to keep up with savvy and sophisticated cybercriminals. Artificial intelligence is one valuable weapon in the arsenal as it can handle certain tasks faster and more efficiently than can human beings. That's why many security pros still want the human element to play a significant role in their security defense, according to a survey from WhiteHat Security. Based on a survey of 102 industry professionals conducted at the RSA Conference 2020, WhiteHat's "AI and Human Element Security Sentiment Study" found that more than half of the respondents are using AI or machine learning (ML) in their security efforts. More than 20% said that AI-based tools have made their cybersecurity teams more efficient by eliminating a huge number of more mundane tasks. Further, almost 40% of respondents said they feel their stress levels have dropped since adding AI tools to their security process.