security vendor
Reshaping the Threat Landscape: Deepfake Cyberattacks Are Here
Malicious campaigns involving the use of deepfake technologies are a lot closer than many might assume. Furthermore, mitigation and detection of them are hard. A new study of the use and abuse of deepfakes by cybercriminals shows that all the needed elements for widespread use of the technology are in place and readily available in underground markets and open forums. The study by Trend Micro shows that many deepfake-enabled phishing, business email compromise (BEC), and promotional scams are already happening and are quickly reshaping the threat landscape. "From hypothetical and proof-of-concept threats, [deepfake-enabled attacks] have moved to the stage where non-mature criminals are capable of using such technologies," says Vladimir Kropotov, security researcher with Trend Micro and the main author of a report on the topic that the security vendor released this week.
PhishClone: Measuring the Efficacy of Cloning Evasion Attacks
Wong, Arthur, Abuadbba, Alsharif, Almashor, Mahathir, Kanhere, Salil
Web-based phishing accounts for over 90% of data breaches, and most web-browsers and security vendors rely on machine-learning (ML) models as mitigation. Despite this, links posted regularly on anti-phishing aggregators such as PhishTank and VirusTotal are shown to easily bypass existing detectors. Prior art suggests that automated website cloning, with light mutations, is gaining traction with attackers. This has limited exposure in current literature and leads to sub-optimal ML-based countermeasures. The work herein conducts the first empirical study that compiles and evaluates a variety of state-of-the-art cloning techniques in wide circulation. We collected 13,394 samples and found 8,566 confirmed phishing pages targeting 4 popular websites using 7 distinct cloning mechanisms. These samples were replicated with malicious code removed within a controlled platform fortified with precautions that prevent accidental access. We then reported our sites to VirusTotal and other platforms, with regular polling of results for 7 days, to ascertain the efficacy of each cloning technique. Results show that no security vendor detected our clones, proving the urgent need for more effective detectors. Finally, we posit 4 recommendations to aid web developers and ML-based defences to alleviate the risks of cloning attacks.
How cybersecurity is getting AI wrong
The cybersecurity industry is rapidly embracing the notion of "zero trust", where architectures, policies, and processes are guided by the principle that no one and nothing should be trusted. However, in the same breath, the cybersecurity industry is incorporating a growing number of AI-driven security solutions that rely on some type of trusted "ground truth" as reference point. This is not a hypothetical discussion. Organizations are introducing AI models into their security practices that impact almost every aspect of their business, and one of the most urgent questions remains whether regulators, compliance officers, security professionals, and employees will be able to trust these security models at all. Because AI models are sophisticated, obscure, automated, and oftentimes evolving, it is difficult to establish trust in an AI-dominant environment.
Security Evolution: From Legacy to Advanced, to ML and AI
AI and ML present a new dawn in the cybersecurity industry. AI is not a new concept to computing. It was defined in 1956 as the ability of computers to perform tasks that were characteristic of human intelligence. Such tasks included learning, making decisions, solving problems, and understanding and recognizing speech. ML is a broad term referring to the ability of computers to acquire new knowledge without human intervention. ML is a subset of AI and can take many forms, such as deep learning, reinforcement learning, and Bayesian networks.
Complexity In Capital: Demystifying The Hype In Cybersecurity
The jargon used to describe the latest cybersecurity solutions has proliferated - "machine learning", "blockchain", "DevSecOps" and "shift left" - but the same problem remains. It is difficult to sift through the noise and find tools that actually work. In a founders' market, startups can take advantage of the easy funding environment by throwing buzzwords into an investor pitch deck, still warm from the heat generated from the RSA theme du jour. Without a doubt, security remains a huge market and an increasingly important one. So how can we identify where true value resides in this market?
Artificial Intelligence in Cybersecurity: Where are We on the Technology Adoption/Hype Cycle?
You likely have noticed how prevalent artificial intelligence (AI) and its related terms such as machine learning, neural networks, and big data analytics have become in the last several years in the world of cybersecurity. Doesn't it make sense for the security industry to be searching for the next big thing given the distressing rate of incidents and breaches the world is currently experiencing? Maybe you - like I - have gone to big security events like the RSA Conference or Black Hat and come away confused as to how these analytic concepts relate to the everyday job of keeping an organization safe. What is the proper role of AI in cybersecurity and when will it assume that role in force? One way to answer that question is to figure out where AI in cybersecurity is in its technology adoption lifecycle generally.
Artificial Intelligence in security market worth $34.81B by 2025
According to the market research report on "Artificial Intelligence in Security Market by Offering (Hardware, Software, Service), Technology (Machine Learning, Context Awareness, NLP), Deployment Type, Security Type, Security Solution, End-User, and Geography – Global Forecast to 2025", published by MarketsandMarkets, the market is expected to be valued at USD 3.92 Billion in 2017 and is likely to reach USD 34.81 Billion by 2025, at a CAGR of 31.38% High usage of the Internet and the constant need for employees to be online are contributing to the growth of this market. Another major factor driving the demand for AI-based security solutions is the shortage of cybersecurity professionals. Using AI-based solutions for cybersecurity covers much of the need for cybersecurity professionals. Software holds a major share of the overall AI in security market owing to the developments in AI software and related software development kits.
How artificial intelligence can stop the malware threats of the future
The threat landscape today is in a state of rapid growth and continuous change posing a serious risk to organisations' assets, reputations, and business. Conventional threat protection solutions have relied on a several techniques to prevent cyber infections. First, they rely on there being a patient zero – to write a signature for malware, legacy AV needs to have already seen it. Secondly, it relies on human experts – which is in short supply. However, ransomware attacks such as WannaCry, 'NonPetya' and the most recent attack, 'Bad Rabbit', continue to make headlines and infect hundreds of thousands of computers across the globe.
How AI can help you stay ahead of cybersecurity threats
Since the 2013 Target breach, it's been clear that companies need to respond better to security alerts even as volumes have gone up. With this year's fast-spreading ransomware attacks and ever-tightening compliance requirements, response must be much faster. Adding staff is tough with the cybersecurity hiring crunch, so companies are turning to machine learning and artificial intelligence (AI) to automate tasks and better detect bad behavior. In a cybersecurity context, AI is software that perceives its environment well enough to identify events and take action against a predefined purpose. AI is particularly good at recognizing patterns and anomalies within them, which makes it an excellent tool to detect threats.
Artificial Intelligence Techniques to Detect Cyber Crime - DZone Big Data
When we talk about artificial intelligence, many imagine a world of science fiction where robots dominate. In reality, artificial intelligence is already improving current technologies such as online shopping, surveillance systems, and many others. In the area of cybersecurity, artificial intelligence is being used via machine learning techniques. Indeed, the machine learning algorithms allow computers to learn and make predictions based on available known data. This technique is especially effective for daily process of millions of malware.