Partner Perspectives  Connecting marketers to our tech communities.
1/17/2017
12:00 PM
Liviu Arsene
Liviu Arsene
Partner Perspectives
Connect Directly
LinkedIn
Twitter
Google+
RSS
100%
0%

Machine Learning For Cybersecurity Not Cybercrime

Cybercriminals have yet to adopt machine learning for offensive attack strategies - and they probably won't for a long time.

The cybersecurity industry has always been under constant strain from cybercriminals and malware. With increasing integration of hardware, software and services being built into every aspect of our lives, the task of keeping data secure has become even more difficult.

The arsenal of tools that cybercriminals now have at their disposal has raised concerns for security companies, and turned the criminals into threat actors who can create, disseminate and penetrate a target’s defenses using custom-built and never-before-seen malware. The security industry has had to adopt a new way of dealing with the unknown by leveraging the powerful capabilities of machine learning algorithms.

Cybersecurity & Machine Learning
Because targeted and advanced threats that seek to prey on organizations and businesses often evade traditional security mechanisms, machine learning algorithms have stepped in to fill in the gap between proactivity and detection. While humans are great at in-depth analysis and pinpointing code subtleties in malicious samples, machine learning is better at applying models on large data without tiring or complaining of repetitive tasks.

In the context of big data – where everything connected to the Internet from IoT devices to physical and virtual endpoints is a potential source of information or point of attack - machine learning can be trained to parse, analyze and interpret that data with little no effort.

The human component, however, is responsible for the accuracy of the machine learning model and for supplying its “wits.” Cybersecurity specialists with years of experience in reverse engineering malware samples and analyzing attack techniques are the ones who usually transfer their experience to machine learning algorithms, training the algorithms for behavior analytics and anomaly detection. While machine learning algorithms range from neural networks to genetic algorithms, their ultimate goal is to adapt to variations of a baseline behavior.

Do Cybercriminals Use Machine Learning?
No, they don’t! That’s because they already have a wide range of tools and mechanisms that have automated not only malware development but also ensured that each new malware sample is unique.

Obfuscation and polymorphism are just two examples cybercriminals use to create and deliver ransomware samples to both average users and organizations. They are so effective that ransomware is estimated to have inflicted at least $1 billion in financial losses in 2016 alone.

Encryption is another powerful tool consistently leveraged by cybercriminals to mask data exfiltration and even extort victims. The whole point of the cybercrime industry is to constantly create new packing mechanisms for malware samples, and not necessarily come up with innovative attack techniques or behavior. This doesn’t require machine learning; it involves constant algorithm tweaking or the development of obfuscation functions or encryption algorithms.

Is Machine Learning Offensive or Defensive?
When applied in the “cyber” context, current machine learning capabilities are mostly defensive. Machine learning helps the security industry tackle more than 500 million malware samples. Cybercriminals have yet to adopt machine learning and they probably won’t for a long time.

While there have been examples of machine learning algorithms being pitted against each other; one looking for software vulnerabilities and the other trying to patch them – these exercises were for demonstration only.

Of course, machine learning can be considered to have offensive capabilities when applied in the gaming industry, as it can be trained to take out virtual foes with the same accuracy as their human counterparts. However, they’re yet to be used for cybercriminal activities. 

Liviu Arsene is a senior e-threat analyst for Bitdefender, with a strong background in security and technology. Reporting on global trends and developments in computer security, he writes about malware outbreaks and security incidents while coordinating with technical and ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Moises Danziger
50%
50%
Moises Danziger,
User Rank: Apprentice
3/24/2017 | 5:27:15 PM
I wouldn't be so sure
During my researchs in the application of Machine Learning (ML) on security I've been surprising with some proposals showing ways to apply ML to cybercrime. For example, for malware obfuscation, to improve the C&C channel from botnets, to add intelligence for worms...etc. These are simple examples. After that, I've been studying the impact of ML when in bad hands. I can tell you hackers will use ML to improve their attack tools soon (although they may already be applying). Our challenge is discovering how it could be dangerous for current security tools.
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
Bitdefender delivers security technology in more than 100 countries through a cutting-edge network of value-added alliances, distributors, and reseller partners. Since 2001, Bitdefender has consistently produced market-leading technologies for businesses and consumers and is one of the top security providers in virtualization and cloud technologies. Bitdefender has matched its award-winning technologies with sales alliances and partnerships and has strengthened its global market position through strategic alliances with some of the worlds leading virtualization and cloud technology providers.
Featured Writers
White Papers
Video
Cartoon
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.