Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Machine Learning Is Cybersecuritys Latest Pipe Dream
Newest First  |  Oldest First  |  Threaded View
dfabbri
dfabbri,
User Rank: Apprentice
11/19/2015 | 6:42:56 PM
Explanation-Based Auditing - A different type of machine learning method for cyber security
The author rightly comments that standard anomaly detection systems are difficult to apply to cyber security. Outlier detection may help identify large scale scraping, but individual and subtle inappropriate acts are hard to find (e.g., accessing an ex-girlfriend's medical record). 

As the author notes:

"Any ML system must attempt to separate and differentiate activity based either on pre-defined (i.e. trained learning) or self-learned classifications"

Thus, for a cybersecurity machine learning system to be effective, it must have some principled and structured method to differentiate appropriate and inappropriate access. And, moreover, the system must have the correct context to make such a decision.

The author makes the statement that ML systems struggle to do this:

"Unfortunately, ML systems are not good at describing why a particular activity is anomalous, and how it is related to others. So when the ML system delivers an alert, you still have to do the hard work of understanding whether it is a false positive or not, before trying to understand how the anomaly is related to other activity in the system."

I would point the author to a new line of machine learning algorithms for access auditing called Explanation-Based Auditing.

A detailed peer-reviewed publication can be found at vldb.org/pvldb/vol5/p001_danielfabbri_vldb2012.pdf.

The general idea is to learn why accesses to data occur (e.g., the doctor accessed a record because of an appointment with the patient). This can be modeled as a graph search between the person accessing the data and the data accessed. When such an "explanation" is found, the system can determine the reason for access, filtering it away from manual review.

Thus, as the previous comment states, such as system can remove a tremendous amount of false positives, allowing the privacy or security officer to focus on the unexplained and suspicious. 

 

 
gyp
gyp,
User Rank: Author
11/5/2015 | 4:01:36 PM
Experts vs. ML is false dichotomy
The role of ML in security is not and never was replacing the experts, rather to free them from doing tedious tasks and to give them efficient tools. You don't want you experts to manually go through tens of thousands of log lines or do manual data munging every time they need to investigate an incident. Actually, if they are true experts, they would be fed up with that quite fast. Build or buy is a valid question, whether an off-the-shelf product can truly find the problems in your scenario better than something custom-built could but discarding data science as part of security alltogether would be a mistake.
RyanSepe
RyanSepe,
User Rank: Ninja
10/31/2015 | 5:04:38 PM
Re: Experts>AI
Very much agree. There will most certainly need to be a human element in cybersecurity.

Unfortunately to improve AI is a catch 22 situation. You need the man power to put hours into benefitting the technology. But then that takes hours away from that persons security knowledge being taken being used in the workforce.
Whoopty
Whoopty,
User Rank: Ninja
10/30/2015 | 8:02:29 AM
Experts>AI
I have to agree with the idea to keep paying experts rather than relying just on AI. Although I think machine learning has the potential in the future to be a major tool used to combat security issues and can be used sparingly now for some uses, there really is no substitute for an intuitive security expert. 

Not only can they improvise on the fly and make jumps way further down the alphabet than a computer controlled system can, they can intuitively figure out how human hackers may think and can provision for them. That's something that will take AI much longer to figure out, as they'll never understand how we think quite like we do.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Developing and Testing an Effective Breach Response Plan
Whether or not a data breach is a disaster for the organization depends on the security team's response and that is based on how the team developed a breach response plan beforehand and if it was thoroughly tested. Inside this report, experts share how to: -understand the technical environment, -determine what types of incidents would trigger the plan, -know which stakeholders need to be notified and how to do so, -develop steps to contain the breach, collect evidence, and initiate recovery.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-44929
PUBLISHED: 2022-12-02
An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.
CVE-2022-44930
PUBLISHED: 2022-12-02
D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.
CVE-2022-45562
PUBLISHED: 2022-12-02
Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account low privilege, this can lead to change hardware settings and execute arbitrary commands in vulnerable system functions that is requires high privilege...
CVE-2022-43325
PUBLISHED: 2022-12-02
An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input.
CVE-2022-44928
PUBLISHED: 2022-12-02
D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.