Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Partner Perspectives //

bitdefender

1/17/2017
12:00 PM
Liviu Arsene
Liviu Arsene
Partner Perspectives
Connect Directly
Twitter
Google+
LinkedIn
RSS
100%
0%

Machine Learning For Cybersecurity Not Cybercrime

Cybercriminals have yet to adopt machine learning for offensive attack strategies - and they probably won't for a long time.

The cybersecurity industry has always been under constant strain from cybercriminals and malware. With increasing integration of hardware, software and services being built into every aspect of our lives, the task of keeping data secure has become even more difficult.

The arsenal of tools that cybercriminals now have at their disposal has raised concerns for security companies, and turned the criminals into threat actors who can create, disseminate and penetrate a target’s defenses using custom-built and never-before-seen malware. The security industry has had to adopt a new way of dealing with the unknown by leveraging the powerful capabilities of machine learning algorithms.

Cybersecurity & Machine Learning
Because targeted and advanced threats that seek to prey on organizations and businesses often evade traditional security mechanisms, machine learning algorithms have stepped in to fill in the gap between proactivity and detection. While humans are great at in-depth analysis and pinpointing code subtleties in malicious samples, machine learning is better at applying models on large data without tiring or complaining of repetitive tasks.

In the context of big data – where everything connected to the Internet from IoT devices to physical and virtual endpoints is a potential source of information or point of attack - machine learning can be trained to parse, analyze and interpret that data with little no effort.

The human component, however, is responsible for the accuracy of the machine learning model and for supplying its “wits.” Cybersecurity specialists with years of experience in reverse engineering malware samples and analyzing attack techniques are the ones who usually transfer their experience to machine learning algorithms, training the algorithms for behavior analytics and anomaly detection. While machine learning algorithms range from neural networks to genetic algorithms, their ultimate goal is to adapt to variations of a baseline behavior.

Do Cybercriminals Use Machine Learning?
No, they don’t! That’s because they already have a wide range of tools and mechanisms that have automated not only malware development but also ensured that each new malware sample is unique.

Obfuscation and polymorphism are just two examples cybercriminals use to create and deliver ransomware samples to both average users and organizations. They are so effective that ransomware is estimated to have inflicted at least $1 billion in financial losses in 2016 alone.

Encryption is another powerful tool consistently leveraged by cybercriminals to mask data exfiltration and even extort victims. The whole point of the cybercrime industry is to constantly create new packing mechanisms for malware samples, and not necessarily come up with innovative attack techniques or behavior. This doesn’t require machine learning; it involves constant algorithm tweaking or the development of obfuscation functions or encryption algorithms.

Is Machine Learning Offensive or Defensive?
When applied in the “cyber” context, current machine learning capabilities are mostly defensive. Machine learning helps the security industry tackle more than 500 million malware samples. Cybercriminals have yet to adopt machine learning and they probably won’t for a long time.

While there have been examples of machine learning algorithms being pitted against each other; one looking for software vulnerabilities and the other trying to patch them – these exercises were for demonstration only.

Of course, machine learning can be considered to have offensive capabilities when applied in the gaming industry, as it can be trained to take out virtual foes with the same accuracy as their human counterparts. However, they’re yet to be used for cybercriminal activities. 

Liviu Arsene is a senior e-threat analyst for Bitdefender, with a strong background in security and technology. Reporting on global trends and developments in computer security, he writes about malware outbreaks and security incidents while coordinating with technical and ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Moises Danziger
50%
50%
Moises Danziger,
User Rank: Apprentice
3/24/2017 | 5:27:15 PM
I wouldn't be so sure
During my researchs in the application of Machine Learning (ML) on security I've been surprising with some proposals showing ways to apply ML to cybercrime. For example, for malware obfuscation, to improve the C&C channel from botnets, to add intelligence for worms...etc. These are simple examples. After that, I've been studying the impact of ML when in bad hands. I can tell you hackers will use ML to improve their attack tools soon (although they may already be applying). Our challenge is discovering how it could be dangerous for current security tools.
Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Microsoft to Officially End Support for Windows 7, Server 2008
Kelly Sheridan, Staff Editor, Dark Reading,  1/13/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15625
PUBLISHED: 2020-01-18
A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.
CVE-2019-19696
PUBLISHED: 2020-01-18
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishi...
CVE-2019-19697
PUBLISHED: 2020-01-18
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must already have administr...
CVE-2019-20357
PUBLISHED: 2020-01-18
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.
CVE-2020-7222
PUBLISHED: 2020-01-18
An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to authenticate. An attacker who changes the result parameter (to true) in this JavaScript code can bypass authentication and achieve limited privileges (...