Artificial intelligence (AI) is finding increasingly broad applications. It is present in many areas of everyday life – from online shopping to healthcare. Unfortunately, cybercriminals also use it, and thanks to these mechanisms they strengthen the effectiveness of their attacks. To fight back effectively, cybersecurity teams should therefore focus on understanding these techniques and use that knowledge to design their action strategy.

As early as 2018, the Electronic Frontier Foundation warned about the possibility of malicious use of artificial intelligence. And indeed, these mechanisms are increasingly becoming a major threat to digital security, because they allow cybercriminals to need less time to break into a network. Usually this operation took even several months, while now it takes a few days. Because of such high effectiveness, the number of attacks based on artificial intelligence and machine learning is growing. Shortening the time needed to carry out malicious activities also translates into lowering the associated costs. In this context, administrators' situation is made more difficult by cybercriminals' ability to automate the entire process of mapping networks, discovering potential targets, finding security gaps in them, and even carrying out non-standard attacks.

– Artificial intelligence in the hands of attackers poses an increasingly serious threat to the security of networks and data. The situation is made worse by their ability to use so-called intelligent swarms and to create automated, script-based threats. All of this is increasing the speed and scale of cyberattacks at breakneck pace – assesses Derek Manky of FortiGuard Labs at Fortinet.

The need to use an integrated security architecture

Integrated security architecture

In many enterprises, the protection architecture is not adapted to defend against AI-based attacks. The main problem is the use of even several dozen point network security products in a single environment, often from different vendors. This makes it difficult to obtain a full picture of the level of protection, because data from many applications must be integrated manually. In such a situation, an effective and coordinated response to a cyberattack covering the entire network is impossible.

Moreover, cybersecurity teams often cannot keep up with detecting threats, because criminals are becoming faster and minimize the time needed to carry out attacks. This in turn creates the so-called Breach Detection Gap, defined as the period from the moment of breaking into a network until the incident is detected. Data presented in the Ponemon Cost of a Data Breach Report 2020 indicate that this time can average as much as 280 days. According to that report, the average cost of a data breach worldwide is $3.86 million. The scale of this phenomenon shows how important it is to integrate existing security measures.

What can IT security teams learn from cybercriminals?

What will a cybercriminal teach us?

Artificial intelligence for cybersecurity: a new defense strategy

Artificial intelligence for cybersecurity: a new defense strategy

The cybersecurity industry is constantly short of a large number of specialists. Recruiting properly qualified employees in this area is a serious problem for companies. It is especially difficult to find people who know artificial intelligence. Meanwhile, along with its development, cybercriminals are developing increasingly effective techniques based on this mechanism. Self-learning solutions used in cyberattacks make it possible not only to quickly find security gaps. They also make it possible to select in real time the malicious code most effective in a given situation and to actively neutralize attempts to block it.

– By using artificial intelligence and combining it with new attack methods, e.g. bot swarms, cybercriminals gain the ability to segment an attack. Its individual functional elements can be assigned to different swarm members to enable interactive communication and accelerate the pace of the attack. It should be noted, however, that it can also be carried out by a single criminal, so involving a larger group of people is not always necessary – describes Derek Manky.

Cybercriminals use increasingly complex and sophisticated techniques, which translates into an increase in the effectiveness of their operations. Therefore, the security strategy should also be strengthened by using solutions that leverage artificial intelligence. Cybersecurity teams should forget the principle that you do not fight fire with fire. In this case, it is the opposite. Leveling the playing field in the fight against cybercriminals will be possible only when their methodology is adapted for protective purposes. This is especially important in a situation of a shortage of specialists on the market. Using the potential of artificial intelligence can improve the work of security teams and at least somewhat reduce the negative effects of the skills gap.

Summary

Artificial intelligence, first warned about by the Electronic Frontier Foundation as early as 2018, has become a key tool for cybercriminals, shortening attack time from months to days. In response, companies must integrate their security measures, as the average time to detect a breach is 280 days, and the cost of an incident is $3.86 million.

Derek Manky of FortiGuard Labs emphasizes that security strategy should draw from attackers' methods, including intelligent swarms. Using AI in defense can level the playing field in the face of the growing skills gap in the labor market.