White Paper | Offense and Defense: How AI is Countering the Threat of AI

White Paper | Offense and Defense: How AI is Countering the Threat of AI

This white paper explores the dual role of artificial intelligence in cybersecurity, highlighting how it can both pose threats and serve as a protective measure. It discusses the implications of AI advancements for security strategies, emphasizing the need for organizations to adopt proactive measures against AI-driven attacks.

White Paper | Offense and Defense: How AI is Countering the Threat of AI

1 Security Leaders Braced for Daily AI-Driven Attacks by Year-End – Infosecurity Magazine, 24th April 2024 2 85% of Cyber security Leaders Say Recent Attacks Powered by AI: Weekly Stat – CFO, 30th August 2023 3 Cyber Attacks Are More Sophisticated Than Ever, With AI-Powered Attacks Posing the Greatest Risk – PR Newswire, 26th March 2024 4 UK Cybercrime Statistics 2024 – Twenty IT Services, 5th July 2024

A lot’s being said about artificial intelligence (AI) right now — particularly when it comes to security.

There’s the fact that 93% of Chief Information Security Officers (CISOs) believe that their organization will face daily AI-driven threats by the end of 2024.1 There’s the thought that 85% of security professionals attribute a recent rise in attacks to bad actors using generative AI2 and there’s the problem that around a third (35%) of organizations believe that they’re not equipped to deal with these kinds of attacks.3

As much as we hear about the dangers of AI, we also need to keep in mind that the same technologies have long been helping to keep organizations safe—and will continue to do so well into the future.

Today, the average Security Operations Center (SOC) is faced with a tidal wave of incoming information, data logs of such volume that it’s impossible to deal with them effectively. More than half a million new cyber threats are identified every day,4 and while SOCs might still be trying, they’re facing a losing battle to single out the 1% of traffic that demands human intervention.

Offence and Defense: How AI is countering the threat of AI

1

At its core, this all comes down to a problem of scale. To deal with threats effectively, SOCs need to be able to:

a) understand the typical trends across their traffic ecosystem—connections, dataflows, addresses, destinations—and analyze them based on a “margin of normality”.

b) understand what “normal” looks like in the first place. So, as well as handling their own flow of information, SOCs need to understand what’s happening out in the wider world, too.

These are not trivial challenges, and the rise in AI-driven threats is only making them harder to tackle. Because of that, we’re now at the point at which the only real way for organizations to protect themselves is to fight fire with fire —or, in this case, AI with AI.

Scale + speed = Superior Security Today, AI is often used as a blanket term. When people talk about it, nine times out of ten they’re actually talking about Generative AI (GenAI) rather than something like Machine Learning (ML) or Neural Networks. It’s important to be clear what we really mean when throwing around terms like “AI”, because when we’re specific it helps us get a much better handle on what a technology is really capable of.

Where GenAI is focused on the creation of text or images, for instance, a technology like ML is far more concerned with things like data analytics and pattern recognition, particularly at scale. It’s for those reasons that ML sits at the heart of Check Point’s own Threat Cloud AI—and has for more than a decade.

In simple terms, ThreatCloud is a repository of every ounce of information we have on current threats. It contains aggregated intelligence from every participating Check Point customer, complimented with data from the likes of internet service providers (ISPs) and indicators of compromise (IoC) from national cyber security centers too.

ML is critical here, because it gives us a way of analyzing a huge amount of data very rapidly. That in turn, allows us to make instantaneous decisions about the way that different factors are coming together.

Say you have an email that’s being sent to a specific endpoint. The email is then opened on a mobile device using Office 365. Subsequently, the endpoint connection takes a brand-new course of action - calling back home, for instance. In isolation, none of these behaviors are necessarily a problem. Combined, however, they might point to a potential security issue. That’s something that ML could flag way faster than a SOC operator ever could.

So, what ML gives us is not just the scale from which we can see the bigger picture, but also the speed to respond appropriately. And it’s for that reason that I think ML will also help security professionals add much greater value to proceedings going forwards.

Playing to each other’s strengths Today, most SOC operators are in the unenviable position of trying to address everything that comes in and automating very little. As technologies like ML become more prevalent, I believe that we have the opportunity to turn that dynamic on its head, freeing up talented resources to do more of what they excel at.

Despite its many strengths, one thing that ML (and AI as a whole) struggles with is context. As humans, we are uniquely blessed in being able to understand the context within which certain events are happening. Bots simply can’t. So, whereas a human might look at a situation and say “while everything technically looks okay, it still makes sense to block this connection,” a bot never would.

Because of that, the future I see isn’t one where AI is being used to combat AI-driven threats alone—but in tandem with the human operators who can make the right judgment calls at the right time. The scale and speed offered by AI will take us a long way, but it’s only through human expertise that we’ll truly succeed.

© 2024 Check Point Software Technologies Ltd. All Rights Reserved. 2


Item Type: pdf