How AI Really Works For InfoSec

It's been about 2 1/2 years now since I signed on with PatternEx and started learning how Artificial Intelligence (AI) fits into the complex cat-and-mouse game that is Infosec. About 6 months in, I had a wake-up call: : my expectations for what AI could do were vastly different from what was actually possible.

The Morning Paper Shares "AI Squared" Research

Adrian Coyler, former CTO of SpringSource and former CTO of Apps at VMWare (later Pivotal), is a venture partner at Accel Partners. He began to tweet about interesting research papers weekly but found the 140 character limit was not always enough to comment properly about the research. He moved longer summaries and commentary to his blog, "The Morning Paper."

Cyber Security and AI-Squared

Monday of this week, MIT put a spotlight on a paper co-written by researchers from PatternEx and MIT CSAIL. The paper compared PatternEx's Active Learning approach with state-of-the-art Anomaly Detection approaches, and had two important conclusions:

  • It is possible for an AI system to automatically adjust its models over time based on human feedback and improve detection capability
  • AI systems using these techniques detect far more attacks with far fewer alerts than solutions based solely on Anomaly Detection

The Goal of PatternEx

Our goal, when founding PatternEx, was to develop a system that mimics a human InfoSec Analyst’s intuition and expertise in real time and at scale.

