Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Applying AI To Access Management
Articles

Applying AI To Access Management

ISBuzz TeamBy ISBuzz TeamMarch 31, 20174 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Secure Access Edge Service (SASE)
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

A branch of artificial intelligence is showing real promise for one of cybersecurity’s biggest challenges.

Administrators trying to secure networks have a big problem, speed. Computer systems deal with traffic on a per-second basis, and security algorithms must spot attacks in that traffic in real time to stop intruders sneaking in unnoticed. That makes cybersecurity difficult for administrators to handle.

This is where a branch of artificial intelligence known as machine learning can help. It applies a new data processing approach to the tasks facing security administrators, helping to prevent account misuse.

The need for real-time analysis is becoming an increasing problem in identity and access management (IAM). An IAM system manages user identities and ensures that they have access to only the applications and data that they need. It stops a junior sales rep from accessing information about the customers not assigned to her, but lets the VP of sales examine the entire customer list, for example.

IAM may stop users from abusing accounts beyond their pay grade, but what happens if an attacker steals a user’s account credentials? This happens all the time, both in the consumer and enterprise worlds. A Forrester report on data breaches in 2016 revealed the compromise of one billion records during the year.

These compromises would have spanned the consumer and enterprise sectors, but even the theft of consumer accounts can lead to the compromise of enterprise ones, as people often reuse their passwords. Once attackers have access, they have the same privileges as the user that they stole from, which puts enterprise data and applications at risk.

Administrators could code rules to try and stop unauthorised logins. The obvious approach is to figure out how users should be accessing the network, and then establish rules that stop them doing anything else.

In practice, though, a world of flexible working, remote contractors and changing business conditions means that access patterns vary between employees, and evolve over time. That makes it more difficult for IT administrators to define rules accurately and keep them up to date.

This is where machine learning comes in. Rather than hand coding these rules individually, companies can instead use these algorithms to ‘learn’ how users behave over time.

Machine learning software takes an original approach to processing data. Instead of following explicit step-by-step rules to analyse each new piece of data in the same way, it makes the computing equivalent of a judgement call, based on data that it has already seen. Programmers ‘teach’ machine learning software to look for certain characteristics in data by feeding it lots of historical information up front.

Feed a machine learning algorithm many audio recordings of people saying ‘hello’, for example, and it will find common data patterns in those recordings. It will search for these patterns in any new audio that it hears, and identify the phrase when spoken.

Companies are already applying these pattern-matching capabilities in many areas. Machine learning software is recognising images and detecting speech. It is approving loans based on patterns of consumer behaviour, and helping to spot financial fraud.

The characteristics of these algorithms map nicely to the IAM problem. A machine learning tool can analyse historical access data from an IAM system, such as who accessed an application, when they accessed it, and from where. Other data such as what they specifically requested access to, and from which device, can also help to refine these models.

Just as machine learning algorithms can learn what a face looks like, they can also learn what normal access patterns look like. This then produces a level of confidence in an access request that administrators can use to help quantify the risk of unauthorised account usage.

Machine learning-enhanced IAM systems can be highly granular, varying their confidence levels based on individual users, without requiring high-maintenance fine-grained rules. Instead, the machine learning algorithm can apply these confidence scores in real time to make smarter decisions.

The IAM system might allow someone access using basic authentication mechanisms if their score doesn’t deviate beyond a certain point, for example. On the other hand, it might escalate the security process if the access pattern seems too unusual.

We may not be able to stop cybercriminals from stealing user accounts using phishing, database hacks or device theft, but we can at least make it more difficult for them to use those account credentials in any meaningful way. Using artificial intelligence, we can spot when a malicious actor is trying to misuse a system by watching for unusual behaviour – and then lock the account down. It’s a good example of applied AI in action.

[su_box title=”About Andy Heather” style=”noise” box_color=”#336588″][short_info id=’101394′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}