Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Artificial Intelligence Just Got Intelligent (from HANDD Business Solutions)
Articles

Artificial Intelligence Just Got Intelligent (from HANDD Business Solutions)

ISBuzz TeamBy ISBuzz TeamApril 23, 20175 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

There’s a real buzz in the industry around artificial intelligence, machine learning, automated network monitoring and user and entity behaviour analytics (UEBA) at the moment. Artificial intelligence (AI) is not a new concept, but it appears that the mere mention of it conjures up an immediate element of fear amongst many. The reality is that AI and skilled individuals can be combined to create the most important aspect in an organisation’s defence in the war on cybercrime and here’s why.

More on User and Entity Behaviour Analytics (UEBA)
UEBA uses advanced analytics to baseline network activity to identify malicious behaviour from external sources, as well as insider threats. It does this by automatically learning what is normal based on typical activity and then, using proprietary algorithms, assigns risk scores to potential malicious behaviour. Alerts provide close to 100% accuracy enabling the SOC to operate far more efficiently and proactively, thus protecting a business before any threat becomes a major issue.

Doesn’t SIEM already do this?
Not even close; there is a major difference between security information and event management (SIEM) and UEBA. SIEM only throws up what a security team tells it to. It assumes that the security team is always aware of everything in the continually evolving threat landscape and is able to configure the product to alert when any one of those threats occur. With an infinite number of false positives possible for what is potentially NORMAL activity, the drain that it has on resources can end up doing more harm than good for an organisation’s security strategy.

UEBA, on the other hand, is signature-less and doesn’t require the use of human input thresholds, but instead learns what is normal activity, taking feeds from all applications (or in some cases, just network traffic) and only flags when something genuinely malicious has occurred. It’s important to note that any investment in SIEM isn’t a complete waste as it serves a huge purpose in centralising security events for monitoring and alerting, but just requires extra assistance to make it more efficient. Take UEBA solution provider, Securonix, for example. It can take a feed from an existing SIEM solution, as well as replace SIEM entirely, to create a more efficient, proactive breach monitoring solution.

Looking at this in practice, for example, someone accesses a job site, which in itself may not be a threat in isolation, but it would go under SIEM’s radar. Securonix’s Security Analytics Platform, can let you know from its DLP feed that this same user has also downloaded the entire customer database and then tried to email it out or save it to USB. This now raises the risk score, as there is a potential flight risk and a genuine insider threat.

Cyglass takes a slightly different approach with the monitoring of network traffic in order to detect rogue behaviour. It’s a subtle difference, as it monitors network traffic between applications and end points. It understands roles through Active Directory integration and looks at connections between devices on the LAN and WAN to detect rogue activity. It doesn’t monitor the feeds from SIEM, DLP or the Mail Gateway to aggregate the risk, it looks purely at the traffic and with whom communications are taking place. It is a proven military grade technology that can support cloud-based analytics, as well as on premises.

SIEM is prone to human error and unimportant information overload, which can become a massive burden as it requires expensive security experts to spend thousands of man hours sifting through millions of largely pointless alerts to find the one threat to act upon. Even then there is no guarantee that they will find the threat or certainly not any time soon.

UEBA not only throws up genuine alerts with a greater degree of accuracy, but most solutions have also developed (or are developing) ways of automating the shutdown of malicious activity so that the problem is nipped in the bud in near real-time. Darktrace has stolen a march having launched its Antigena product that replicates the “human immune system by creating digital antibodies” to shutdown malicious connections. This massively reduces the timeframe in which the security team responds to threats, which in turn can help support GDPR compliance notification requirements.

Market leader, Forcepoint has also made a huge investment in its security offering with the transfer of SureView from Raytheon to become “Forcepoint Insider Threat”. Taking feeds from the existing DLP platform, the march toward a “single pane of glass” to monitor insider threats has taken huge steps forward in recent months.

Microsoft has also emphasised the importance of AI with the inclusion of an Advanced Threat Analytics (ATA) component in its recently launched Enterprise Mobility Suite.

What will happen to the workforce?
Those working in security need not fear AI; in fact, recent experience tells us that one of the most critical concerns among the UK’s leading banks is the lack of resource and shortfall of skills available in the security industry. UEBA doesn’t mean “replacing all the people”; in fact it’s quite the opposite.

UEBA frees up resource to concentrate on doing the things that humans need to do, such as working on the security strategy, applying patches, fixing vulnerabilities, responding to threats, training, skilling up, etc. UEBA helps to address some of that shortfall, while adding that extra efficiency required to bolster defence capabilities. Skilled security people are in demand, so allow them to do the jobs they were employed to do.

By working effectively together, AI and a skilled security team can be the most important tools in the war on cybercrime. By allowing them both to do the job they were designed to do will ensure an organisation’s security strategy operates more efficiently than ever before.

[su_box title=”About Danny Maher” style=”noise” box_color=”#336588″][short_info id=’101698′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}