Home Blog Page 137

Verizon’s Chatbox Flaw Leaks Customers’ Personal Information

Verizon’s Chatbox Flaw Leaks Customers’ Personal Information

Verizon Communications, an American telecommunications company, has been found exposing customers’ personal data for months due to a technical glitch in its chatbox on the company’s website. As reported by Ars Technica, the vulnerability is making the chat window display the conversations between Verizon’s employees and customers. Customers’ personal details such as transcripts, full names, phone numbers, addresses, account numbers, etc., are displayed when users click on a link to chat.

While it is unknown when Verizon’s chatbox began leaking the data, the company stated that it is notifying the users about the data leak as a precautionary measure.

“We are looking into an issue involving our online chat system that assists individuals who are checking on the availability of Fios services. We believe a small number of users may have seen a name, phone number, and/or a home or building address from an unrelated individual who had previously used this chat system to enter that information. Since the issue was brought to our attention, we have identified and isolated the problem and are working to have it resolved as quickly as possible,” Verizon said.

Not the First Time!

It is not the first time Verizon has exposed customers’ private details. In December 2019, the company suffered a massive data breach that occurred due to an error from a third-party contractor. The incident exposed personal information of hundreds of thousands of Verizon subscribers on unprotected public cloud servers. Around 261,300 documents were exposed on the server hosted by Amazon Web Services (AWS). The leaked information included phone bills, subscriber name, address, phone numbers, call histories, bank statements, screengrabs of usernames, passwords, and PIN numbers. Read the full story here…

XRSI launches XR Safety Awareness Week

XRSI

Commencing today (December 7, 2020), XR Safety Initiative (XRSI), a not-for-profit Standards Developing Organization (SDO), has launched the first annual XR Safety Awareness Week to celebrate XR with a focus on issues like child safety, diversity & inclusion, medical XR, media & art, etc.

“As the founder CEO of the XR Safety Initiative (XRSI), an organization dedicated to helping build safe immersive environments, my bigger worry these days is about the diversity and other biases creeping into our emerging technologies, including machine learning and artificial intelligence, said Kavya Pearlman, CEO and founder of XRSI, in an exclusive interview with CISO MAG.

Pearlman continued, “While we have not even fully addressed the cybersecurity challenges with existing technologies, a whole new wave of emerging technologies including virtual, augmented and mixed reality (collectively known as XR), Brain-computer Interface (BCI) and rollout of 5G communication infrastructure is bringing a whole new set of novel cybersecurity challenges that we need to address as soon as possible. It is imperative that we get more women and minorities involved: it is the only way we will be able to close some of the identified gaps in the existing and emerging domains of technologies.”

What is XR Safety Awareness Week?

The XR Safety Awareness Week is an annual event, which is both a celebration of the many different facets of XR, and an opportunity for individuals, organizations, policymakers, and institutions to find a platform for promoting ideas and thought leadership, which will guide us towards a safer future with XR technologies. While getting into XR might seem as straightforward as putting on an HMD or holding up a phone to view Augmented Reality (AR) content, cultivating a sense of awareness is imperative. XR Safety Awareness Week is to encourage everyone to get into XR “With Awareness,” independent of the use case platform or experience.

Egregor Ransomware Hits HR Agency Randstad

Ransomware attacks, ransomware, Sinclair Broadcast group

Popular staffing company Randstad has suffered a ransomware attack in which threat actors stole unencrypted files from its network. In an official release, the HR agency stated that the Egregor ransomware group illicitly obtained access to the company’s global IT environment, which affected certain servers.  The incident impacted operations in the U.S., Poland, Italy, and France offices.

While there is no information on what data has been accessed by attackers, the company stated that its systems are running without interruption and there has not been any disruption in operations. Randstad has engaged third-party cybersecurity and forensic experts to investigate the incident. The company also highlighted that malicious actors have become highly sophisticated and aggressive in recent months, resulting in numerous cyberattacks on organizations globally.

“Prompt global action was taken to mitigate the incident while further protecting Randstad’s systems, operations, and data. As a result, a limited number of servers were impacted. Our systems have continued running without interruption and there has not been any disruption to our operations. Based on our current investigation, there is no indication that any third-party systems were impacted. Relevant regulatory authorities and law enforcement agencies have been notified,” Randstad stated.

Egregor Targeting Global Firms

Cybersecurity researchers from Appgate recently stated that the Egregor ransomware variant is targeting organizations globally to encrypt files that hold sensitive information. Egregor seems to be derived from the Sekhmet malware family. The threat group uses code obfuscation and packed payloads to escape security detection. The researchers also found Egregor’s news website, hosted on the dark web, is used for leaking stolen data and other malicious activities. Read the full story here…

Five Key Cybersecurity Lessons from SecOps

Cyber security operations

Security Operations (SecOps) team members have interesting stories to tell about their run-ins with cyber adversaries. Some of these professionals have built and run Security Operations Centers (SOCs) for some of the world’s largest companies. They’ve seen daily incidents that they strive to address and resolve. And from these war stories comes a fundamental understanding of some of the best practices to fight cybercriminals.

By Chris Triolo, Vice President of Customer Success, Respond Software

1. Pay attention to lateral attacks

The steady flow of news articles about vulnerabilities in IoT devices may seem like hyperbole, but the reality is that the risk continues to grow. In fact, during a recent proof-of-concept I worked on, an organization detected evidence of lateral movement from an IoT device (in this case, a network of security cameras) to other systems in the environment. Lateral movement is a technique where an attacker breaks into one system and uses that as a beachhead to move on to other systems in the environment. In this case, their physical security camera systems were on the same network as systems managing critical data. A best practice is to monitor all devices on the network and ensure appropriate network segmentation so that critical systems would never be on the same network as IoT devices like security cameras and smart TVs.

2. Don’t make assumptions when you tune

Another company I spoke with recently found a Zeus infection within their network. Infected internal systems were reaching out to known malicious IPs. The company had seen so many of these alerts that they assumed they were false positives and began disabling the intrusion detection signatures – that is, tuning down the sensors. Eventually, they found evidence that these “false positives” were real, re-enabled the signatures, and took action to clean up the infected systems.

3. Infected systems need cleaning

It’s a common occurrence for systems to be infected with malware and “beacon out”—that is, they’re communicating with attacker systems outside the network. In some cases, the customer who has already anticipated this situation has technology controls in place that drop or block the traffic on its way out of the network so that the internal system can’t reach out to the external system of the attackers. Some organizations will say, “No problem! The traffic is blocked; I’m safe.” However, that still leaves them with a compromised or infected system inside the network that needs to be cleaned.

Just because the malicious traffic is blocked, doesn’t mean it can be ignored. What if the system is a laptop and is taken home (out of the office) where it’s no longer protected? There’s nothing to stop it from communicating with the attacker’s system when on the employee’s home Wi-Fi.

4. Watch out for misconfigurations

Organizations also must regularly deal with security sensors that don’t work as expected. The solution is to catch misconfigurations and ensure that security controls are working as they should. For instance, pay attention to traffic volumes. What if they are unusually low–too low for normal URL traffic? If there is not enough user activity for this size of the environment, review the configurations on the URL Filtering software; it is most likely misconfigured. Once fixed, SecOps teams are better able to detect malicious and actionable security incidents that need an incident response. This makes the difference between a company thinking it is protected and being protected.

Daily, a typical environment will have more than 300 unique IDS signature alerts. Dramatic changes in this can be indicative of problems. For instance, let’s say a company had only 30 unique signature alerts on a day. This could indicate that their IDS was misconfigured or over-turned, so the company reviewed its configs, made updates, and began seeing normal volumes of IDS traffic. The company started catching the bad guys again, escalating new incidents once the fix had been made.

It is important to consistently make sure that the sensor grid is working. Pay attention to expected traffic volumes and signature feeds, and when there are anomalies, investigate.

5. Be careful about whitelisting

By constantly monitoring a company’s incident, discovery solution, one can catch pen-test and red team activity of its own defense testing. Interestingly enough, companies with a managed security service provider (MSSP) or internal security team typically miss the tell-tale signs. Here’s the interesting part: since this is just testing and not actual, malicious traffic, companies often want to “whitelist” the system(s) conducting pen-tests or red teams, as they are not real incidents. The best practice is to not whitelist these systems because it’s a great way to prove the incident discovery solution is working; and it’s good to test security controls and security detection capabilities regularly.

Benefit from SecOps Wisdom

It’s clear that many things can go wrong when defending against malicious actors, but cybersecurity is something organizations must get right. Fortunately, many dedicated SecOps professionals have learned valuable lessons to draw from. Use the best practices outlined above to pay attention to the details, properly configure the system, and ensure a clean, well-tuned, and secure network.


About the Author

Chris Triolo is the Vice President of customer success at Respond Software. His security expertise includes building world-class professional services organizations as Vice President of professional services at ForeScout and Global Vice President of professional services and support for HP Software Enterprise Security Products (ESP). Triolo’s depth in security operations and leadership includes a long tenure at Northrop Grumman TASC supporting various Department of Defense and government customers including Air Force Space Command (AFS PC) Space Warfare Center, United States Space Command (USSPACECOM) Computer Network Attack and Defense, Air Force Information Warfare Center (AFIWC), and others.

Disclaimer

CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

Securing Health Care’s Digital Transformation: The Rise of Enterprise Cyber Risk Management Software

Healthcare Data Breaches, Premier Diagnostics data exposed

The digital transformation of health care is driving the adoption of new technology and information systems to support key business and clinical initiatives. We are experiencing a veritable explosion in health care data, systems, and devices. Health care data has grown by 878% since 2016, and the number of endpoints from which it can be accessed is growing exponentially. It is estimated that 25,000 petabytes of health care data will be online by 2020. The Internet of Medical Things (IoMT) is expected to grow to more than 50 billion devices by 2021. In addition to external devices like wireless IV infusion pumps or heart monitors that may be attached to our patients, the IoMT includes wireless implantable devices such as deep brain neurostimulators, cochlear implants, gastric stimulators, cardiac defibrillators/ pacemakers, foot drop implants, and insulin pumps. Health care data, systems, and devices are more voluminous, more visible, more valuable, and, at the same time, more vulnerable than ever.

By Steve Cagle, CEO, Clearwater

The Explosion of Health care Data, Systems and Devices…and Compromises

According to one survey, more than one in three health care organizations have suffered a cyberattack while one in 10 have paid a ransom. In terms of vulnerability, in its April 2014 Private Industry notification, the FBI wrote, “The health care industry is not as resilient to cyber intrusions compared to the financial and retail sectors; therefore, the possibility of increased cyber intrusions is likely.”

We have certainly seen evidence of that over the last five years. These continuing trends are resulting in even greater cyber risk exposures for health care organizations. In the first half of 2019, there were 285 reported breaches affecting 32 million individuals, more than double the total for all of 2018 .

In the wake of so many largescale data breaches, the Office for Civil Rights (OCR) has stepped up HIPAA enforcement, levying a record $28.7 million in fines in 2018, representing an increase of almost 50% over 2017. Comprehensive, high-quality risk analysis and risk management are among the highest areas of their focus, as OCR official Nick Heesters recently commented: “Some of the risk analysis we get back just doesn’t really reflect what the rule requires. The rule requires that it be done in an accurate and thorough manner. To accurately and thoroughly assess the risks to an organization’s ePHI. Frankly, that’s not what we get.”

Risk Analysis Failures and Enforcement

As of this writing, an analysis of 66 OCR Enforcement Actions indicates there were 48 cases involving electronic Protected Health Information (ePHI) where risk analysis and risk management were to have been performed by the organization who suffered the breach. In those 48 cases, OCR found 43 organizations or 90% had not completed OCR-quality risk analysis. Forty of the 48 (83%) had adverse findings when it came to risk management. To date, OCR has collected $106.9 million in negotiated settlement amounts and civil money penalties.

State attorney generals are becoming much more active in investigating data breaches and are now banding together to initiate multi-state suits.

They are working in coordination with OCR and bringing their own actions against health care organizations that have violated HIPAA regulations, including most recently in cases where there has been a failure to conduct a risk analysis, such as the aforementioned MIE case that resulted in an additional $900,000 being paid out in a multi-state lawsuit involving 16 State AGs. Of the 21 State AG enforcement actions that have occurred over the last few years, 16 of them (76%) involved ePHI.

In addition to satisfying regulatory requirements, there is a growing need for health care organizations to understand where their highest exposures are in order to ensure they are protecting their assets appropriately by prioritizing and investing in the most optimal security controls to maximize their limited budgets.

Despite 82% of hospitals reporting breaches, only 5% of hospital IT budgets go to cybersecurity. Financial services, which are considered much more mature in Cyber Risk Management (CRM), spend 7.1%. Miniscule budgets and limited cybersecurity staff make it critical for hospitals to ensure they focus resources on mitigating their highest risks. A hospital or other health care provider can only be certain it is implementing the right controls if it knows where it has gaps.

Enterprise Cyber Risk Management Software (ECRMS): A Better Way to Manage Cyber Risk

In response to growing threats, increased regulatory scrutiny, and customer demand, leading health care organizations are recognizing that traditional approaches to assessing and managing cyber risk are not effective. A well-designed information security program begins with an enterprise risk analysis that assesses vulnerabilities and risks that apply to each and every information system that maintains protected health information. It continues with an integrated risk management program, which tracks and manages risk remediation action items that ultimately reduce risk to acceptable levels.

Until recently, most health care organizations have struggled to execute an enterprisewide, information system-based risk analysis and risk management program as they have lacked the software tools and methodologies to do so.

Without a system in place to identify and remediate high risks, these organizations face the very real potential of experiencing a preventable compromise of health care data, systems, and devices, which can lead to fines, lawsuits, legal and other fees, disruption in operations, reputational damage, and loss of customers.

Many health care organizations struggle to:

  • Maintain an inventory of their health care data, systems, and devices – many have not even identified their “crown-jewel” information assets
  • Establish a common definition of risk and their cyber risk appetites
  • Perform risk analysis on all information systems across the enterprise
  • Assess the likelihood and impact of asset-vulnerability-threat scenarios relevant to their systems
  • Retain a single source-of-the-truth for risks
  • Track and manage risk mitigation action items effectively
  • Report on the progress of risk analysis and risk response to governance functions
  • Treat CRM as a continuous process

Managing cyber risk in health care today is complex. Risk presents itself in an ever-changing threat landscape, filled with bad actors who don’t play by the rules. A health care organization trying to manage this cyber risk without software designed for this purpose is no better off than one who is trying to manage payment processing, payroll, or electronic medical record-keeping with spreadsheets.

A best-in-class ECRMS platform not only facilitates compliance with regulations, but also creates the basis for a comprehensive, integrated, and holistic approach to identifying, managing, and reducing cyber risk across the evolving health care IT ecosystem. Deploying an ECRMS in a health care organization is no longer an option—it is a necessity in order to maintain secure operations in today’s increasingly digitized health environment.


About the Author

Steve CagleSteve Cagle is CEO of Clearwater, the leading provider of Enterprise Cyber Risk Management and HIPAA Compliance software and services for the health care industry. Clearwater’s IRM|Pro® software and consulting services help health care organizations avoid preventable breaches, protect patients, and meet OCR’s expectations while optimizing and prioritizing cybersecurity investments.

Disclaimer

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

 

These are the Top Security Concerns and Cyberthreats Globally

microsoft, flaws in SonicWall SRA SMA

A survey from cloud security provider Trend Micro revealed that 23% of organizations globally suffered seven or more cyberattacks. Nearly 83% of organizations surveyed stated that most of the potential attacks are “somewhat” to “very” likely to be successful in the coming year. The survey highlighted the security gaps among organizations by measuring their current security posture and their likelihood of being attacked.

According to Trend Micro’s Cyber Risk Index (CRI), organizations listed their Top Cyberthreats  globally, which include:

  • Phishing and social engineering
  • Clickjacking
  • Ransomware
  • Fileless attacks
  • Botnets
  • Man-in-the-middle attacks

 Key concerns of organizations globally:

  • The loss of customer data
  • Access to IP and financial information
  • Customer churn
  • Stolen or damaged equipment

The Top Security Risks within IT infrastructure include:

  • Organizational misalignment and complexity
  • Negligent insiders
  • Cloud computing infrastructure and providers
  • Shortage of qualified personnel
  • Malicious insiders

Jon Clay, director of global threat communications for Trend Micro said, “The CRI is fast becoming an indispensable resource for CISOs looking to assess their readiness to respond to cyberattacks. This year we have added data from Europe and APAC to provide truly global insight. It will help organizations across the world find better ways to cut through complexity, mitigate insider threats and skills shortages, and enhance cloud security to minimize cyber risk and drive post-pandemic success.”

Defending Cyberattacks in the Pandemic

A similar survey revealed that businesses across the globe are implementing new cybersecurity measures to prevent security incidents during the pandemic. Despite rising cyberthreats due to remote work, nearly 34% of employees in the U.S. stated that their companies did not practice basic cybersecurity protocols. Read the full story here…

FINRA Alerts About Yet Another Phishing Campaign Using Imposter Domain

Phishing Campaign on FINRA

The U.S. Financial Industry Regulatory Authority (FINRA) warned its brokerage firms about an ongoing phishing campaign targeting users to steal personal information. In a security alert,  FINRA stated that malicious actors are sending fraudulent emails to users with a source domain “@invest-finra.org.” FINRA has asked users to verify the legitimacy of the email before downloading any attachments or clicking on any links, and also requested the Internet domain registrar to suspend services for the invest-finra.org.

FINRA is a non-profit organization supervised by the Securities and Exchange Commission (SEC) that regulates member brokerage firms and exchange markets in the U.S.

A Homoglyph Technique?

Attackers are impersonating FINRA members by using their real names and images to trick users into believing that they are legitimate.  This technique is used in a homoglyph attack, where, cybercriminals misuse the similarities of character scripts to create phony domains of existing brands to trick users into clicking on fraudulent emails.  A homoglyph is one of two or more characters or glyphs with shapes that appear identical or very similar.

FINRA has asked users to delete all emails originating from “invest-finra.org.”

Not the First Time

Earlier, FINRA stated that attackers used registered brokers’ data to create phishing emails and imposter websites. The fake emails were embedded with phishing links or malicious attachments that contained malware. Several members fell victim to these sites, compromising their personally identifiable information (PII) like names, email addresses, and contact details. Read the full story here…

NTreatment Exposes Thousands of Health Records and Lab Results in a Security Lapse

NTreatment health records exposed

In a cloud storage security lapse, NTreatment exposed around 109,000 files that contained health records and lab results.

The said cloud server was hosted on Microsoft Azure.

NTreatment, a U.S.-based health tech company, experienced a security lapse on one of its cloud storage servers hosted on Microsoft Azure, which lacked password protection. The incident exposed around 109,000 files that contained health records, doctors’ notes, insurance details and claims, lab results, and much more. NTreatment, if proven guilty for the lack of basic security protocols, can attract a hefty fine from the Health Insurance Portability and Accountability Act (HIPAA).

Reason Behind the Lapse

NTreatment provides electronic health records (EHR) maintenance services for doctors based in the U.S. The lapse was found when researchers from TechCrunch stumbled upon the trove during a separate investigation. However, with the amount of PII being exposed, they decided to investigate it deeper. Researchers found three astonishing findings:

  1. The Microsoft Azure server used to store the data that did not have any password.
  2. None of the data discovered on the server was encrypted.
  3. All the exposed data could be easily viewed in any browser.

Related News:

Jackson Health’s HIPAA Violation Costs US$ 2.15 million fine

NTreatment’s exposed data contained the following set of information:

  • Lab test results from third-party providers like LabCorps.
  • Medical records, doctors’ notes, insurance claims, and other sensitive health data of patients having tie-up doctors and healthcare providers using NTreatment HER services.
  • Company’s internal documents, including a non-disclosure agreement (NDA) with a prescription provider.

TechCrunch’s researchers reached out to NTreatment to get the issue fixed to which they responded promptly. For the time being, any exploitation or download of the said data is not known. However, the set of data exposed included a certain subset of information, which is deemed highly protected under the HIPAA. Although they have dodged the bullet from threat actors, the researchers believe that NTreatment can be slapped with a heavy fine.

Related News:

Failure in HIPAA Compliance Costs URMC $3 million fine

Everything You Need to Know About NZ’s New Privacy Act 2020

American Cybersecurity Literacy Act

The New Zealand government introduced the New Privacy Act 2020 (NZ), on December 1, 2020, which brings several reforms in the way organizations collect, use, and manage users’ data. The new legislation will replace the existing Privacy Act 1993 (NZ).

The new privacy laws impose strict rules on data protection, it mandates businesses to report data breaches immediately. The New Privacy Act 2020 will apply to all organizations and cloud computing providers based in New Zealand as well as overseas companies that collect information related to New Zealanders.

What the New Privacy Act Covers

  • Whether the Privacy Act effectively protects personal information and provides a practical and proportionate framework for promoting good privacy practices
  • Whether individuals should have direct rights of action to enforce privacy obligations under the Privacy Act
  • The impact of the notifiable data breach scheme and its effectiveness in meeting its objectives
  • Whether a statutory tort for serious invasions of privacy should be introduced into Australian law
  • The effectiveness of enforcement powers and mechanisms under the Privacy Act and how they interact with other Commonwealth regulatory frameworks
  • The desirability and feasibility of an independent certification scheme to monitor and demonstrate compliance with Australian privacy laws

Penalty for Non-Compliance

As per the Privacy Act 2020, enterprises could be fined up to NZ$10,000 ($7,000) for violating the data protection laws. The Act allows the Office of the Privacy Commissioner (OPC) to raise the penalty to NZ$230,000 ($162,000). The OPC can also investigate an organization concerning security incidents or data protection practices.

Recently, the New Zealand government also launched its new data breach reporting tool “NotifyUs” to help organizations report data breaches and assess whether a security incident is notifiable or not.

Security Evolution: From Legacy to Advanced, to ML and AI

Artificial Intelligence

AI and ML present a new dawn in the cybersecurity industry. AI is not a new concept to computing. It was defined in 1956 as the ability of computers to perform tasks that were characteristic of human intelligence. Such tasks included learning, making decisions, solving problems, and understanding and recognizing speech. ML is a broad term referring to the ability of computers to acquire new knowledge without human intervention. ML is a subset of AI and can take many forms, such as deep learning, reinforcement learning, and Bayesian networks. AI is poised to disrupt the cybersecurity space in many ways in what might be the ultimate win for the cybersecurity industry against cybercriminals.

By Dr. Erdal Ozkaya, MD & Regional CISO of a Global Bank

AI/ML in cybersecurity involves deploying self-sufficient tools that can detect, stop, or prevent threats without any human intervention. The detection of threats is done based on the training that the algorithm in the security tool will have undertaken on its own, and the data already supplied by the developers. Therefore, throughout its life cycle, an AI-powered security tool will become better at detecting threats. The original dataset of threats provided by developers will provide a reference base that it can use to know what is normal and what is malicious. The security tool will then be exposed to insecure environments before final deployment. In the environments filled with threats, the system will continually learn based on the threats that it detects or stops. Hacking attempts will also be directed at it. These attempts will involve hacking or attempts to overwhelm its processing capabilities with lots of malicious traffic. The tool will learn the most commonly used hacking techniques for breaching systems or networks. For instance, it will detect the use of password-cracking tools such as Aircrack-ng on wireless networks. Similarly, it will detect brute-force attacks on login interfaces. The main role that will be played by humans in cybersecurity will be to update the algorithms of the AI tools with more capabilities.

AI security systems will possibly contain all threats. Conventional security systems are usually unable to detect threats that exploit zero-day vulnerabilities. With AI, even after evolving and adapting new attack patterns, malware will not be able to penetrate the AI system. The system will check the code being run by the malware and predict the outcome. Outcomes that are deemed to be harmful will cause the AI system to prevent the program from executing. Even if the malware obfuscates its code, the AI system will keep tabs on the execution pattern. It will be able to stop the program from executing once it attempts to carry out malicious functions such as making modifications to sensitive data or the operating system.

It is already projected that AI will overtake human intelligence. Therefore, a foreseeable point in the future will see all cybersecurity roles moved from humans to AI systems. This is both advantageous and disadvantageous. Today, when an AI system fails, the results are normally tolerable. This is because the scope of operations played by AI systems is still limited. However, when AI finally overtakes human intelligence, the results of a failure in the systems might be intolerable. Since the security systems will be better than humans, it is possible that they will be in a position to refuse input from humans. A malfunctioning system might, therefore, continue operating without any interventions. The perfectionist nature of AI will be both good and bad. Current security systems work toward reducing the number of attacks that can succeed against a system. However, AI systems work toward eliminating all threats. Therefore, false-positive detection might not be considered as such; they might be treated as positive detection and thus cause disruptions in the affected harmless systems that are stopped from executing.

Lastly, there are fears that the integration of ML and AI into cybersecurity might lead to more harm than good. As has been observed over the years, attackers are resilient. They will always try to find ways to beat a cybersecurity system. Normal cybersecurity tools are beaten using more sophisticated methods than the tools are aware of. However, the only way to beat AI will be to confuse it. Therefore, threat actors might infiltrate AI training systems and provide bad datasets, thus affecting the knowledge acquired by the AI-backed security systems. The actors might also create their own adversarial AI system to even the playing field. This would result in an AI versus AI battle.

Lastly, hackers might still use methods that circumvent AI security systems. Social engineering can still be carried out physically. In such cases, AI systems will not be able to help the target. Shoulder surfing—the simple act of looking over someone’s shoulder as they enter crucial details—is also conducted without the use of hacking tools. This also circumvents the security system. Therefore, AI and ML might not be the ultimate answer to cybercrime.

This article has looked at the evolution of cybersecurity from legacy to advanced and then on to futuristic technologies such as AI and ML. It has been explained that the first cybersecurity system was an antivirus system that was created to stop the first worm. Cybersecurity then followed this example, where security tools were created as responses to threats. Legacy security systems started the approach of using signature-based detection. This is where security tools would be loaded with signatures of common malware and use this knowledge base to detect and stop any program that matched the signature. However, the security systems were focused on malware, and thus, hackers focused on breaching organizations through the network. In 1970, an OS company was breached via its network and a copy of an OS was stolen. In 1990, the US military suffered a similar attack where a hacker broke into 97 computers and corrupted them. Therefore, the cybersecurity industry came up with stronger network security tools. However, these tools still used the signature-based approach and thus could not be trusted to keep all attacks at bay.

In the 2000s, the cybersecurity industry came up with a new concept of security where it advised organizations to have layered security. Therefore, they had to have security systems for securing networks, computers, and data. However, layered security was quite expensive, yet some threat vectors were still infiltrating computers and networks. By 2010, cybercriminals started using threats called advanced persistent threats. Attackers were no longer doing hit-and-run attacks; they were infiltrating networks and staying hidden in the networks while carrying out malicious activities. In addition to this, phishing was revolutionized and made more effective. Lastly, there was another development where attackers were using DoS attacks to overwhelm the capabilities of servers and firewalls. Since many companies were being forced out of business by these attacks, the cybersecurity industry developed a new approach to security, known as cyber resilience. Instead of focusing on how to secure the organization during attacks, they ensured that organizations could survive the attacks. In addition to this, users became more involved in cybersecurity where organizations started focusing on training them to avoid common threats. This marked the end of security 1.0.

The cybersecurity industry then moved to the current “security 2.0”, where it finally created an alternative to signature-based security systems. Anomaly-based security systems were introduced and they came with more efficiencies and capabilities than signature-based systems. Anomaly-based systems detect attacks by checking normal patterns or behaviors against anomalies. Apps and traffic that conform to the normal patterns and behaviors are allowed to execute or pass, while those that do not are stopped. While anomaly-based tools are effective, they rely on decisions from humans. Therefore, a lot of work still comes back to IT security admins. The answer to this has been to leverage AI with the hopes that such security systems will become self-sufficient.

AI sounds promising, though many doubts have been cast against it. AI and ML security tools will operate by detecting threats based on anomalies and taking informed decisions on how to handle these threats. The AI-security tools will have a learning module that will ensure that they only get better with time. Before deployment, these systems will be extensively trained using datasets and real environments that have real threats. Once the learning module is able to provide sufficient information to protect an organization from common threats, it will be deployed. One of the main advantages of AI security systems is that they will evolve along with the threats. Any new threats will be studied and thwarted. Despite the advantages of AI-powered security systems, there are worries that they may ultimately become harmful. As AI overtakes human intelligence, there might come a point where such tools will not accept any human input. There are also worries that attackers might poison the algorithms to make them harmful. Therefore, the future of AI in cybersecurity is not easy to foretell, but there should be two main outcomes: either AI-backed security systems will finally contain cybercrime, or AI systems will go rogue, or be made to go rogue and become cyber threats.

Artificial Intelligence and Cybersecurity

Enterprise customers around the world are investing in Artificial Intelligence and automation to improve their business processes, reinvent productivity, and improve operational excellence. Banks are looking into new ways of how to implement fraud detection in their ATM networks, insurance companies are exploring how to use Artificial Intelligence to predict the profitability of their services to the end customers, and brokers have started to apply Artificial Intelligence to predict stock market movements. The following diagram illustrates the reasons why business organizations are adopting worldwide Artificial Intelligence as of 2019:

Artificial Intelligence-powered cybersecurity

Almost all security vendors currently advertise that their technology has some sort of Artificial Intelligence. However, Artificial Intelligence comes in many variations and there are many underlying technologies. You will want to watch out for buzzwords that have been placed by marketing departments. It is not always clear what these security vendors are specifically doing with Artificial Intelligence, Machine Learning, and so on.

Building a security solution that is powered by Artificial Intelligence is challenging and requires investments. The costs include building the fundamental systems that are required to operate the technology, additional costs that are required for scaling the system in a hyperscale environment, and, lastly, there is a very limited pool of talents available in the market that have sufficient experience in working on Artificial Intelligence code and who are able to handle complex mathematical principles to create an efficient and scalable solution. Even if some companies can invest in the infrastructure and are able to hire these talents, Artificial Intelligence requires data—a lot of data to train the Artificial Intelligence. There are only a few companies in the world who actually have that amount of data. These companies need to have in-depth knowledge and data on the threat landscape, on digital identities, email accounts, web presence, and telemetry coming from endpoints and mobile devices. With that, companies like Apple, Google, Microsoft, Amazon, and Facebook have a clear advantage.

It is clear that Artificial Intelligence-powered security solutions will assist cybersecurity teams in many stages of defense. Narrow AI could be used to perform simple tasks such as searching for a specific Indicator of Compromise (IOC) in a threat intelligence database, all the way up to a super AI being self-aware and not only alerting the Security Operations Center (SOC) when it detects a cybercriminal trying to breach the environment, but also automatically adjust preventative security controls to prevent the breach from happening in the first place. Without any doubt, Artificial Intelligence-based security solutions will offer intelligent recommendations to the cybersecurity teams. The following screenshot illustrates the artificial intelligence-based security automation from the Microsoft Defender ATP solution:

Use Cases

There are five use cases that you will want to enable through Artificial Intelligence to improve your cyber hygiene and operational excellence, all of which are shown in the following diagram:

All of these use cases are fairly new and yet their full potential hasn’t been discovered by any security vendor. It is clear, however, that the benefits of Artificial Intelligence to fight cybercrime is critical and that security vendors are investing.

In summary, in this article we covered that Artificial Intelligence is not just Artificial Intelligence — there are many different technologies, use cases, and scenarios to take into account too. It is important to deeply understand what Artificial Intelligence is before jumping on the next call with the sales representative of a security vendor that tries to sell the world’s first Artificial Intelligence-based security solution. You are now able to ask smart questions such as is the Artificial Intelligence a Narrow AI or True AI capability? and when you say Machine Learning, is it supervised Machine Learning, Unsupervised Machine Learning, or semi-supervised Machine Learning? The key is not to get fooled and understand how technology can help you protect, detect, and respond against the ever-changing threat landscape. You will want to make sure that technology helps you to truly discover and remediate cyber-attacks as quickly as possible. The following diagram illustrates a project from MIT, of an Artificial Intelligence-based cybersecurity system that can detect 85% of cyber-attacks. However, this is only the beginning:


About the Author

Dr. Erda Ozkaya is a tenured cybersecurity professional and has juggled the roles of a security advisor, speaker, lecturer, and author. Having excelled in business development, management and academics focused on securing cyberspace, he is passionate about imparting knowledge from his hands-on experiences.

As an award-winning technical expert, Dr. Erda has received many accolades. His recent awards are the Cyber Security Professional of the year MEA, Hall of Fame by CISO Magazine,  Cybersecurity Influencer of the year (2019), Microsoft Circle of Excellence Platinum Club (2017), NATO Center of Excellence (2016) Security Professional of the year by MEA Channel Magazine (2015), Professional of the year Sydney (2014) and many speakers of the year awards in conferences. He also holds Global Instructor of the year awards from EC-Council & Microsoft.

Dr. Erdal has the following qualifications: Doctor of Philosophy in Cybersecurity, Master of Computing Research, Master of Information Systems Security, Bachelor of Information Technology, Microsoft Certified Trainer, Microsoft Certified Learning Consultant, ISO27001 Auditor & Implementer, Certified Ethical Hacker (CEH), Certified Ethical Instructor & Licensed Penetration Tester. He has also been a part-time lecturer at Australian Charles Sturt University and has co-authored many cybersecurity books, as well as security certification course-ware and examinations.

Disclaimer

CISO MAG did not evaluate the advertised/mentioned products, service, or company info, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the articles do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views are personal.