a.i. led security€¦ · spectre is harder to exploit than meltdown, but it is also harder to...

18

Upload: others

Post on 13-Aug-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4
Page 2: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4

A.I. Led Security Steve Grobman, McAfee

Page 3: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4

Steve GrobmanSVP & Chief Technology Officer

McAfee

Page 4: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4

New Attack Methodologies Create New Challenges

Page 5: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4
Page 6: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4
Page 7: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4

Artificial Intelligence

Machine Learning

Deep Learning

Page 8: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4

Ideally suited for a wide range of cyber security defense use cases…

Page 9: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4

Detection rate: 88.65%False Positive rate: 0.00%

Threat Intelligence driven security

Page 10: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4

Detection rate: 97.42%False Positive rate: 9.67%

Machine Learning driven security

Page 11: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4

Detection rate: 98.86%False Positive rate: 0.38%

Threat Intelligence + M.L. driven security

A.I./ML

ThreatIntelligence

Page 12: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4
Page 13: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4
Page 14: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4

Adversarial Machine Learning

(~100%) (~50%) (<1%)

Page 15: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4

Artificial Intelligence “Black Box Duality”

• Detect Previously Unseen Attacks

• Non-Deterministic

• Often Unable to Explain “Rationale for the conclusion”

• False Positives and False Negatives are inherent

Page 16: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4

In comparison to traditional risk measurement; the focus is on probability instead of possibility

Business Function 5

Business Function 4

Business Function 2

Business Function 3

Business Function 1

Page 17: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4

One final thought

NIST physicists used three beryllium ions to demonstrate a crucial step in a procedure that could enable future quantum computers to break today's most commonly used encryption code

…We must act now!!

Page 18: A.I. Led Security€¦ · Spectre is harder to exploit than Meltdown, but it is also harder to mitigate However, ... 2-0 f i O q 6 Y 32 s 3 93001 q S 34 73 q 668 c 487 go q / 4