Security teams turn to AI to fight hackers

Cisco: CISOs rely on machine learning and automation to combat increasing threat volumes

Security teams are increasingly reliant on machine learning and AI tools to cope with the sheer volume of security threats they face, according to new figures.

More than 70% of 3,600 organisations across 26 countries said they were mostly or entirely reliant on AI, automation and machine learning in order to help cope with the amount of threats faced by businesses, according to Cisco's 2018 Security Capabilities Benchmark Study, released today.

The high volumes of intrusion attempts made on many organisations - in the UK, for example, councils face an average of 27 attacks per minute - often result in huge volumes of event logs, which can be impossible to sift through by hand. This task is made even more difficult by malware that uses encrypted traffic - in which Cisco researchers saw a 300% increase over 12 months.

Instead, many businesses are turning to AI tools, the network vendor claimed, because these can automatically learn what is and is not a normal event, and flag high priority items to security staff.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Similarly, behavioural analytics tools can automatically detect what a given user's normal behaviour is and can identify when an account is acting suspiciously, which may indicate a compromised account or a malicious insider. A total 92% of security professionals said these tools work either very or extremely well.

In order to try and cope with the growing breadth and scale of attack attempts, organisations are deploying an increasing number of tools.

A quarter of respondents to the study reported using security products from between 11 and 20 vendors, an increase of 7% from the previous year. The number of organisations using between 21 and 50 vendors more than doubled, and 5% reported using more than 50 vendors' products.

"Last year's evolution of malware shows adversaries are becoming wiser at exploiting undefended gaps in security," said John N. Stewart, senior vice president and chief security and trust officer at Cisco. "Like never before, defenders need to make strategic security improvements, technology investments, and incorporate best practices to reduce exposure to emerging risks."

Featured Resources

What you need to know about migrating to SAP S/4HANA

Factors to assess how and when to begin migration

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

Best practices for implementing security awareness training

How to develop a security awareness programme that will actually change behaviour

Download now
Advertisement

Recommended

Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/policy-legislation/data-governance/354496/brexit-security-talks-under-threat-after-uk-accused-of
data governance

Brexit security talks under threat after UK accused of illegally copying Schengen data

10 Jan 2020
Visit/web-browser/30394/what-is-http-error-503-and-how-do-you-fix-it
web browser

What is HTTP error 503 and how do you fix it?

7 Jan 2020
Visit/infrastructure/server-storage/354476/broadberry-cyberserve-r182-z90-review-gigabytes-epyc-gamble
Server & storage

Broadberry CyberServe R182-Z90 review: Gigabyte’s EPYC gamble pays off handsomely

7 Jan 2020
Visit/operating-systems/microsoft-windows/354514/gchq-warns-against-windows-7-for-email-banking
Microsoft Windows

GCHQ warns against Windows 7 for email, banking

13 Jan 2020