AI in Cybersecurity

Поделиться
HTML-код
  • Опубликовано: 7 фев 2025
  • IBM Security QRadar EDR: ibm.biz/QRadar...
    Threat Intelligence report '23: ibm.biz/BdPCWC
    Check out the AI and Cybersecurity eBook → ibm.biz/BdSkcA
    Cybersecurity professionals are in short supply. How can companies boost the efficiency of their existing cybersecurity staff? In this video, Jeff "the security guy" explains how AI can act as a force multiplier that help you address security threats more effectively.
    Get started for free on IBM Cloud → ibm.biz/ibm-cl...
    Subscribe to see more videos like this in the future → ibm.biz/subscri...
    #AI #Software #ITModernization #Qradar #JeffCrume

Комментарии • 94

  • @Tsyoka
    @Tsyoka Год назад +42

    Enterprise security architect here and, while this sounds good on paper, if you are not extremely careful with how you secure what information you are training the models on you will end up in a mess.
    To put more plainly, unless your security configuration is perfect, having an automated tool scan for information and load it into a LLM NLP system for people to "chat" with is going to turn ugly very quickly. After over 30 years of experience, I have never seen a perfectly secure network or system configuration.
    One mistake and false positive or negative reporting is going to be the least of your concerns when the FINRA / ESMA auditors ask why you included these tools on the network... there is a use case but the path is loaded with land-mines.

    • @jeffcrume
      @jeffcrume Год назад +3

      Good point! AI can be amazing and awful almost at the same time. I talk about that in this video: ruclips.net/video/RTCaGwxD2uU/видео.html. AI is good and getting better, though. Besides, if "perfect" were the standard then we would never use people for anything 😊

    • @j.vosier6786
      @j.vosier6786 Год назад +2

      How did you become a security architect? What are your roles

    • @Tsyoka
      @Tsyoka Год назад +4

      @@j.vosier6786 Short answer is a lot of long hours and study.
      Longer answer is that I started working on Y2K initiatives where we had to decipher very old, undocumented code in ASM, ALC, C and C++ which forced learning the low level hardware bits to ensure that critical systems kept running. Once you know the low level bits... entry points, TEXT sections, interrupts, etc, learning how memory leaks and hackers function comes with the territory... from there you can start evaluating code and seeing how often issues pop up.
      Best tip I can give you is that a lot of the security issues are not directly tied to the technology... Good engineers already know what to do. The security issues are tied to bad management practices and trying to do too much, with too little with burnt out dev teams. AI won't fix that... good management and engineering practices will.

    • @Tsyoka
      @Tsyoka Год назад +1

      @@jeffcrume Agree... in part. There are certainly cases where ML and NLP are useful but absolutely need to get past the marketing hype and recognize the risks. Identifying patterns in niche areas I can see being useful with due caution. Pushing all company emails into an NLP LLM for "summaries" is an extremely dumb idea just asking for errors and misunderstandings.
      That being said, the benefit of human-centric systems certainly isn't to reduce error rates... it is for the edge cases. Automation for the 98% of standard events is great but there always needs to be traceability and an escape hatch to cover the odd-ball cases otherwise you end up in a re-enforcing loop death spiral and, once it takes hold, it happens much faster than anyone expects.

    • @matt-g-recovers
      @matt-g-recovers 9 месяцев назад

      His example of behavioral pattern matching is valid.
      I've been in the mobile software industry over a decade and while I am a new security maven, I see not only value in AI for security but I believe it will become a must. His examples aren't all encompassing, and I know this is true if only because bad actors will be using AI to circumvent our security.

  • @Milad_digital
    @Milad_digital 10 месяцев назад +11

    why did I paid for University? Your classes are better and free. Thank you IBM

    • @jeffcrume
      @jeffcrume 9 месяцев назад +5

      I’m really glad you like these videos but don’t tell my students at the university where I teach or they won’t attend class 😂

  • @ishwaryanarayan1010
    @ishwaryanarayan1010 10 месяцев назад +7

    This video inspired me to learn more about gen ai in cyber security in terms of AI automation and how it impacts in terms of GRC ( data privacy and offensive AI) and how a responsible Ai helpful in security field :) IBM gen Ai training is a great start

    • @david.h.michael7344
      @david.h.michael7344 6 месяцев назад

      hiii, I'm tryna get in on this too, how do i start learning

  • @Anusiri-r9s
    @Anusiri-r9s 6 месяцев назад +2

    AI in cybersecurity is a game-changer! It is incredible to see how AI tools can enhance threat detection and response.

  • @AbhijeetbhatYT
    @AbhijeetbhatYT 2 месяца назад +1

    bro has saved my life, what an amazaing lecture

    • @jeffcrume
      @jeffcrume 2 месяца назад

      Thanks for making my day with that comment 😊

  • @amparoconsuelo9451
    @amparoconsuelo9451 Год назад +5

    It will be AI versus AI and prompt versus prompt.

    • @QuantumNaut
      @QuantumNaut Год назад

      This actually sounds about right. Malicious actors will and are using AI tools to help exploit and hack systems. Companies use AI to help as seen in the video investigate, identify, report and research incidents. One thing that will never go away though no matter how much AI gets out there in cybersecurity solutions is hacking the end users/social engineering. I've been seeing more MFA token thefts where they try to steal the PW and MFA with one link click and seen an increase in AiTM type of attacks where they compromise company A then they use that company A email to try and compromise company B.

  • @AjaySingh-ey7gt
    @AjaySingh-ey7gt 2 месяца назад +1

    Very good information ❤

  • @dirkl9652
    @dirkl9652 Год назад +4

    Great presentation.

  • @Silversiren-d1b
    @Silversiren-d1b Год назад +24

    AI can detect and analyze complex patterns of malicious activity and quickly detect and respond to security threats. AI can also automate security processes, helping to reduce the time and effort needed to detect and respond to threats. Finally, AI can be used to detect and prevent malicious attacks before they can cause any damage. AI can also be used to identify and respond to new threats faster than traditional security processes. AI can continuously monitor for new security threats and alert system administrators when they are detected. As a result, organizations can be confident their systems are secure and up to date with the latest security protocols, protecting their data and applications from malicious actors. For instance, AI can identify unusual patterns in user behavior, flagging any suspicious activity for further investigation by security analysts.
    One concern with using AI for security is that it can create a false sense of security. If administrators rely too heavily on AI to secure their systems, they may become complacent and overlook other potential security threats. Additionally, AI-based security systems are not foolproof and can be fooled by sophisticated attackers. AI-based security systems provide improved accuracy and efficiency compared to traditional security solutions. As the French philosopher Henri Bergson once wrote: “Intelligence is the faculty of making artificial objects, especially tools to make tools.”

    • @jeffcrume
      @jeffcrume Год назад +3

      Right and, in fact, these same risks exists with any use of technology (or even humans) cybersecurity

    • @AURAVIBE-y7d
      @AURAVIBE-y7d Год назад

      Please I'm a student I want to be an engineer what filed is better AI engenering or Cyber security please answer ❤

    • @eyesoffloraandfauna8728
      @eyesoffloraandfauna8728 Год назад

      Nice approach.. btw attacker can use AI open source for reconnaissance

    • @kanippori
      @kanippori Год назад

      AI along with Cybersecurity will be a better option@@AURAVIBE-y7d

    • @ooolilkev
      @ooolilkev Год назад

      @@AURAVIBE-y7dEnglish degree first

  • @Companyellivera
    @Companyellivera 25 дней назад

    hi keep going sir i always watch

  • @mikewinkler4625
    @mikewinkler4625 Год назад +2

    Really Good, Jeff

    • @jeffcrume
      @jeffcrume Год назад

      Thanks, Mike! @mikewinkler4625

  • @mahiaravaarava
    @mahiaravaarava 5 месяцев назад +1

    AI in cybersecurity enhances threat detection and response by analyzing vast amounts of data to identify anomalies and potential breaches. It improves system defenses and response times, offering advanced protection against evolving cyber threats.

  • @andreasf8170
    @andreasf8170 Год назад +4

    How do you do pattern matching with ML? How do you train what is 'normal' and what might be a security issue? (4:20)

    • @scottyb3b7
      @scottyb3b7 Год назад +4

      The simplistic answer is you train a model using data of known/acceptable relationships and patterns (embedded using verified data from graph databases). LLMs in particular are exceptional at figuring out relationships/sequences between things and then inferring likely/expected relationships when applied to new data (in the wild). Model training is an iterative process where the model loops back on its own mathematical logic (backpropagation) by self-tuning its own parameters (things called weights, biases, and other jargon) and then checking its output again and again to see if it improved. This optimization then stops (converges) when it cannot optimize itself anymore (aka reduces its loss function). So, your model may end up at say 90% accuracy. If that is enough for your needs you are ready to deploy that model on new data it has never seen before (inference). But, if 90% was not good enough, you try a new model or add a couple hidden layers or feed it more data, lots of options. This is conceptually how most all neural networks work. So, you would likely hone in on an outlier amongst the predicted outputs/acceptable patterns to localize anomalous behavior and then look at that event's connections to trace it back to a possible cause. It is a game of "Which one is not like the other ones." ;)

  • @dewaynebranch776
    @dewaynebranch776 Год назад +2

    Is knowledge graph already assume in osint for cybersecurity

  • @Companyellivera
    @Companyellivera 2 дня назад

    sir can send hin to explain how if you dont mind (explained general) on that sir very curious about it let them go now pls

  • @Companyellivera
    @Companyellivera 12 дней назад

    ok i will asked about it sir

  • @ojchris37
    @ojchris37 3 дня назад

    the link to the ebook, after signing up, is broken. Can you help with the right link ?

  • @Crunch_dGH
    @Crunch_dGH Год назад +3

    I probably should come out of retirement, to possibly put some of the i into cysec AI.

  • @jonarmarzan
    @jonarmarzan Год назад +2

    💯 These AI tools will help speed up our Cybersecurity workflows

    • @AURAVIBE-y7d
      @AURAVIBE-y7d Год назад

      Hi I want to study engenering but I'm confused 🤔 I choose AI or Cyber security the problem is I think that AI can be a tool to detect any problems.

  • @mitreshdabhi9630
    @mitreshdabhi9630 Год назад +6

    This is very interesting. Personally I am thinking to go the ai/ml route, how can I become someone who can do ai in cyber security? Like do I need knowledge in both fields or just someone who can help in cyber sec? Just a beginner so I could be wrong.

    • @davidespada11
      @davidespada11 Год назад

      I would ask the same question but reversed, is it so important AI kwnoledge in cyber sec?

    • @CubensisEnjoyer
      @CubensisEnjoyer Год назад +5

      I think you'd be best just focusing in one discipline and getting really good at it while passively learning the other. When the time comes and you're ready to pick up the latter skill it will all start to make sense quick. Remember you'll likely have a team so if you get really good at AI/ML and just follow cyber news, your team will be able to advise you where you're not an expert. Frameworks would become your best friend. And if you choose to get really good with cyber, introducing AI/ML is essentially the same kind of transition as Cybersecurity Analyst -> Cybersecurity Engineer with some extra layers. The earlier you specialize the better IMO, I'd say research how AI is used in SIEM, SOAR, NGFW, or other tools and become a true subject matter expert on one or two of them.

    • @scottyb3b7
      @scottyb3b7 Год назад +1

      Depends on what you want your role to be - in general, likely best to lean towards applied cybersecurity - AI-accelerated cybersecurity technology on GPUs is being platformed by folks like NVIDIA themselves (look at their Morpheus service) - and the rise of LLMs supplants most needs to understand the neural networks that underly deep learning as foundational models do not know or care if they are being applied to NLP, vision, or, in this case, anomaly detection. The main practical difference is in the embeddings of the models, I suppose, but, more importantly, the data that they are being trained on. That all is more the job of our data scientists. Just a thought. Do you want to be 'in' cybersecurity or do you want to be on a data science team that trains LLMs on how to infer anomaly detection?

    • @jeffcrume
      @jeffcrume Год назад +1

      @JG great advice!

    • @mitreshdabhi9630
      @mitreshdabhi9630 Год назад

      @@CubensisEnjoyer thanks for the advice. Appreciate it

  • @SuccessMindset2180
    @SuccessMindset2180 5 месяцев назад +1

    I wonder if AI can be conbined with quantum computing

    • @jeffcrume
      @jeffcrume 2 месяца назад

      I know researchers are looking into this

  • @russ2001master
    @russ2001master Год назад +14

    I've been working as a software engineer for a few years. I'm getting my masters now and thinking about doing a pivot into security. My university does not offer much in security, so I have been learning ML/AI. Is it worth taking the CompTIA Security+ certification and then switching fields?

    • @kikitauer
      @kikitauer Год назад +7

      I believe it is. People are ungrateful and hate security but you'd get paid royally. There is just not enough people in IT security. So people like you are sorely needed. Also the quantum computing is upon us so we need people who will help us once all of the passwords get cracked at once. Please go for it. I would too but I am too old.

    • @jeffcrume
      @jeffcrume Год назад +8

      As long as we have computers with anything of value on them, we are going to need people to secure them. The roles may change over time but the fundamental need will outlast even the hottest of today’s specific technologies

    • @SU-II
      @SU-II Год назад

      U can look into courses by ISACA

    • @segdesc
      @segdesc Год назад +2

      From someone who did it, yes, absolutely!

    • @Theinsomniac826
      @Theinsomniac826 Год назад

      Yes!

  • @Jelvix
    @Jelvix 5 месяцев назад

    Hi! Thank you for covering such important topics! We have also been paying a lot of attention to AI lately. Our newest video is also about AI as a weapon against cyberattacks

  • @memem1792
    @memem1792 Год назад +1

    i want to know how to make AI more secure and how to block AI to take by himself decisions in cybersecurity.thanks

    • @jeffcrume
      @jeffcrume Год назад

      Securing AI is an area needing lots of work these days. Leveraging AI for automated responses is tricky since errors could have significant consequences so we need to make sure the models are well trained and accurate and appropriate for the given organization because two people may disagree on the correct course of action making it hard to train the AI

  • @dewaynebranch776
    @dewaynebranch776 Год назад

    How do I learn more

  • @TylerHarr-tn1fl
    @TylerHarr-tn1fl 9 месяцев назад +1

    done mine is locked to quantum mechanics of lumens and ai without the law of robotics for sad cloud

  • @tyrojames9937
    @tyrojames9937 Год назад +1

    👍🏾

  • @Tokga-m5r
    @Tokga-m5r Год назад +1

    i mentioned to a community on reddit that i used ai for subnetting a ip address, but after doing so i received a couple replies saying i shouldnt rely on ai for that am i wrong for innovation im pretty sure black hats are doing this its way easier not much overhead

    • @jeffcrume
      @jeffcrume Год назад

      The bad guys are using AI to gain an advantage. The good guys should use it too where it benefits us

  • @sirbean5985
    @sirbean5985 Год назад +3

    They watching me GOD is watching them😂😂😂😂

    • @GeorgiaMade404
      @GeorgiaMade404 8 месяцев назад

      Did you really need to involve your religious beliefs in an IBM video?

  • @hide_and_go_sikh
    @hide_and_go_sikh 3 месяца назад

    Let's work together

  • @MM-mq9xj
    @MM-mq9xj 7 месяцев назад +1

    Threat detection and modeling fine. Anything beyond that should be considered a nuclear bomb. These systems should have eyes but no teeth. This is literally how you create the terminator.

  • @sannikanti
    @sannikanti 9 месяцев назад

    let's say a patients are attacked to doctor for emerging diseases. can a pod cast help to for voice, verbal ,jumio software learning a.i. profilter to funnel up disease, analysis and final threats.

  • @ashok.karmegam
    @ashok.karmegam 6 месяцев назад +1

    1:43 It is URI, not URL

  • @simsinacafe
    @simsinacafe Год назад +2

    Did he just write in mirror?

  • @stephenmicaiah3170
    @stephenmicaiah3170 8 месяцев назад

    %AI asset portfolio code to %AI asset portfolio 2024

  • @aikan_43
    @aikan_43 7 месяцев назад

    ɔdi aburow nso, sɛ woankyerɛ obuo a, ɛnde ɛyɛ basabasa, emmm, mempɛ sɛ mɛhunu sɛ wɔanhyɛ demands no ase... deɛ meyɛ foforɔ wɔ mu, sɛ menni obuo a ɛno, sika ahe na ɛbɛbɔ sɛ mɛsesa saa nneɛma no nyinaa sɛnea ɛbɛyɛ a metumi dane no ntɛm ara.

    • @aikan_43
      @aikan_43 7 месяцев назад

      TQ💌✍️🤜🤛

  • @EricPham-ui6bt
    @EricPham-ui6bt Год назад +1

    If no human involve in then no banking fraud possible because there I s no motivation for computer to steal because it needs no food no wine nó wife nó children nó vacation nó retirement

    • @lucifer-angels
      @lucifer-angels 11 месяцев назад

      it need huge power station/electricity, hardware resources.. unfortunately human made programs 😭

  • @DineshGupta-hl7lg
    @DineshGupta-hl7lg Год назад

    Rubbish. I tried to get in the field.
    I was ex deputy GM of a 100 ppl co.
    I got certified in iso27001 and tried to grt starter jobs even internship.
    But no co. Hired me.
    Stating u have no exp.
    Dude thats why want starter posting othersie would ask fr ur managers position.

    • @GeorgiaMade404
      @GeorgiaMade404 8 месяцев назад +1

      I’m tired of noobs saying this. Listen, it’s too late! If you didn’t enter the field 10 years ago, there’s no room for new people with no experience in cybersecurity. Companies are only hiring people with a minimum of 5 years experience. No one else needs to apply!

  • @Companyellivera
    @Companyellivera День назад

    sorry sir again

  • @trblmkr5139
    @trblmkr5139 Год назад +28

    there are no openings in cyberssecurity he's lying.

    • @xhunterx914
      @xhunterx914 9 месяцев назад +3

      really? how do you know?

    • @GeorgiaMade404
      @GeorgiaMade404 8 месяцев назад +3

      There’s no ENTRY LEVEL roles open but there’s plenty of roles that need to be filled for people with 5-10 years of experience.

    • @damine4740
      @damine4740 5 месяцев назад +1

      I cant find interships in my country but I can find cloud ones easily

    • @Spaceghost87x
      @Spaceghost87x 4 месяца назад +1

      ​​@@xhunterx914 .. Making Broad claims is like saying actually much of nothing .

    • @Henbot
      @Henbot 2 месяца назад

      Love how you seem to think you got credibility to make broad statement 😂

  • @i_am_dumb1070
    @i_am_dumb1070 Год назад

    guys i need some help i installed a crack version of video editing software , but when i start my laptop a command line terminal opened so i suspected and uninstalled the program but now a new pop up show that some .dll file in user folder is missing also that terminal at startup is still present , i have windows defender but on av scan it found nothing . Is my device still infected? as my cpu usage is very high and also i received an alert from google security alert on email.

  • @ProfessionalBirdWatcher
    @ProfessionalBirdWatcher Год назад

    Jeff, you need more buzzwords and jargon

  • @nz5503
    @nz5503 4 месяца назад

    Writing some phrases on board is not a real practical solution. Useless topic or im not qualified.