There are currently a minor number of topics creating the press in the computer industry than machine learning (ML) & artificial intelligence (AI). AI has been in process for well over a decade, yet recently has been much more publicized in the press. Most persons may be familiar with ML and AI from the movies (Tron, Her, iRobot, Blade Runner, 2001: A Space Odyssey, and many others) or commercial ventures with security incident and event management (SIEM) applications (Dawson, 2017). These applications have also been implemented with recreational users with the Go game, IBM Watson, and other applications.
InfoSec
InfoSec has many functions, too numerous to detail. These include, but are not limited to, log analysis, spam filter applications, network IDS/IPS, fraud detection, botnet detection, user authentication and validation, and in general monitoring activities (Rossi, 2016). With the vast number of responsibilities, time is of the essence. This is only further exasperated by the mass number of attacks that are present and that will continue to grow.
These attacks have been increasing over time as a function of the increasing attack surface of increasing data and system complexity coupled with the potential revenue to be generated. The amount of data generated from daily operations increases making it difficult to analyze all of the data (Siwicki 2017). This grows, in comparison, from a small to medium, or medium to large sized business. The increased amount of available threats (Stevens, 2018) have subsequently increased the network breaches in the mid-decade (Li, 2015) and recently. Although this is abstract, the reality of the situation incorporates the actual cost to the organization. In 2013, the estimated global cost of cybercrime was $113B (Sanders, 2015). As the number of attacks has grown along with the mass volume of data being targeted daily, the cost has increased rather significantly.
These attacks also have increased in depth. These have moved from the shallow, low hanging fruit to the more in-depth, complex attacks. With the number of new InfoSec tools engineered specifically to compromise systems and these being designed with a GUI for complete ease of use.
The attacks have also increased in criticality. The targets are involved with more criticality. The targets are involved with more critical operations for the organization. The attacks are becoming more concerned with these high-value targets, providing greater attention when compromised.
Current Workforce
In InfoSec, as a general indicator, there have been and continue to be a significant shortage of qualified staff. In cybersecurity, this is much worse. There presently is and will continue to be a severe shortage of cybersecurity professionals throughout the country (Li, 2015). The issue isn’t merely with the number of staff members not being sufficient, but also with experience. The expertise of the staff members also is lacking (Cowley, & Greitzer, 2016).
One area this is specifically problematic is within the automotive cybersecurity field. With the new modules and operations, along with the new push for autonomous drive (AD) vehicles, there is a much larger need for cybersecurity professionals. This demand for the automotive cybersecurity professionals will continue to outpace the supply (Uchill, 2017).
Staffing Limitations
The InfoSec staffing shortage is well-known and published in various mediums, and a challenge (ISACA, 2018). This shortage is not localized, but a global issue (Ollmann, 2016). Within this industry, 59% of cyber- and InfoSec positions are not filled (Zorz, 2018). The same study also noted 54% of respondents say filling an open position generally requires at least three months. This time frame experience is not acceptable.
To further this, 59% of the enterprises responded the organization experienced open security positions (Teitler, 2018). This is as of a limited time span. Over time, this has also been the case. ESG recently conducted their annual global survey focussing on the state of IT. From this survey, the number of organizations claiming a shortage of cybersecurity skills has increased since at least 2014 (Oltsik, 2018). This study indicated the obvious of filling these cybersecurity positions was more difficult in 2018 versus 2017 (Rio, 2018).
Expected Labor Force Shortage
As noted, the past and present shortage of qualified, experienced cybersecurity staff has been growing noticeably (Morgan, 2017). This is the reality for the industry. Looking forward, the shortage of staff is expected to be approximately 1.8M by 2020-2022 (Condon, 2018; Stolte, 2018; MacDonald, 2018; Gil, 2018; Kawamoto, 2017).
AI to the Rescue
The past, present, and future labor shortage is well-known. One discipline which may be of assistance is AI (Rio, 2018). While this is not a panacea and won’t be able to solve all the presented issues (Oliver, 2018), there is a clear benefit to the implementation (Scroxton, 2018). In general, AI will be able to increase human productivity (Reese, 2018). As the beneficial processes are experienced by the organization, the cybersecurity teams will achieve a greater level of understanding (Ismail, 2017). This greater depth of understanding will provide for a faster, better, and less costly cybersecurity program.
This understanding will provide for the upgraded modules to better identify threats, assess the risk, and apply the remediation protocol. Identifying threats has proven to be difficult due to the attack surface and data continuing to grow. There is a limited amount of resources being applied to the network, endpoint protection, applications, cloud services, mobile devices, and other points and processes. Assessing the risk involves correlating the external threat data with the business criticality. This activity along is well-suited for ML and AI applications, along with the added functionality AI provides for. This may be used to assess the security gaps and possible points of breach or compromise.
Trust
For the full implementation of AI into InfoSec, there has to be trust with the system. The humans require a full understanding and appreciation of the system, knowing the risk of an oversight or negligent decision is as close to a null as possible, with the awareness that there will be a rather insignificant level of potential error in the application. No human deiced without an error on some level over decades of work. This confidence in the system is vital (Stilgherrian, 2018).
For the trust to be in place, there need to be two pertinent factors in place. These are operational and data security (Hengstler, Enkel, & Duelii, 2016). The operational safety facet involves the technology itself being reviewed and approved per the appropriate level of governance. The data itself also has to be secure, and not modified. With these fully engaged, the issue of a lack of trust would be marginalized.
Replacing Humans
Another issue noted was the AI system would replace most of the humans, leading to mass unemployment. Users may have the visions from Hollywood of the machine taking over step by step. This will not be the case. The AI systems will work to supplement the workflows, not replace humans, freeing time which may be applied elsewhere on other projects (Rio, 2018).
There are many types of duties and work which AI is not able to do so (Skilton, 2017). Humans have the ability to generalize, reason through issues, and intuition, which would not be able to be fully replaced by code or a machine (Towers-Clark, 2018). From this, clearly, the cybersecurity role is and won’t be targeted (Korolov, 2016).
Regarding job functions, there will be fewer jobs at risk of being affected by automation than previously thought (Vincent, 2018). There will not be the need for humans lessening as the new paradigm shift occurs. This potentially will affect, to the detriment of, low skilled jobs. As an example, there have been in use for over a year AD bus lines on the campus of the University of Michigan-Ann Arbor. These naturally have a limited scope of use, however, have been in place, are actively used, and are trusted by the students and University.
This will be used more to review threats originating from outside of the entity (Needle, 2017), for data protection (Help Net Security, 2018), to detect anomalies in traffic, and to create a more difficult environment for attackers to compromise (Osborne, 2018).
There is a level of faulty reasoning as the AI system will not be usurping the human’s authority and autonomy. The industry and civilization will still need human developers (Merritt, 2018). There is no question as to this use case. Humans will be needed for advancing to tools we have in place presently. Each business is unique in its parameters and application requirements (Allen, Filar, & Seymour, 2017). The humans will be needed to fulfil the varied requests and requirements in a creative manner. While creativity is one of the functions of AI in the long-term, the humans will still need to be directly involved in these endeavours.
The humans will be required to manage the contingencies involved with business operations, incident response, and many other areas. While computing this is a controlled process, the human aspect will be needed as creativity is a required function. The decision process is multi-faceted and still will require a human’s interpretation of events, and rank in the decision matrix.
ML and AI will assist with InfoSec as an effective assistant (Siwicki, 2017). The users are too numerous to enumerate, however, the generalized uses are notable. These include, however, are not limited to:
a. Analyzing the mass amount of data generated daily from operations, AD vehicles, and the myriad of other sources (Graham, 2018),
b. Improving accuracy, which would subsequently increase the human's confidence (Ashford, 2017),
c. Automating initial and secondary false positive review (Morgan, 2017), effectually freeing up a large block of time for the InfoSec team,
d. Improving predictive analytics to possibly identify pre-compromised targets, reviewing the requirements for the InfoSec team to remediate issues,
e. Force multiplying; as this will supplement the InfoSec team’s efficiency, allowing each member of the team to achieve more in different areas, and
f. Training, personalized for each staff member to assist them with their position, goals, and careers.
Supplement and Augment
AI will be a benefit to commercial organizations, consumers, and others involved. In the subject context, the benefits are numerous and too expansive to list for the InfoSec field. This, as the implementation evolves and increases in usage, will become more evident and show not only its promise, however also its potential to make the InfoSec worker more efficient, and multiply their efforts.
This shift in the application will not be quick. This is a needed, as with this level of a technology shift, the steps need to be sure, planned, and executed within a governance model.
References
Cowley, J.A., & Greitzer, F.L. (2015). Organizational impacts to cybersecurity expertise development and maintenance. Proceedings of the Human Factors and Ergonomics Society Annual Meeting, 59(1), 1187-1191. doi:10.1177/1541931215591185
Hengstler, M., Enkel, E., & Duelli, S. (2016). Applied artificial intelligence and trust-The case of autonomous vehicles and medical assistance devices. Technological Forecasting & Social Change, 105(2016), 105-120. doi:http://dx.doi.org/10.1016/j.techforce.2015.12.014
Li, C. (2015). Penetration testing curriculum development in practice. Journal of Information Technology: Innovation in Practice, 14, 85-99. doi:https://doi.org/10.28945/2189