Tag: cyberattack

How Artificial Intelligence Is Helping Fend Off Cyberattacks

Intellectual property cyber security

Artificial Intelligence (AI) is the ability of technology to think and act similar to a human and is being utilized to help fight off potential cyberattacks. Employing AI and machine learning to detect vulnerabilities significantly enhances human capabilities, as AI can analyze and report millions of cyber threats in a fraction of the time it might take a person to do the same.

AI can get “smarter” and “learn”; as an AI algorithm continues to search and monitor data, it can improve its understanding of different types of potential attacks.

What is a Cyberattack?

You’ve probably heard a lot about cyberattacks and data breaches on the news lately, but what exactly is a cyberattack and why is it important to protect our data?

“In short, a cyberattack is a deliberate and often targeted attempt to mount an action via or against digital technology,” says IEEE Senior Member Steven Furnell. “In practice, cyberattacks can take many forms, but we tend to most commonly associate things like hacking and malware, and perhaps phishing. However, there is a far broader range of labels that can be used to reflect the specific approaches and motivations that may be involved.”

“After the attack, the computer or the network will be destroyed, exposed, modified or lose some functions,” adds IEEE Senior Member Guangjie Han. “And your personal information or important data will be acquired by someone else without authorization. Consider the potential benefit behind the data — that’s why these attacks exist.”

Junior hackers might only have an interest in stealing money, acquiring personal data, or merely for the joy of hurting others. More senior hackers have the potential to breach entire companies or governments.

How AI Prioritizes Security Needs

Once AI has effectively identified the potential risks and threats, the next step is to prioritize what gets addressed and in what order.

“Since AI-based detection systems usually work with certainty, they are useful not only to raise alerts when something seems to be wrong but also to give a score on how close a given event is from a cyberattack,” says IEEE Member Marcos Simplicio. “Events with higher scores can then be prioritized accordingly. For example, above a certain score, automated measures may be taken to stop the highly probable attack without any human intervention. Events with a lower score can then be forwarded to administrators for further analysis, and some events with low scores may be simply logged without any additional action, since handling them may not be worth the effort.”

Other Methods of Stopping Cyberattacks

AI and machine learning are not the only mechanisms used to prevent and fight off cyberattacks. A wide range of robust technologies protect our systems and help fend off severe breaches.

IEEE Senior Member Aiyappan Pillai explains that in addition to AI, cryptography, emerging quantum cryptography, analytics, IoT security, blockchain security, and hardware authentication technologies are also helping technologists keep our digital infrastructure secure.

Lastly, another way to prevent cyberattacks is continuing to educate users to stay away from suspicious activity. “It is important to remember that security is largely a matter related to processes and behaviours and therefore administrative, education and awareness processes play a key role in any well-designed security strategy,” stresses IEEE Senior Member Raul Coucher.

An Analytics & Behavior-Centric Approach to Digital Payment Security for the RBI

The recent news of cyberattack on a large private bank, where banking operations were halted for two days is really alarming. It appears to have been a denial of service (DDoS) attack or some other flaw in the netbanking system, which led to this attack, where people were not able to connect to the bank’s server and its netbanking site for 48 hours. These types of attacks are always related to flooding of traffic for a specific service because of which the service would stop responding or crash. A known vulnerability within an internal application can also pose these kinds of issues which can lead to a big impact such as bringing the system to a complete halt.

Examples like this always result in the amendment of current security practices. It is good that the Reserve Bank of India (RBI) is focusing on this and bringing more digital initiatives that will ensure banking transactions are secure from a cybersecurity perspective. When banks undertake updates or add new applications, they should evaluate the risk related to these applications and ensure that people accessing them can trust the new services. These parameters need to be assessed every time the bank does a vulnerability assessment. The security team at a bank should know how a certain application is behaving, what is the baseline load, what type of transactions are happening, etc, but this information also needs to be captured at an analytics level. Then if this baseline load is exceeded, it acts as an early warning system to step in and address DDoS attacks quickly.

As RBI is focused on building a more secure digital framework, it should look at utilizing analytics to make sure banking platforms are resilient. In India, the banking sector seems to be heading towards a big transformation. For instance in the past, RBI rolled out new kinds of credit cards for users where a small chip is inserted in cards to improve security and convenience for card transactions. This shows how RBI is working towards modern initiatives and frameworks for the banks to adopt. Once we get to know the new policy and guidelines, we can further share our thoughts.

I imagine that RBI would intend to build a robust security policy that takes all types of banking players (private, nationalized, overseas and cooperative) and modes of transactions into account. As India is talking about data protection and data privacy, these factors will also have to be considered. For example, whether a person completes a transaction from a mobile phone or laptop or from any location, data gets logged into the system. This brings up the question of data security and privacy. I’m sure RBI will focus on these aspects from their digital initiative perspective-how to manage the infrastructure risk along with the privacy risk. Data protection is another point that RBI may keep in mind while designing security policies. Data can be protected and better secured by taking a behavior-centric approach to security.

For instance, during a crisis Forcepoint’s Data Loss Prevention (DLP) solution can help banking customers detect and protect data leaks from a compromised system, the web, email or from an endpoint. As any B2B service consumes that data, it can also monitor data over the transport layer.

Our Dynamic User Protection helps in detecting and preventing an insider threat, and monitors user activities using indicators of behaviors to implement an auto-response based on the risk matrix. This helps banks detect risky behaviors in the core banking system and to identify people who interact with that data.

As people are working from home even in the banking sector, our Private Access replaces the traditional VPN and brings in micro-segmentation. This solution helps in segregating network and data management plane to provide secure remote access to applications and data in the datacenter.

Indian Startups & SME’s most vulnerable to fall prey to cyberattacks: CyberPeace Foundation (CPF) 2020 eBook Report

While digital transformation has been a great boon for SME’s and Startups in 2020 as more businesses come online, it has also opened up opportunities for cybercriminals to target weak or non-existent cybersecurity infrastructure which smaller businesses tend to generally have in India.

As per findings in the recent handbook titled “Cybersecurity for SMEs & Startups” by CyberPeace Foundation (CPF), a leading civil society organization and think tank of cybersecurity and policy experts, startups and SMEs remain the most vulnerable segment in India when it comes to cyberattacks.

The eBook is being launched in joint collaboration with the United Nations Global Compact Network (UNGCNI), Autobot Infosec and The Institution of Electronics and Telecommunication Engineers (IETE). The eBook not only reveals key findings of cybersecurity vulnerabilities in the Indian startup & SME ecosystem but also recommends best practices to avoid the same.

When it comes to the most common challenges faced by organizations, one of the most critical ones is the cybersecurity risks. They interrupt the functioning of an organization and compromise the confidentiality, integrity, and availability (CIA) of valuable information assets. However, the cybersecurity risks themselves stretch across a broad spectrum.

As per the findings in the eBook, the most common forms of cybersecurity challenges faced by startups are –

Negligence by employees: The most common forms of employee negligence which lead to cyberattacks including data breaches are accidental loss of the device containing confidential data, leaving the workstation unprotected or unattended, sharing confidential information such as passwords via paper notes & remote working using an unsecured or public network connection.

Employee Mobility: With COVID19 prompting startups & SMEs to institute work from home policies, the potential for cyberattacks has increased manifold. Most employees tend to use personal unsecured devices to do work which results in data breach. IoT devices used by employees are often unsecured which results in the maximum number of data breaches.

Most common types of cyberattacks faced by startups & SME’s are Ransomware, Cyptojacking, Phishing, Password targeting attacks & APT attacks.

Talking about the findings & report, Vineet Kumar, Founder and President, CyberPeace Foundations, said, ”On one hand India is the 3rd largest startup nation in the world while on the other hand majority of Indian startups & SMEs routinely disregard cybersecurity. The challenge is exacerbated by SMEs who may not have the knowledge or understanding of cybersecurity.

I think startups and SMEs are particularly lax in terms of ensuring #cybersecurity, they only take it seriously after the breach has happened, which is very irresponsible. With the launch of the eBook, we hope to address the problem and create more awareness for budding startups & SMEs who are building businesses online.”

Launching the eBook on CyberSecurity for SMEs and Start-ups, Lt. General (Dr.) Rajesh Pant, PVSM, AVSM, VSM, National Cyber Security Coordinator (NCSC), Prime Minister’s Office mentioned, “To know how to defend yourselves or your organization, it is important to understand how the attacks happen and what methodology do cyber predators use to harm organizations. October is considered as “CyberSecurity Month” and seeing that everyone across the nation is taking initiative and coming up with this eBook is very relevant and I compliment everyone for this.”

Commenting on the grave issue, Dr. Jagdish Bakal, President, The Institution of Electronics and Telecommunication Engineers (IETE) said, ”As per the Government of India, India has the 3rd largest startup ecosystem in the world; expected to witness YoY growth of consistent annual growth of 12-15%. India has about 50,000 startups in India in 2018; around 8,900 – 9,300 of these are technology-led startups 1300 new tech startups were born in 2019 alone implying there are 2-3 tech startups born every day. The pace of growth in the startup ecosystem has increased to 15% year-on-year in 2018, while the growth of the number of incubators and accelerators has grown to 11%.”