In today’s digital age, threat actors are succeeding in using offensive security tools (OSTs), misconfigured cloud environments, and stolen credentials to access sensitive information. According to the 2024 Elastic Global Threat Report, public sector agencies and private industry struggle with these vulnerabilities and attack threats. The report also delves into critical vulnerabilities within cloud systems, malware detections across major operating systems, and evolving Generative AI (GenAI) threat tactics, including AI-augmented phishing and deepfake scams.
However, the report also reveals that artificial intelligence (AI)-based security analytics proactively provides a robust and adaptive defense mechanism against many cyber threats. While AI can increase the sophistication of threats in some instances, it is also a powerful tool in the hands of defenders by advancing threat detection and automating testing, making its benefits outweigh its risks for analysts.
AI Combats Malware Attacks and Threat Tactics
Elastic’s Global Threat Report reveals that Windows accounts for the largest share of malware detections (66.1 percent), while Linux saw 32.2 percent of detections. This data reflects a significant shift as more adversaries target server environments and critical infrastructure. Trojans constitute 82 percent of all observed malware, with a substantial 21 percent increase compared to last year. This increase indicates a trend of malware disguising itself as legitimate software, a deceptive tactic becoming increasingly common.
So, where does AI come in? AI can help address these malware threats by sifting through extensive data to identify malware on various operating systems by spotting unusual patterns and behaviors, even those of previously unknown threats. It can also monitor login attempts and access patterns, detecting and responding to suspicious activities in real-time. This proactive approach can minimize the risk of credential theft and misuse, giving cybersecurity teams a sense of control in the face of evolving threats.
AI Aligns with Zero Trust
AI security is also pivotal as the federal government transitions deeper into the Zero Trust security model. AI security analytics, aligning with Zero Trust security, actively monitors and analyzes user behavior, network traffic, and system activity. This capability enables real-time threat detection and response, a crucial aspect of a Zero Trust security model’s ‘never trust, always verify’ principle. AI automates the continuous verification process needed in a Zero Trust environment, making it more dynamic and effective against evolving threats.
AI and machine learning (ML) play crucial roles in enhancing response capabilities within Zero Trust frameworks. They help Zero Trust detection solutions identify and respond to potential threats faster and more precisely, providing a sense of reassurance and confidence in agencies’ security measures.
AI Evolving as a Security Tool
Security analysts have used AI and ML for years to quickly identify and remediate known and unknown threats. Emerging capabilities, such as AI-powered security detection and advanced attack and discovery capabilities, elevate this process, allowing security operations center (SOC) analysts to prioritize attacks over alerts.
By applying attack and discovery capabilities, security analysts can train large language models (LLMs) on their internal cybersecurity frameworks and security playbooks, tailoring responses to specific threats faced by their agency or organization. For instance, when security operators have 200 alerts on their console, running an attack discovery capability against these alerts helps identify coordinated attacks and assess the agency’s vulnerability based on its security posture. This approach accelerates threat identification and resolution, improving the effectiveness of SOC analysts.
Additionally, as agencies migrate from legacy security information and event management (SIEM) and threat-hunting platforms, they must import data into new, modern security platforms, which is typically a manually intensive task. AI can streamline this process by creating ingest models for applications and automating data integration.
AI and ML are essential for developing effective security analytics and empowering security teams to proactively detect anomalies and pinpoint vulnerabilities to combat various threats and attacks. AI-powered security analytics give SOC teams greater visibility into the most pressing threats and trends, ensuring their priorities align with adversary activities occurring within their IT environments.
While social engineering attacks have become more sophisticated, our researchers have not observed a significant increase in infection rates over the past year. Instead, we’ve found that AI and GenAI have greatly benefited cyber defenders by summarizing security events, automating complex analytical and management tasks, and ranking suggested actions.
Tighten up the Weak Link
As the cybersecurity landscape evolves with the rise of AI-driven threats, the benefits of leveraging AI in security operations are undeniable. By empowering SOC teams with advanced AI and ML capabilities, agencies can enhance their ability to detect and respond to threats more effectively. This includes using AI to analyze vast amounts of data and identify patterns that may indicate malicious activity, automating responses to common threats, and providing analysts with real-time insights to make faster and more informed decisions.
The insights gleaned from the 2024 Elastic Global Threat Report underscore the pressing need for robust security measures, and AI is a critical component in this evolving landscape. As agencies embrace the Zero Trust security model, integrating AI into their frameworks will be crucial for improving identity management and threat detection. AI can help automate the continuous verification process at the heart of Zero Trust, while also analyzing user behavior and network traffic to identify anomalies and potential threats in real-time. By combining AI with a strong security posture and a culture of awareness, agencies can strengthen their defenses against evolving threats and safeguard their critical assets.
The author, Chris Townsend, is Vice President of Public Sector at Elastic.
