Skip to main content

Posts

Showing posts from October, 2016

Applying Machine Learning to Cybersecurity

In a recent article on the OPM hack, the author describes a pretty typical security situation for a large enterprise:The Office of Personnel Management repels 10 million attempted digital intrusions per month—mostly the kinds of port scans and phishing attacks that plague every large-scale Internet presence—so it wasn’t too abnormal to discover that something had gotten lucky and slipped through the agency’s defenses.Enormous pressure at scale from criminals makes automated systems essential for security. While humans can inspect packages coming into the building, only a computer can work quickly enough to inspect packets. Firewalls are the prototypical example: you allow certain traffic through according to a set of rules based on the source and destination IPs and the ports and protocols being used.In recent years, there's been a lot of buzz about machine learning in cybersecurity--wouldn't it be great if your automated system could learn and adapt, stop threats you don’t ev…

Anomaly Detection White Paper

We are pleased to release a new Data Science White Paper, focused on our approach to Anomaly Detection. This paper, which is available upon request, picks up where our October 2015 Data Science White Paper left off, describing in detail our approach and the use cases we support.The paper starts with a motivating example, describing the traces a sophisticated attacker leaves behind and how the traces can be detected. We then describe our algorithms within the context of the example and provide other use cases covered by our approach. We finish with a summary of the strategic advantages of the platform.Read this paper to learn more about:Our unsupervised anomaly detection approach, including detection of rare events, spikes, and out of context events.Entity level alert roll-ups, which help users prioritize investigations.The specific security use cases we address, which we map to the Lockheed cyber kill chain.The key advantages of our approach and algorithms.To learn more, get your own…