AI is making bad actors craftier. Here’s how security companies are using AI to fight back

Are you human?

It’s an increasingly important question, and one that’s getting harder to answer.

With its squiggly letters, the old CAPTCHA, the Completely Automated Public Turing Test To distinguish Computers from Humans, was developed in the early 2000s to stop malicious bots from creating new email accounts and was later used, somewhat ironically, to train machines to “read” garbled text. But given recent advancements in machine learning, the test and its various successors can’t keep the bots at bay the way they used to.

This isn’t just a problem if you’re trying to buy concert tickets. Automatic CAPTCHA solving fuels a fusillade of online attacks, including phishing, password spraying, malware, and propaganda campaigns. Last December, Microsoft and a startup called Arkose Labs took down Storm-1152, a Vietnam-based operation that sold CAPTCHA-cracking services—powered by machine learning—to hacker groups like Octo Tempest that perpetrated ransomware attacks that eventually inflicted hundreds of millions of dollars in damages. 

Which is why, if you sign in to some of the world’s biggest online platforms these days, you’re more likely to see something else: Instead of a text or image CAPTCHA, there might be a puzzle asking you to rotate a toy pickup in the direction of a pointing hand, or listen to three tunes and indicate which has a second instrument. The tests were developed by Arkose, which makes AI-enabled tools that help companies like LinkedIn, Roblox, X, and OpenAI stay ahead of the bots. Thanks to the explosion of generative AI and cybercrime vendors like Storm-1152, malicious bot activity is booming, now estimated to account for more than half of the web’s traffic.

A new AI-fueled arms race is erupting across the internet and everything connected to it. Machine learning has become “this incredible acceleration mechanism” for attacks, says Sherrod DeGrippo, director of threat intelligence at Microsoft. And if miscreants are using AI to break in, she says, “we should use machine learning, data science, and AI to improve our security tools and make it harder.” (To see how companies are making important strides in these areas today, read the full list of the Most Innovative Companies in the Security category.)

As AI supercharges ransomware attacks, by making it easier to construct convincing phishing campaigns, for instance, Texas-based Halcyon is using machine learning to block infections prior to execution, and in some cases, it says, even decrypt devices without the need for ransoms. The company is also armed with a deep fund of human intelligence about how attackers get in: the founders’ previous Thiel-backed venture Boldend got its start building cyberweapons for the U.S. government.

Before the hackers arrive, defenders are using AI to help organizations keep their posture from slouching. Cyera, founded by veterans of the Israeli military’s Unit 8200, uses AI to automatically and continuously identify an organization’s sensitive data and lets security teams literally interrogate their systems for vulnerabilities, generate and enforce new policies, or ask why a defense was triggered. DataGrail and Vanta are also leveraging AI and LLMs to help businesses map their data landscape, allowing customers to manage security and privacy workflows and comply with a growing raft of industry and regulatory frameworks like HIPAA and GDPR.

Being human is one thing—but are you who you say you are? Security mainstay Yubico is focused on a simple but growing vulnerability: the password-based login, which thanks to infostealers and other crimeware, is still a popular entry point for the bad guys. The YubiKey security key lets you log in using numerous multifactor authentication protocols, including biometric identification—without the need to quickly copy a code off your phone. 

“We cannot depend on people” to be a security tool, says DeGrippo, but we can depend “on technology configured properly.” She thinks it’s pointless to blame us humans for getting duped by a hacker’s email—especially as AI gets ever better at tricking us.

Clicking on a phishing link “doesn’t make you unintelligent,” she says. It just “means that there’s someone out there with an organized crime organization going after you while you’re trying to do your job.”

You’re only human after all.

Right?

Explore the full 2024 list of Fast Company’s Most Innovative Companies, 606 organizations that are reshaping industries and culture. We’ve selected the firms making the biggest impact across 58 categories, including advertising, artificial intelligence, design, sustainability, and more.

https://www.fastcompany.com/91038985/security-spotlight-most-innovative-companies-2024?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Created 1mo | Mar 28, 2024, 11:40:04 AM


Login to add comment

Other posts in this group

Banning TikTok just puts a Band-Aid over social media’s problems

When President Joe Biden signed a $95 billion foreign aid bill into law on April 24, it started the clock on a nine-mont

Apr 27, 2024, 1:20:03 PM | Fast company - tech
AI is about to make app subscription fatigue even worse

If you hate dealing with opaque and costly app subscriptions, I’ve got bad news for you: the situation is about to get even worse—and you can blame artificial intelligence for that.

App

Apr 27, 2024, 11:10:02 AM | Fast company - tech
Claros is your AI personal recommendation wizard

Tell me if you can relate to this: The time comes for you to buy something new. Maybe it’s something big and expensive, like a refrigerator. Or maybe it’s something small and insignifi

Apr 27, 2024, 6:30:03 AM | Fast company - tech
Why TikTok’s technology is special

The content recommendation algorithm that powers the online short video platform TikTok has once agai

Apr 26, 2024, 9:20:05 PM | Fast company - tech
Be careful where you upload files: Cybersecurity researchers highlight a new ransomware threat to browsers

You probably know better than to click on links that download unknown files onto your computer. It turns out that uploading files can get you into ransomware trouble, too.

Today’s web br

Apr 26, 2024, 7:10:03 PM | Fast company - tech
Google’s dividend upstages its cloud battle with Microsoft

This story originally appeared in The Technology Letter and is republished here with permission.

Thursday evening’s e

Apr 26, 2024, 4:40:10 PM | Fast company - tech
Tech earnings week turns around after Google, Microsoft, and Snap delight Wall Street

Until late yesterday, major tech stocks were having a pretty rough few weeks. But thanks to premarket surges this morning from Google, Microsoft, and Snap, the final week of April could be a very

Apr 26, 2024, 2:30:06 PM | Fast company - tech