Fusion of Deception and AI for Active Defense

Satnam Singh, PhD, Chief Data Scientist at Acalvio

Recent cyber attacks and data breaches clearly show that traditional perimeter-based information security tools are ineffective against ransomware attacks, insider attacks, multi-stage attacks, and APTs. Cyber criminals have crafted tools and devised techniques that enable them to evade detection by traditional security tools. Also, even if real alerts are triggered, they can either get lost among a large number of false alerts or lost in a deluge of alerts, resulting in very low signal/noise ratio. Deception provides an alternative tool to traditional tools with nearly 0% false positive rate to detect, engage, trap and remediate inside-network attacks. Furthermore, by fusing deception with AI, one does not need to boil the ocean to detect anomalies in raw data. Instead anomalies are surfaced itself when an attacker bumps into the deceptions. Using AI, deception alerts are correlated with other data sources to provide actionable insights about the adversary profile, lateral movements and attack tactics. In this talk, we share our work on the fusion of deception and AI for active defense.

Acalvio provides Advanced Threat Defense (ATD) solutions to detect, engage and respond to malicious activity inside the perimeter. The solutions are anchored on patented innovations in Deception and Data Science.