Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

9/4/2019
05:47 PM
Dark Reading
Dark Reading
Products and Releases
0%
100%

Darktrace Cyber AI Analyst Investigates Threats At Machine Speed

Augments Human Security Teams Reducing Time to Triage by 92%

Cambridge, UK – Wednesday, September 4th, 2019 – Darktrace, the world’s leading cyber AI company, has today announced the launch of the Cyber AI Analyst, a new technology that emulates human thought processes to continuously investigate cyber-threats at machine speed. With the power to transform the security industry, early adopters of this technology reported a 92% reduction in the time required to investigate threats and provide conclusions to executives.

This ground-breaking innovation is the culmination of over three years of research at the Darktrace R&D Center in Cambridge, UK. Using various forms of machine learning, including unsupervised, supervised, and deep learning, the technology learned human intuition and trade craft from more than 100 world-class cyber analysts across thousands of customer deployments.

Typically, a human analyst will spend anywhere between half an hour and half a day investigating a single suspicious security incident. They look for patterns, form hypotheses, reach conclusions about how to mitigate the threat, and share the findings with the rest of the business. Darktrace’s Cyber AI Analyst accelerates this process, continuously conducting investigations behind the scenes and operating at a speed and scale beyond human capabilities.

“Darktrace’s Cyber AI Analyst quickly presents security information in a format that’s both elegant and intuitive,” commented Chris Kissel, Research Director at IDC. “By automatically investigating security events, the AI Analyst helps reduce noise more than any other technology. This is an important development in the security industry. 

“These are exactly the kinds of security insights my team wants to have at their fingertips,” commented Dan McNamara, CTO at Medreview. “Automating as much of incident response as possible is the end-game. The AI Analyst is the obvious next step and a clear evolution of the Darktrace platform.”

By learning from the millions of interactions between Darktrace’s expert analysts and Darktrace’s flagship solution, the Enterprise Immune System, the Cyber AI Analyst combines human expertise with the consistency, speed, and scalability of AI. The ability of AI to investigate every possibility, make connections between seemingly disparate events, and quickly illuminate the full scope of a security incident dramatically reduces ‘time to meaning’ and buys back time for human teams. 

“The burden of investigating threats typically falls on the shoulders of a small number of trained security professionals,” commented Mike Beck, Global Head of Threat Analysis, Darktrace. “With Cyber AI Analyst, security teams can now rely on AI to investigate hundreds of threats at once, allowing human analysts to focus on the most strategic work.”

About Darktrace

 

Darktrace is the world’s leading cyber AI company and the creator of Autonomous Response technology.

Its self-learning AI is modeled on the human immune system and used by over 3,000 organizations to protect against threats to the cloud, email, IoT, networks and industrial systems. This includes insider threat, industrial espionage, IoT compromises, zero-day malware, data loss, supply chain risk and long-term infrastructure vulnerabilities.

The company has over 900 employees, 40 offices and headquarters in San Francisco and Cambridge, UK. Every 3 seconds, Darktrace AI fights back against a cyber-threat, preventing it from causing damage.

 

# # #

 

 

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-8423
PUBLISHED: 2020-04-02
A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the configuration of the Wi-Fi network.
CVE-2019-14868
PUBLISHED: 2020-04-02
In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those env...
CVE-2019-20635
PUBLISHED: 2020-04-02
codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class loader via computed fields.
CVE-2020-11452
PUBLISHED: 2020-04-02
Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases. By providing an external URL under attacker control, it's possible to send requests to external resources (aka SSRF) or leak files from the local system using the f...
CVE-2020-11453
PUBLISHED: 2020-04-02
Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStrategyWS/. The functionality requires no authentication and, while it is not possible to pass parameters in the SSRF request, it is still possible to exploit it ...