Artificial Intelligence & Machine Learning
,
Next-Generation Technologies & Secure Development
Five Eyes Share Optimism on the Impact of AI on the Balance of Power in Cyberspace
Artificial intelligence will help both attackers and defenders in cyberspace, but will net out to the benefit of defenders – although it will get “bumpy” on the way there, senior officials from the national cybersecurity centers of all the Five Eyes treaty partner nations said last week.
See Also: A Darkening Landscape: AI, Friend and Foe of Cyber Resilience
“I think we’ve seen a bit of the bumps, and I’m sure there’ll be more to come,” U.K. National Cyber Security Centre CEO Richard Horne said Sept. 8 at a Billington Cybersecurity Summit Panel in Washington, D.C.
AI is not replacing human cybersecurity analysts, but rather boosting their productivity by orders of magnitude, added Rajiv Gupta, the head of the Canadian Centre for Cyber Security, a part of the Communications Security Establishment Canada, the nearest thing Ottawa has to the National Security Agency.
AI is very good at very narrow, specialized elements of the analytic process such as malware reverse engineering and vulnerability detection, said Gupta. “Where we get to is being able to spread that right across the whole [analytic] chain and being able to … automate cyber defense life cycles right across from beginning to end,” to scale and speed the response to new attacks, he said.
Gupta said AI will empower rather than replace analysts or other human knowledge workers in the intelligence field. Their productivity could rise by “10x or 20x,” he said. “So, how do we use that wealth of expertise to actually augment those cyber specialists, intelligence specialists, to make sure that we’re getting the most out of every single one of them?”
There’s at least one valuable use case of AI for cyber defense: Data analysis, said Stephanie Crowe, who leads the Australian Cyber Security Centre, part of Canberra’s NSA equivalent, the Australian Signals Directorate.
“There’s this volume of data they have to look through in order to defend their network,” she said, referring to the huge quantities of telemetry and other data collected by modern network defense tools.
AI would allow defensive tools to “only collect the data you need to collect to defend networks,” Crowe said.
She added secure deployment of new technologies was key. “Like any other piece of new technology or software, you have to make sure it’s designed securely, deployed securely and used securely,” she said.
The remarks are noteworthy as they represent the consensus wisdom of the Five Eyes nations – Australia, Canada, Great Britain, New Zealand and the United States – on one of the key and possibly existential questions of our times: What impact will AI have on cybersecurity?
The remarks, which represent the judgement of officials from the most cyber-empowered democracies, cut through the viral fear, uncertainty and doubt and marketing claims that tend to dominate the conversation.
David Imbordino, director of the NSA’s Cybersecurity Directorate, explained that the role of intelligence has always been to distinguish the signal from the noise. “We’re looking at how we use AI to triage so much more volume. Volume has always been a problem, but now how can we get to the nuggets a lot quicker?”
Drawing the line where AI could be trusted was important, said Catriona Robinson, deputy director-general for cybersecurity at the National Cyber Security Centre, part of New Zealand’s Government Communications Security Bureau.
“Machine verification” is something Auckland has been working on, Robinson said. “Autonomy is okay where you’ve got good verification wrapped around the trust that you’ve set in the AI,” she said.
