GrrCON

Abstract

Cybersecurity analysis leading to deterrence of cybercrime requires processing thousands to billions of digital signals per second. Those signals must be accurately comprehended, forensically preserved then used to detect and investigate potential cybercrime. The work products must not only assist the investigators but must be translated into language that non-technical lay audiences including judges, lawyers and jurors can understand.

This presentation explores how generative artificial intelligence (GenAI), natural language processing (NLP), graph-theory and artificial narrow intelligence (ANI) can play a role in delivering these outcomes.

The session includes demonstrations of opensource toolkits, datasets and models designed to assist in this work.

Background

Since 2016, WitFoo has researched how artificial intelligence (AI) can be used to synthesize human expertise at multi-Terabyte data rates required in cybersecurity analytics. This session includes a summary of lessons learned from that research concerning analytic modeling. 

Objectives

  • Learn how to build a dataset and train a generative AI model learn it using the ArtiFish toolkit.
  • Understand the strengths and weaknesses of GenAI, NLP, ANI and Graph Theory in cybersecurity analysis.
  • Examine the impact of triaging digital signals on effective analysis.
  • Understand how generative AI can be an effective tool in translating cybersecurity analytic data to non-technical audiences.

 

References

Attachment

About the Author

Charles Herring

Charles Herring

Co-founder & Chairman, WitFoo

I started WitFoo in 2016 to make information and operations shareable across the craft of cybersecurity — between companies, law enforcement, national security and insurers, who mostly cannot see what each other sees. Before that I was at Lancope and Cisco, and I began in 2002 as Network Security Officer for the Naval Postgraduate School.

I lead research and development on a platform that ingests trillions of messages a day across hundreds of clusters. It is sold as Conductor, Reporter and Analytics, licensed flat per appliance with unlimited data — because a team charged by the gigabyte ends up making coverage decisions on a spreadsheet, months before the incident that needed the logs they dropped.

Everything here is mine, not the company's, and it wanders. Corrections are genuinely welcome — I would rather be right than consistent.

A note on how this was written: I use artificial intelligence tools to help me research, check facts, and edit these posts. The ideas, the arguments, and any mistakes are mine. I read the sources, I check the claims, and I take full responsibility for what I publish here. The views are my own and the writing is my intellectual property.