SAN FRANCISCO – Keeping identities and authentication safe from bad actors at all levels of IT security isn't simply a name, biometric or password problem anymore. It's fast becoming a data problem for artificial intelligence (AI) and machine learning (ML) to help solve.

In 2021, the Biden Administration ordered all civilian government agencies to establish and implement a zero-trust security plan by the end of September 2024. Zero trust is a security model that assumes that no user or device can be trusted by default, and that access to resources must be verified at all times. This model is in contrast to the traditional security model, which assumes that users and devices are trusted within the network perimeter.

With this federal mandate, security software providers are retooling their products and services in order to keep up with where the trend is headed.

RSA says it has been on this since long before the mandate. As it hosts its annual conference here at the Moscone Center, the Bedford, Mass.-based company today revealed additional updates to its enterprise platform that lean even more on generative AI to make it even smarter than it already is.

The overall preponderance of data – personal, business and machine-made – is the key trigger for all this change, RSA Chief Product Officer Jim Taylor told SDxCentral.

Taylor, explaining the long-term importance of AI to the company's identity product plans, told SDxCentral that "the goal is that we get to things like dynamic data, recommendation engines, you know, those kinds of things. We're seeing this explosion of data and entitlements (that require zero trust); identities have become a data problem over the last couple of years.

RSA says the deluge of data calls for AI

"To be able to manage that, it goes beyond being a personal problem – it's become a superhuman problem. So you really need AI to be able to evaluate in real time a lot of those risks and a lot of those contexts," Taylor said.

RSA, long a major contractor for the U.S. federal government, also revealed today how its updated Unified Identity Platform will integrate the authentication, access, governance and lifecycle data federal agencies need to meet EO 14028, OMB M-22-09 and the National Cybersecurity Strategy, Taylor said. Its FIDO2-certified, anti-phishing DS100 hardware authenticator uses proprietary technologies, open standards and FedRAMP JAB P-ATO approval to provide new capabilities for public sector agencies, government contractors and systems integrators, he said.

The new software package will become generally available later this year, the company said.

AI and social platforms are a dangerous combo

"Just having credentials to log on is not sufficient anymore," Taylor told SDXCentral. "You need more than that. We are starting to see things like AI malware. People are using AI engines for hacking, which is a terrifying prospect – because when you think about the most predominant AI, it's in social platforms.

"Think about Cambridge Analytics; what does Facebook know about people? What do social engineers know about people? So if I use an AI engine for nefarious purposes, I can gather a whole bunch of data around you, and I can potentially create a deep fake. I can spoof your credentials. So the protection part of that equation needs to be equally equipped; we need to use AI as a weapon for good to combat AI, because it is really good at recognizing some of those nuanced patterns."

In addition to the capabilities listed above, AI can also improve the following aspects of zero-trust security:

  • Scalability: AI can be used to scale zero trust security to meet the needs of large organizations.
  • Cost-effectiveness: AI can help to reduce the cost of zero-trust security by automating tasks that would otherwise be performed by human analysts.
  • Reliability: AI can help to improve the reliability of zero-trust security by reducing the risk of human error.

Overall, AI is has become a critical enabler of zero-trust security. Without AI, it would be difficult to implement and maintain a security posture that is effective against today's advanced threats, Taylor said.