SAN FRANCISCO – Artificial intelligence (AI) and diversity are two key and connected components to fighting the ongoing surge in cyberattacks, which has doubled over the past year to an amount not easy to fathom.
Vasu Jakkal, corporate vice president for Microsoft Security, Compliance, and Identity, said during a keynote address at this week’s RSA Conference that "the vendor is now tracking 921 attacks per second, which is twice the amount it was seeing a year ago."
Those attacks are also getting more sophisticated and targeted, and it is putting further strain on systems designed to defend against those attacks.
“We have to push relentlessly on the borders and the boundaries of technology innovation,” Jakkal urged. “Because, guess what, our adversaries are definitely pushing on those boundaries.”
AI is emerging as one of those technology innovations apt to provide the most bang for that development buck, especially in how it can extend the boundaries of human expertise.
“For all that hype today, there are relatively few use cases we can point to that are clear, accurate, and attributable to AI,” Jakkal said. “But, and that's a big but, without AI we simply cannot scale our defenses at the rate of attack to fight this asymmetric war, and it's pretty asymmetric out there. We have to use AI and all of its superpowers.”
Jakkal explained that one of AI’s most important uses today is in detection. She noted AI is incredibly effective in processing and classifying large amounts of data and determining “what’s good, bad, and large?”
“At Microsoft, we process 24 trillion signals every single day,” Jakkal said, noting this was across identities, end points, devices, and collaboration tools. “And without AI, we simply could not tackle this.”
This load is a challenge, but it also helps to power AI systems. This insight can be turned back into those platforms using machine learning to make them smarter.
Diversity Required for AI EthicsHowever, the challenge then becomes in determining if this increased data collection is being used in an ethical manner. This requires those collecting and analyzing that data to have processes in place that can manage and implement ethical best practices.
“We need more data to be effective. And yes, absolutely, we need to be responsible, we need to be ethical, and we need to have privacy at its heart and core,” Jakkal said. “But when we have more data, and when we share more data, when we come together for that, AI can be really effective.”
Diversity is key to ensuring data is being collected and used in an ethical manner. This requires the cybersecurity industry to attract and retain a workforce representative of people and groups that have historically been on the outside looking in.
Jakkal cited numbers that showed just 24% of the global cybersecurity workforce is women, and only 20% of that workforce are people of color. And she added that attackers are able to exploit these biases.
“When you think about the diversity, our attackers are diverse, and they exploit the seams,” Jakkal said. “They exploit biases in our systems when we have homogenous teams.”
To counter this, the industry needs to re-examine how it attracts workers, or as Jakkal said, it needs to go “to different watering holes for these people.”
This aligned with a report earlier this year from Gartner that IT organizations with high overall diversity tend to churn out more innovative products and strategies, are more productive on metrics that matter to business leaders, and increase profits.
“We need to create platforms where every person no matter who you are, can do your best work and thrive.” Jakkal added.
Comments