Artificial Intelligence and Machine Learning for Network Security: Quo Vadis?
摘要
Today, the ever-growing world of interconnected devices and networks are faced with a new and constantly evolving threat landscape that can no longer be protected with basic network monitoring and analysis tools and traditional network intrusion detection systems. As a result, artificial-intelligence (AI) and machine learning (ML) is increasingly becoming the focal point of many advancements in network intrusion detection systems. Consequently, in an effort to counter AI/ML driven security and evade detection, adversaries have engaged in new and never before seen attacks against the AI/ML models in network intrusion detection systems. Such attacks are commonly referred to as adversarial ML. The defense of AI/ML systems against adversarial ML in many application domains has drawn significant research and development attention, but none more than image recognition. However, these defenses are specific to the field of image recognition and may not transfer to a network intrusion detection context, which we present in this chapter. Additionally, there is a lack of emphasis on the defense of traditional AI/ML systems such as Support Vector Machine (SVM), Random Forest, and Gradient Boosting, which are favored in the network intrusion detection domain. In this chapter, unlike most previous work that have evaluated the security of AI/ML systems from the perspective of adversarial ML, we evaluate security of AI/ML systems from an end-to-end perspective that accounts for vulnerabilities in software dependencies and supply chain and discusses the need for a vulnerability disclosure program in AI/ML.