Transfer Learning: Analyst-Sourcing Behavioral Classification

BSidesLV 2017

Presented by: Ignacio Arnaldo, Tim Mather
Date: Tuesday July 25, 2017
Time: 15:30 - 16:00
Location: Ground Truth

Information Security (InfoSec) operations analysts are deluged with data, and that is with not even reviewing a significant portion of an organization's logged data - and certainly not in anything close to real-time. Additionally, too many of the alerts generated by log reviews (e.g., by a SIEM) are false positives - an unnecessary distraction for analysts, and a contribution to the embarrassing number of false negatives. With log volumes growing significantly year over year, a radical change in approach is needed.

Enter AI. Not just machine learning, but AI; specifically, active learning. In this presentation, we will discuss how to augment a critical shortage of trained analyst personnel with active learning, institutionalize their knowledge of benign traffic and attacks, and how to share that knowledge between organizations.

Tim Mather

Long-time information security practitioner, single parent of three (all cats - rescues).

Ignacio Arnaldo

I am working at PatternEx, a Bay Area startup developing an artificial intelligence platform for InfoSec. The platform leverages state-of-the-art machine learning and artificial intelligence algorithms for real-time attack prevention in enterprise applications.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats