ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Staying cyber-secure with AI and Machine Learning

cyber-security and AI
cyber-security and AI

Kevin Curran at Ulster University explains how artificial intelligence is bringing cyber-security to a new level of effectiveness

 

The vast adoption of artificial intelligence (AI) in recent years is fundamentally transforming the way society behaves. According to research from Cybercrew, there were approximately 1,070 artificial intelligence companies in the UK in 2010 while in 2018 there were more than 2,500, showing the rapid rate of growth within the industry. 

 

Although there is risk associated with the technology, such as bias, poor decision-making, low transparency and potential job losses, it is undeniable that AI plays a huge role within a number of industries. For example, healthcare professionals utilise it to diagnose diseases and develop clinical pathways.

 

Another paramount use of AI is the way it protects us online, by helping to prevent security attacks.

 

The core structure of AI

Like other technical innovations, many believe AI is over-hyped when it comes to its application in domains. This happens a lot in cyber-security, where vendors use terms such as AI to advertise a product as more sophisticated.

 

In reality, a lot of the time, these products will simply follow traditional rules and techniques to classify threats. This makes AI little more than an industry buzzword. Despite this, AI has the potential to significantly impact the way organisations protect themselves in the coming years.

 

Machine learning is a type of artificial intelligence that enables software applications to become more accurate at predicting outcomes. Essentiallyit is the process of building a scientific model after discovering knowledge from a data set.

 

These methods can be categorised into symbol-based, connectionist-based, behaviour-based, and immune system-based activities.

 

Machine learning can also replicate some specific elements of intellectual ability, enabling computers to solve problems in limited realms. Although the basic idea of machine learning is quite simple, the execution can be extremely complicated.

 

Firstly, the algorithm gathers facts about a situation through sensors or human input. Then, the computer compares the stored data and decides what it signifies. Once this is done, it runs through various possible actions to predict which action will be most successful.

 

The role AI plays in cyber-security

On a global scale, many organisations are dealing with economic challenges as a result of the ongoing pandemic and global issues. Unfortunately, cyber-criminals are provided with an opportunity here, as they can take advantage of vulnerabilities within areas such as the supply chain.

 

Therefore, enterprises need to be as prepared as possible and should implement the required tools ahead of time before any true damage is done.   

 

Machine learning and other interdisciplinary capabilities can address the challenges of securing enterprises, as they use statistics and pattern recognition to discover previously unknown valid patterns in large data sets. One key area to apply machine learning would be in anomaly detection which can target any event falling outside of a predefined set of normal behaviours. 

 

Anomaly detection needs to define a profile of normal behaviours, which reflects the health and sensitivity of a cyber-infrastructure. This is where behavioural analytics can contribute: it assists in isolating patterns in an enterprise’s data which do not conform to the expected behaviours. Examples of these might include outliers, abbreviations, contaminants, and unexpected behaviour within the enterprise system applications.

 

It is essential for organisations to recognise the limitations of computing power and the sophistication of machine learning algorithms. A computer can only solve problems it is programmed to solve, as it does not have any generalised analytical ability.

 

Limitations that need to be overcome are the degree to which data should be balanced, so that ordinary machine-learning methods work, and the best performance metric for imbalanced learning intrusion or spam detection systems can be easily defined. 

 

In addition, trusted data sets or data generation tools are needed, due to the fact that there are few publicly available data sets, such as train intrusion detection systems. The lack of proper evaluation data sets hampers the fair evaluation of any machine learning systems, as these data generation tools should be able to consider both the normal network traffic conditions and the anomalous traffic flows in any test traffic traces.

 

One general problem with machine learning is that it can be hard to find the dominant trends for profiling cyber information to simplify data sets into lower dimensions. 

 

Undoubtedly, the role of machine learning and AI in cyber-security is increasing significantly, particularly as more challenges appear with the rapid development of information discovery techniques.

 

Combined with this, is the dynamic change of threats, and the severe imbalanced classes of normal and anomalous behaviours. As a result of the constantly evolving cyber-threats, building static defence systems for discovered attacks is not enough to protect users.

 

Of course, more sophisticated techniques such as machine learning and AI can discover lurking cyber intrusions which may not have been noted without machine learning pattern matching. However, these techniques must be adaptive and self-learning in complex network trafficking to preserve accuracy and a low false acceptance rate.

 


 

Kevin Curran is IEEE senior member and professor of cyber-security at Ulster University

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543