As organizations collect increasingly large amounts of security logs from their network and endpoints, this data can be used proactively for breach prevention and mitigation. We are actively working on new AI and machine learning-based techniques to extract meaningful intelligence from different security data sources, and detect security-related anomalies with high accuracy and low false positive rates. Of particular interest are attacks such as advanced persistent threats (APTs) and self-propagating malware (SPM), which are difficult to detect with existing technologies. We are also interested in detecting coordinated attack campaigns across multiple networks, and designing methods for information sharing for more resilient global defenses. The main challenges in deploying these machine learning methods are prioritizing the most important alerts, while reducing false positives and being resilient to adversarial evasion strategies.


