/* ---- Google Analytics Code Below */
Showing posts with label Risks. Show all posts
Showing posts with label Risks. Show all posts

Monday, March 13, 2023

Do We Need a National Algorithms Safety Board?

 Safety is yes, means of determining that is the issue.    Especially with regard to transportation and related supply chain decisions and risks. 

Do We Need a National Algorithms Safety Board?

By The Hill, February 28, 2023,     Opinion Piece

A close-up of hands on a laptop keyboard, with image overlays of various tech-based iconography.

Perfectly safe algorithmic systems are not possible, but safer systems are.

In the U.S., the National Transportation Safety Board is widely respected for its prompt investigations of plane, train, and boat accidents. Could a National Algorithms Safety Board have a similar impact in increasing safety for algorithmic systems, especially the rapidly proliferating artificial intelligence applications based on unpredictable machine learning? Alternatively, could agencies such as the Food and Drug Administration, Securities and Exchange Commission, or Federal Communications Commission take on the task of increasing safety of algorithmic systems?

From The Hill   View Full Article

Tuesday, October 11, 2022

Crypto Declared a Risk

Crypto is Possible Systemic Risk

ACM NEWS

FSOC Warns Crypto is Possible Systemic Risk

By Politico, October 4, 2022

Said U.S. Treasury Secretary Janet Yellen, “We've seen very significant shocks and volatility within the crypto asset system, particularly over the last year.”

Top U.S. banking and markets regulators on Monday warned that the crypto industry could pose a major risk to the financial system if lawmakers and agencies don't act soon to set ground rules.

The Financial Stability Oversight Council — a Treasury-led panel of top officials from the Federal Reserve, SEC and other agencies — released a 120-page report that identified a wide range of regulatory gaps and market risks affecting everything from Bitcoin trading platforms and stablecoins to consumer protection and cyberattacks.

Those risks will get more severe as the industry expands and digital asset businesses forge ties with traditional financial institutions like banks and payment systems, according to the report, which was produced in accordance with President Joe Biden's March executive order on crypto.

From Politico

View Full Article

Tuesday, April 05, 2022

Explainable AI Risks

Excerpt From  Opinion Section of ACM.  Fascinating piece here.  

Explainable AI

By Veda C. Storey, Roman Lukyanenko, Wolfgang Maass, Jeffrey Parsons

Communications of the ACM, April 2022, Vol. 65 No. 4, Pages 27-29   10.1145/3490699

Advances in AI, especially based on machine learning, have provided a powerful way to extract useful patterns from large, heterogeneous data sources. The rise in massive amounts of data, coupled with powerful computing capabilities, makes it possible to tackle previously intractable real-world problems. Medicine, business, government, and science are rapidly automating decisions and processes using machine learning. Unlike traditional AI approaches based on explicit rules expressing domain knowledge, machine learning often lacks explicit human-understandable specification of the rules producing model outputs. With growing reliance on automated decisions, an overriding concern is understanding the process by which "black box" AI techniques make decisions. This is known as the problem of explainable AI.2 However, opening the black box may lead to unexpected consequences, as when opening Pandora's Box.

Black Box of Machine Learning

Advanced machine learning algorithms, such as deep learning neural networks or support vector machines, are not easily understood by humans. Their power and success stems from the ability to generate highly complex decision models built upon hundreds of iterations over training data.5 The performance of these models is dependent on many factors, including the availability and quality of training data and skills and domain expertise of data scientists. The complexity of machine learning models may be so great that even data scientists struggle to understand the underlying algorithms. For example, deep learning was used in the program that famously beat the reigning Go world champion,6 yet the data scientists responsible could not always understand how or why the algorithms performed as they did.

Opening the black box involves providing human-understandable explanations for why a model reaches a decision and how it works.

Opening the black box involves providing human-understandable explanations for why a model reaches a decision and how it works. The motivation is to ensure decision making is justified, fair, and ethical, and to treat the "right to explanation" as a basic human right.7 Notably, the European Union's General Data Protection Regulation requires companies to provide "meaningful information" about the logic in their programs (Article 13.2(f)). The goal is to ensure the rules, data, assumptions, and development processes underlying a machine learning model are understandable, transparent, and accessible to as many people as possible or necessary, including managers, users, customers, auditors, and citizens.

The explainable AI challenge usually focuses on how to open the black box of AI; for example, by considering how various features contribute to the output of a model or by using counter-factual explanations that measure the extent to which a model output would change if a feature were missing.7 We pose a seldom-asked, but vital, question: Once a mechanism is in place to open the black box, how do we, as a society, prepare to deal with the consequences of exposing the reasoning that generates the output from AI models?

Pandora's Box of Explainable AI

In Greek mythology, Pandora's Box refers to a container of evils that are unleashed and cannot be contained once the box is opened. We employ this analogy because, although opening the black box of AI may shed transparency on the machine learning model, it does not mean the processes underlying the model are free of problems. As in Pandora's Box, these problems are revealed once we move from a black box to a white box of AI. Machine learning explainability is a worthy goal; however, we must prepare for the outcome. Opening the black box can metaphorically open a Pandora's Box, as shown in the accompanying figure. .... '

Friday, January 28, 2022

Tesla Hacking Possible

 Probably possible in many modern automobile applications, good to see the warning early.

Third-Party Software for Teslas Can Be Hacked, German Teen Says

Bloomberg, Katrina Nicholas; Jordan Robertson, January 12, 2022

German teenager David Colombo claims to have discovered flaws in third-party software that could allow hackers to remotely hijack certain functions of Tesla cars. He tweeted that the software insecurely stores data required to link the cars to the software, which hackers could steal and use to send malicious commands to the vehicles. Colombo reportedly exploited the vulnerability to unlock doors and windows, start cars without keys, and deactivate their security; he also said he could see if a driver was in the vehicle, turn on stereo systems, and flash headlights. Colombo said he was able to access over 25 Teslas in at least 13 countries via the flaw. He asked Bloomberg not to publish specifics of the exploit, as the company that makes the affected software has not yet released a patch.

Monday, January 03, 2022

On Quantum Related Risk

 Good overview of the risks to be considered regarding.

Quantum Computing Is for Tomorrow, But Quantum-Related Risk Is Here Today   

By Kevin Townsend on January 03, 2022  in Security Week

Booz Allen Hamilton has analyzed the quantum computing arms race to determine China’s current and future capabilities, and to understand the likely use of China’s cyber capabilities within that race. It concludes, “Risk management must start now.”

The report is really in two halves. The first describes the cybersecurity threat inherent in the quantum arms race, while the second is a primer on the complexities of quantum computing. While this is worth reading, only the cybersecurity threats are relevant to us here.

The two cybersecurity threats

Theft of quantum-relevant research

The background is China’s avowed intention to lead the world in technology and economy. The former is key to the latter; and being first to achieve quantum computing will be a major fillip. For now, China is behind the U.S. and Europe in quantum research but claims it will achieve at least parity by the mid-2020s.

Booz Allen is not convinced this will happen, but believes that China may be the first to achieve limited use cases in quantum computing. The first practical benefits from quantum are likely to come from quantum simulators rather than general purpose quantum computing. These are sometimes called ‘noisy intermediate scale quantum’ (NISQ) computers, so named by John Preskill, a quantum physics researcher at Caltech. 

They will be able to outperform classical computers in areas that include quantum properties – such as drug research. Booz Allen sees this area as providing the earliest quantum computing benefit. In the shorter term, the best quantum simulators will provide the greatest economic benefit.

This is not a cybersecurity threat. But western research in this area will be a primary target for Chinese threat groups seeking to ensure that Chinese capabilities remain at the forefront.

Quantum decryption

The most direct cybersecurity threat will come from quantum-assisted asymmetric decryption – that is, the ability to crack the public key encryption ubiquitous in communications. A quantum asymmetric decryption algorithm was developed by mathematician Peter Shor as long ago as 1994. Although still largely theoretical, it is believed that this algorithm will crack asymmetric encryption at usable speeds as soon as a sufficiently powerful quantum computer is developed. The report suggests this could be achieved as early as 2027, but is more likely to be impossible before 2030

Booz Allen alludes to this threat in three of its five ‘anticipated quantum computing threats from China’: theft of encrypted data with an expectation of future quantum-assisted decryption; adversarial development of quantum-assisted decryption sooner than quantum-resistant encryption can be deployed; and unobservable adversarial development of quantum-assisted decryption. .... ' 

Thursday, July 29, 2021

Cost of Data Breaches

What it costs to have a Data Breach, useful data.

IBM Report: Data-Breach Costs Hit 17-Year High of $4.24M

Nancy Chenyizhi Liu | Editor in SdxCentral

July 28, 2021 12:01 AM

Data-breach costs jumped nearly 10% from an average of $3.86 million to $4.24 million per incident over the past year, according to IBM’s latest Cost of a Data Breach Report.    It marks the highest average total cost in this report’s 17-year history and the largest single-year increase in the last seven years. 

The 2021 Cost of a Data Breach Report  is based on analysis of 537 real-world data breaches in 17 different industries across 17 countries and regions that occurred between May 2020 and March 2021.

Despite the overall cost growth, organizations with more mature security postures that deployed tools including artificial intelligence (AI), automation, zero trust, and cloud security saw significantly lower costs.

IBM’s report indicates that around 35% of the surveyed organizations had implemented a zero-trust security approach, and 48% of those were in the mature stage. The average data breach cost for companies with a mature zero-trust strategy was $3.28 million, which was $1.76 million less than the ones without zero trust.    ... ' 

Thursday, March 11, 2021

Web As We Know it Ending?

 Changing yes, but ending now.  We are too dependent on it for too many things.  No doubt using it is getting trickier.  Need to look closer at risks and Threats. 

The Worldwide Web As We Know It May Be Ending   By CNN in ACM   February 25, 2021

Over the last year, the worldwide web has started to look less worldwide.

Europe is floating regulation that could impose temporary bans on United States tech companies that violate its laws. The U.S. was on the verge of banning TikTok and WeChat. India is now at loggerheads with Twitter.

If such territorial clashes become more common, the globally-connected Internet we know will become more like what some have dubbed the "splinternet," or a collection of different Internets whose limits are determined by national or regional borders.

A combination of rising nationalism, trade disputes, and concerns about the market dominance of certain global tech companies has prompted threats of regulatory crackdowns all over the world. These forces are not just upending the tech companies that built massive businesses on the promise of a global Internet, but also the very idea of building platforms that can be accessed and used the same way by anyone anywhere in the world.

From CNN

Sunday, February 14, 2021

Ready for the Next Pandemic

Lets do this without destroying the education of the current generation. 

A number of articles on the proposition that we will be ready.  in IEEE Spectrum

COVID-19 has galvanized tech communities. The tens of billions we’re spending on vaccines, antivirals, tests, robots, and devices are transforming how we’ll respond to future outbreaks of infectious disease.

Here’s How We Prepare for the Next Pandemic

If we keep developing the tech that has been supercharged for COVID-19, it never has to be this bad again By Eliza Strickland and Glenn Zorpette  ... 

Thursday, February 11, 2021

India Analyzing Data Goals and Gaps with AI

Notable use  of AI and other pattern recognition approaches: What data do we have, its ability, to achieve certain levels of understanding of our economy.   Then what data, quality of data, and metadata is needed at what cost, to further tune that understanding?   Note out past looks at the 'data as an asset', for more explorations of this.   Gaps analysis to achieve goals.  With risks considered along the way.   Note the mention of real-time data. 

AI Is India's Solution to Fix Data Gaps   By Bloomberg Quint, February 11, 2021  in   ACM

India is turning from man to machines to improve the quality and speed of its economic data.

India's Ministry of Statistics is accelerating artificial intelligence (AI) usage for collecting, analyzing, and disclosing data to better monitor the economy, including an initiative with the World Bank employing an information portal that collates real-time data.

The Ministry's Kshatrapati Shivaji said, "There's a growing need for more and more data, faster data, and also more refined data products," and end-to-end computerization "will enhance the quality, credibility, and timeliness of data."

He added that AI will see extensive use, and help to overcome staffing limitations.

Shivaji said, "Because of automation and technology-intensive applications, the capability and productivity of staff is getting enhanced substantially. Wherever there is a component where we're able to squeeze the time with the help of technology, we're trying to do that."

From Bloomberg Quint in ACM

Tuesday, May 19, 2020

Why We Need Bayesian

This link is first a reminder to myself that we need to continually promote means of risk and uncertainty awareness in models.    Meta-reasoning is always important.  Thinking about the context in which your models will be used.  If you don't do that you have missed something important.  Understanding the risks it will have in use.   The article gets quite technical, but the intros are worthwhile to read.  And there are links to good online courses, which  also have good intros.

Bayesian meta-learning
This story introduces bayesian meta-learning approaches, which covers bayesian black-box meta-learning, bayesian optimization-based meta-learning, ensembles of MAMLs and probabilistic MAML. This a short summary of the course ‘Stanford CS330: Multi-Task and Meta-Learning, 2019 | Lecture 5 — Bayesian Meta-Learning’.
By Qiurui Chen in TowardsDataScience

For meta-learning algorithms, 3 algorithmic properties are important: expressive power, consistency, and uncertainty awareness. Expressive power is the ability for f to represent a range of learning procedures, it measures scalability and applicability to a range of domains. Consistency means learned learning procedure will solve tasks with enough data, this property reduces reliance on meta-training tasks, which leads to good out-of-distribution performance. Uncertainty awareness is the ability to reason about ambiguity during learning. It allows us to think about how we might explore new environments in a reinforcement learning context in order to reduce our uncertainty. It also thinks about if we are in safety-critical settings, we want to calibrate uncertainty estimates. It also allows us to think about, from the Bayesian perspective of Meta-learning, what sort of principle approaches can be derived from those graphical models?

This story covers 1. Why be Bayesian? 2. Bayesian meta-learning approaches 3. How to evaluate Bayesians ... "   ...'

Friday, April 17, 2020

Cybersecurity Risk

Advancing for some time now,  but at least we should be able to assemble defenses for the inevitable?

Why Is Cybersecurity Not a Human-Scale Problem Anymore?
By Gaurav Banga
Communications of the ACM, April 2020, Vol. 63 No. 4, Pages 30-3410.1145/3347144

Rarely a day goes by that we don't see news about the poor state of affairs in cybersecurity. From data breaches at Target, the U.S. Office of Personnel Management, Sony, Disney, Yahoo!, Equi-fax and Marriot, the drumroll continues unabated. We are now in a world, where it's a matter of when, not if, an organization is compromised by a cyber-attack.

Most of us think of cybersecurity as a series of controls (tools and knobs) that an organization has to implement, and it seems perplexing why cyber-defenders in the situations mentioned here failed to take the necessary steps to protect themselves. Our focus on addressing cybersecurity challenges has been around inventing new controls (or enhancing existing ones) and implementing them correctly in the enterprise. This is an inadequate view.  ... ." 

Friday, March 27, 2020

On Novel Risks in the Enterprise

Something we studied in some detail, solution was to have sufficient knowledge and resources, internal and access to external to be able to address the context of such problems.   Making them less 'Novel'.    Not sure how well that works in the current situation.

Novel Risks   by Robert S. Kaplan, Dutch Leonard, and Anette Mikes  in HBSWK

Companies can manage known risks by reducing their likelihood and impact. But such routine risk management often prevents them from recognizing and responding rapidly to novel risks, those not envisioned or seen before. Setting up teams, processes, and capabilities in advance for dealing with unexpected circumstances can protect against their severe consequences.

Author Abstract
All organizations now practice some form of risk management to identify and assess routine risks for compliance—in their operations, supply chains, and strategy, as well as from envisioned external events. These risk management policies, however, fail when employees do not recognize the potential for novel risks to occur during apparently routine operations. Novel risks—arising from circumstances that haven’t been thought of or seen before—make routine risk management ineffective, and, more seriously, delude management into thinking that risks have been mitigated when, in fact, novel risks can escalate to serious if not fatal consequences. The paper discusses why well-known behavioral and organizational biases cause novel risks to go unrecognized and unmitigated. Based on best practices in several organizations, the paper describes the processes that private and public entities can institute to identify and manage novel risks. These risks require organizations to launch adaptive and nimble responses to avoid being trapped in routines that are inadequate or even counterproductive when novel circumstances arise.  .... 

Paper:  http://www.hbs.edu/faculty/pages/download.aspx?name=20-094.pdf 

Sunday, March 15, 2020

Slowing Down for Decisions in Crisis

Sensible, but depends on the flow of  risk as well.

Slow Down to Make Better Decisions in a Crisis  by Art Markman in HBR

The news about the spread of COVID-19 is changing fast — and people are trying to make decisions about everything from whether to cancel vacations to how to best protect themselves and their communities. There are several psychological reasons why you may find decision-making difficult right now.

First, there is a looming present threat. The disease is real. Around the world, people are dying from it and it is spreading rapidly enough that there is new news every day. Humans are wired to pay attention to threats, and so this story captures our attention in a way that a distant threat like climate change does not.

Second, there is a lot of uncertainty about the spread of the virus — how many people have it, how quickly it’s moving through communities, how many people will ultimately get it. When it comes to future projections, we’re good at understanding linear trends. We are bad at understanding trends that involve an accelerated growth like an exponential function. At the front end of a bloom in a virus, there will be few cases, but they can grow rapidly. The uncertainty that creates for people increases our attention to it. .... "

Wednesday, January 29, 2020

NIST Privacy Framework

Brought to my closer attention this week.   An excellent checklist for important privacy issues in current and approaching technology contexts.  Currently reviewing for projects underway.   Like the fact that this is considering the risk dimension.  More on this to follow.

National Institute of  Standards and Technology  (US Dept of Commerce)

The NIST Privacy Framework is a voluntary tool developed in collaboration with stakeholders intended to help organizations identify and manage privacy risk to build innovative products and services while protecting individuals’ privacy. .... 

https://www.nist.gov/privacy-framework   Overview 

https://www.nist.gov/system/files/documents/2020/01/16/NIST%20Privacy%20Framework_V1.0.pdf   40 Page pdf

Wednesday, June 19, 2019

Waking up to New Risks

In some ways we saw this coming,  risk was increasing, and that risk was coming from within in things we had specifically built.   Our internet of things

Deep Insecurities: The Internet of Things Shifts Technology Risk
By Samuel Greengard
Communications of the ACM, May 2019, Vol. 62 No. 5, Pages 20-22
10.1145/3317675

It is human nature to view technology as a path to a better world. When engineers and designers create devices, machines, and systems, the underlying premise is to deliver benefits. The Internet of Things (IoT) is certainly no exception. Smartphones, connected cars, automated thermostats, smart lighting, connected health trackers, and remote medical devices have made it possible to accomplish things that once seemed impossible. Everything from toothbrushes to tape measures are getting "smart."

However, at the center of the tens of billions of connected devices streaming and sharing data lies a vexing problem: cybersecurity. It is no secret that hackers and attackers have broken into baby monitors, Web cameras, automobiles, lighting systems, and medical devices. In the future, it is not unreasonable to assume that cybercriminals could take control of a private citizen's refrigerator or lighting system and demand a $1,000 ransom in bitcoin in order to restore functionality. It is also not difficult to fathom the threat of a vehicle that won't brake, or a pacemaker that stops working due to a hack. Hackers might also weaponize devices and take down financial systems and power grids.

The thought is chilling, and the repercussions potentially far-reaching. "All these devices, which now have computing functionality, affect the world in a direct physical manner—and that just changes everything," observes Bruce Schneier, an independent computer security analyst and author of Click Here to Kill Everybody: Security and Survival in a Hyper-connected World (W. W. Norton & Company, 2018). "Today, computers can actually kill you."

Adds Stuart Madnick, John Norris Maguire Professor of Information Technologies at the Massachusetts Institute of Technology (MIT) Sloan School of Management, "We are entering a dangerous period. We have to wake up to the risks." .....

Thursday, May 16, 2019

Transparency to understand, Control Risk.

To hope to get a handle on risk, you need to understand both the process involved, and known or predicted measures of risk.   To lead some useful management approach.  That's also a  key element of transparency.

Customers Deserve Transparency to Manage Risk   By Anthony Grieco  in Cisco Blog   Contributors: Russ Smoak

Our commitment to customers is to be open and transparent, especially as it relates to issues that could negatively impact their business. At Cisco, our leadership made the decision over twenty years ago that we would clearly communicate with customers about technical or other issues that could potentially expose their organizations to risk. It is one of the many ways we act as a trusted partner to our customers. Over those last twenty years, our team and security vulnerability process has evolved to meet customers’ needs. Ultimately, we want our customers to have the information they need to protect their networks.

We get called out from time to time about vulnerability disclosures we make. Yet… our policy remains unchanged: when security issues arise, we handle them openly and as a matter of top priority, so our customers understand the issue and how to address it. To fulfill this promise we follow a strict process to manage the receipt, investigation, and public reporting of security vulnerability information that is related to Cisco solutions and networks.

With that in mind, we’d like to address some of the most common questions and misconceptions we hear from our customers and the media about our vulnerability disclosure process.

What is a vulnerability and how are they identified?  .... "

Saturday, April 27, 2019

The Risks of Artificial Intelligence

Having now been involved in many applications using AI oriented methods,  it was rare that there were not risks in their application.  We saw them all.  From legal exposure to regulatory penalties to the loss of public trust to shifts in context that made the results wrong.    Because cognitive AI is always to some degree utilizing something that is like human decision making, or mimics cognitive facilities, we always included risk analyses.   Depending on the nature of the problem, these could be extensive in place testing,  direct comparisons to other methods,  exposure to teams of users or consumers, or formal risk models.

As the article suggests, the risks need to be confronted.   This is rarely done for many kinds of analytics.    Because the intent is often to use these methods predictively, the assumption is that they will enable, enhance or even replace human decision making, so you have to understand the implications of that.  If your system is working with human resources, you need to further consider risk of how those teams will work.    The human, machine and combined elements of such an intelligence will behave in different, sometimes unexpected ways.

McKinsey provides a good article:

Confronting the risks of artificial intelligence  in McKinsey Quarterly
 By Benjamin Cheatham, Kia Javanmardian, and Hamid Samandari

With great power comes great responsibility. Organizations can mitigate the risks of applying artificial intelligence and advanced analytics by embracing three principles.

Artificial intelligence (AI) is proving to be a double-edged sword. While this can be said of most new technologies, both sides of the AI blade are far sharper, and neither is well understood.

Consider first the positive. These technologies are starting to improve our lives in myriad ways, from simplifying our shopping to enhancing our healthcare experiences. Their value to businesses also has become undeniable: nearly 80 percent of executives at companies that are deploying AI recently told us that they’re already seeing moderate value from it. Although the widespread use of AI in business is still in its infancy and questions remain open about the pace of progress, as well as the possibility of achieving the holy grail of “general intelligence,” the potential is enormous. McKinsey Global Institute research suggests that by 2030, AI could deliver additional global economic output of $13 trillion per year.

Yet even as AI generates consumer benefits and business value, it is also giving rise to a host of unwanted, and sometimes serious, consequences. And while we’re focusing on AI in this article, these knock-on effects (and the ways to prevent or mitigate them) apply equally to all advanced analytics. The most visible ones, which include privacy violations, discrimination, accidents, and manipulation of political systems, are more than enough to prompt caution. More concerning still are the consequences not yet known or experienced. Disastrous repercussions—including the loss of human life, if an AI medical algorithm goes wrong, or the compromise of national security, if an adversary feeds disinformation to a military AI system—are possible, and so are significant challenges for organizations, from reputational damage and revenue losses to regulatory backlash, criminal investigation, and diminished public trust.   .... "

Wednesday, October 31, 2018

See a Demonstration of Threat Intelligence

See much more on Threat Intelligence.

Attend a Live Demo of Recorded Future
Dark Web Threat Intelligence With QRadar
Join us for a 30-minute live demo of Recorded Future every week. The next one is Thursday, November 1 at 2:00 PM ET, focusing on dark web threat intelligence with QRadar.

Register now (link above) to hear an experienced analyst cover how to:
Increase analyst “speed to no” by enriching the indicators present in QRadar log activity.
Analyze dark web sources for riskiness and add value to your analyst workflows.
Use Recorded Future Risk Lists and associated context to detect important incidents and prioritize actions.

Pivot to the source of Recorded Future threat intelligence on demand, even if it is a dark web or special access source.   .... "

Thursday, October 04, 2018

The Threat Intelligence Handbook

Just reading.   Well done.  See recordedfuture.com      Get the free book here.

The Threat Intelligence Handbook   (108 pages)

A Practical Guide for Security Teams to
Unlocking the Power of Intelligence

Edited by Chris Pace
Foreword by Dr. Christopher Ahlberg

It’s easy to find descriptions of what threat intelligence is. But it’s harder to learn how to use it to truly make your organization safe from cybercriminals. How can threat intelligence strengthen all the teams in a cybersecurity organization?

This book answers this question. It reviews the kinds of threat intelligence that are useful to security teams and how each team can use that intelligence to solve problems and address challenges. It discusses how security analysts in the real world use threat intelligence to decide what alerts to investigate (or ignore), what incidents to escalate, and what vulnerabilities to patch. It examines how information collected outside of the enterprise can help model risks more accurately and prevent fraud.

We invite you to learn about how threat intelligence can help everyone in cybersecurity anticipate problems, respond faster to attacks, and make better decisions on how to reduce risk. ... "

Tuesday, September 18, 2018

Cisco Talks Network Assurance with AI

Specific term was new to me.  But I do like the link to the business, the process, the goals.  Are the intents the same as in a simulation model of the business process?   Risks?  Reading more. 

Machine Learning for Analytics and Assurance
By Duval Yeager in Cisco BlogNetwork operation based in the intent of the business.  Goals?  Intriguing.

We are hearing amazing stories from our Cisco customers as they roll out intelligent analytics and assurance solutions in the form of Cisco DNA Center, Meraki insight, and Network Assurance Engine (NAE). The comments are on the accuracy and complexity of the analytical models that we have built, based on 30 years of Cisco networking leadership. You can read my blog post on how analytics works here. But, the back story to this is the approach of Machine Learning. When we add advanced machine learning algorithms to these products, the intelligence and system flexibility will be even more exciting. Let me explain…

Assurance in IP networking uses an analytics engine to verify that the network is operating based on the intents of the business. These intents are translated based on the network policies that IT configured when the system was set-up. The resulting model drives the decisions that an assurance solution makes to improve the network. This model is very good at network optimization, but every network is different, and network utilization is always changing as we change the way we use it  .... "