• bitcoinBitcoin(BTC)$76,342.000.10%
  • ethereumEthereum(ETH)$2,442.320.98%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$738.341.81%
  • rippleXRP(XRP)$1.29-0.34%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$101.432.68%
  • tronTRON(TRX)$0.334731-0.24%
  • zcashZcash(ZEC)$1,463.329.25%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.05%
  • HyperliquidHyperliquid(HYPE)$85.409.06%
  • dogecoinDogecoin(DOGE)$0.0816111.10%
  • moneroMonero(XMR)$518.423.74%
  • USDSUSDS(USDS)$1.000.02%
  • whitebitWhiteBIT Coin(WBT)$78.660.54%
  • RainRain(RAIN)$0.012729-1.27%
  • chainlinkChainlink(LINK)$11.382.91%
  • leo-tokenLEO Token(LEO)$8.90-0.86%
  • cardanoCardano(ADA)$0.2027453.29%
  • stellarStellar(XLM)$0.183301-0.98%
  • uniswapUniswap(UNI)$7.8417.51%
  • Ethena USDeEthena USDe(USDE)$1.00-0.01%
  • bitcoin-cashBitcoin Cash(BCH)$235.176.40%
  • daiDai(DAI)$1.000.00%
  • USD1USD1(USD1)$1.000.00%
  • litecoinLitecoin(LTC)$53.984.56%
  • nearNEAR Protocol(NEAR)$3.1619.41%
  • CantonCanton(CC)$0.1021170.00%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.341.40%
  • avalanche-2Avalanche(AVAX)$7.600.88%
  • Global DollarGlobal Dollar(USDG)$1.00-0.01%
  • hedera-hashgraphHedera(HBAR)$0.0744841.18%
  • shiba-inuShiba Inu(SHIB)$0.0000053.70%
  • suiSui(SUI)$0.743.66%
  • crypto-com-chainCronos(CRO)$0.0580072.91%
  • paypal-usdPayPal USD(PYUSD)$1.00-0.03%
  • MemeCoreMemeCore(M)$1.206.61%
  • tether-goldTether Gold(XAUT)$4,348.871.55%
  • BittensorBittensor(TAO)$232.934.03%
  • Circle USYCCircle USYC(USYC)$1.140.01%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • Ripple USDRipple USD(RLUSD)$1.00-0.01%
  • okbOKB(OKB)$111.920.73%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.140.07%
  • AsterAster(ASTER)$0.745.46%
  • aaveAave(AAVE)$128.467.42%
  • BitwayBitway(BTW)$0.72-3.13%
  • Pump.funPump.fun(PUMP)$0.00406411.65%
  • pax-goldPAX Gold(PAXG)$4,346.241.47%
  • mantleMantle(MNT)$0.573.16%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

Clearing the “Fog of More” in Cyber Security

May 31, 2024
in AI & Technology
Reading Time: 5 mins read
A A
Clearing the “Fog of More” in Cyber Security
ShareShareShareShareShare

At the RSA Conference in San Francisco this month, a dizzying array of dripping hot and new solutions were on display from the cybersecurity industry. Booth after booth claimed to be the tool that will save your organization from bad actors stealing your goodies or blackmailing you for millions of dollars.

After much consideration, I have come to the conclusion that our industry is lost. Lost in the soup of detect and respond with endless drivel claiming your problems will go away as long as you just add one more layer. Engulfed in a haze of technology investments, personnel, tools, and infrastructure layers, companies have now formed a labyrinth where they can no longer see the forest for the trees when it comes to identifying and preventing threat actors. These tools, meant to protect digital assets, are instead driving frustration for both security and development teams through increased workloads and incompatible tools. The “fog of more” is not working. But quite frankly, it never has.

YOU MAY ALSO LIKE

FAA Says Laser Strikes On Aircraft Fell For The Third Consecutive Year

Microsoft Open-Sources TauGrid: A Kubernetes-Native Stack for GPU AI Workloads

Cyberattacks begin and end in code. It’s that simple. Either you have a security flaw or vulnerability in code, or the code was written without security in mind. Either way, every attack or headline you read, comes from code. And it’s the software developers that face the ultimate full brunt of the problem. But developers aren’t trained in security and, quite frankly, might never be. So they implement good old fashion code searching tools that simply grep the code for patterns. And be afraid for what you ask because as a result they get the alert tsunami, chasing down red herrings and phantoms for most of their day. In fact, developers are spending up to a third of their time chasing false positives and vulnerabilities. Only by focusing on prevention can enterprises really start fortifying their security programs and laying the foundation for a security-driven culture.

Finding and Fixing at the Code Level

It’s often said that prevention is better than cure, and this adage holds particularly true in cybersecurity. That’s why even amid tighter economic constraints, businesses are continually investing and plugging in more security tools, creating multiple barriers to entry to reduce the likelihood of successful cyberattacks. But despite adding more and more layers of security, the same types of attacks keep happening. It’s time for organizations to adopt a fresh perspective – one where we home in on the problem at the root level – by finding and fixing vulnerabilities in the code.

Applications often serve as the primary entry point for cybercriminals seeking to exploit weaknesses and gain unauthorized access to sensitive data. In late 2020, the SolarWinds compromise came to light and investigators found a compromised build process that allowed attackers to inject malicious code into the Orion network monitoring software. This attack underscored the need for securing every step of the software build process. By implementing robust application security, or AppSec, measures, organizations can mitigate the risk of these security breaches. To do this, enterprises need to look at a ‘shift left’ mentality, bringing preventive and predictive methods to the development stage.

While this is not an entirely new idea, it does come with drawbacks. One significant downside is increased development time and costs. Implementing comprehensive AppSec measures can require significant resources and expertise, leading to longer development cycles and higher expenses. Additionally, not all vulnerabilities pose a high risk to the organization. The potential for false positives from detection tools also leads to frustration among developers. This creates a gap between business, engineering and security teams, whose goals may not align. But generative AI may be the solution that closes that gap for good.

Entering the AI-Era

By leveraging the ubiquitous nature of generative AI within AppSec we will finally learn from the past to predict and prevent future attacks. For example, you can train a Large Language Model or LLM on all known code vulnerabilities, in all their variants, to learn the essential features of them all. These vulnerabilities could include common issues like buffer overflows, injection attacks, or improper input validation. The model will also learn the nuanced differences by language, framework, and library, as well as what code fixes are successful. The model can then use this knowledge to scan an organization’s code and find potential vulnerabilities that haven’t even been identified yet. By using the context around the code, scanning tools can better detect real threats. This means short scan times and less time chasing down and fixing false positives and increased productivity for development teams.

Generative AI tools can also offer suggested code fixes, automating the process of generating patches, significantly reducing the time and effort required to fix vulnerabilities in codebases. By training models on vast repositories of secure codebases and best practices, developers can leverage AI-generated code snippets that adhere to security standards and avoid common vulnerabilities. This proactive approach not only reduces the likelihood of introducing security flaws but also accelerates the development process by providing developers with pre-tested and validated code components.

These tools can also adapt to different programming languages and coding styles, making them versatile tools for code security across various environments. They can improve over time as they continue to train on new data and feedback, leading to more effective and reliable patch generation.

The Human Element

It’s essential to note that while code fixes can be automated, human oversight and validation are still crucial to ensure the quality and correctness of generated patches. While advanced tools and algorithms play a significant role in identifying and mitigating security vulnerabilities, human expertise, creativity, and intuition remain indispensable in effectively securing applications.

Developers are ultimately responsible for writing secure code. Their understanding of security best practices, coding standards, and potential vulnerabilities is paramount in ensuring that applications are built with security in mind from the outset. By integrating security training and awareness programs into the development process, organizations can empower developers to proactively identify and address security issues, reducing the likelihood of introducing vulnerabilities into the codebase.

Additionally, effective communication and collaboration between different stakeholders within an organization are essential for AppSec success. While AI solutions can help to “close the gap” between development and security operations, it takes a culture of collaboration and shared responsibility to build more resilient and secure applications.

In a world where the threat landscape is constantly evolving, it’s easy to become overwhelmed by the sheer volume of tools and technologies available in the cybersecurity space. However, by focusing on prevention and finding vulnerabilities in code, organizations can trim the ‘fat’ of their existing security stack, saving an exponential amount of time and money in the process. At root-level, such solutions will be able to not only find known vulnerabilities and fix zero-day vulnerabilities but also pre-zero-day vulnerabilities before they occur. We may finally keep pace, if not get ahead, of evolving threat actors.

Credit: Source link

ShareTweetSendSharePin

Related Posts

FAA Says Laser Strikes On Aircraft Fell For The Third Consecutive Year
AI & Technology

FAA Says Laser Strikes On Aircraft Fell For The Third Consecutive Year

September 17, 2026
Microsoft Open-Sources TauGrid: A Kubernetes-Native Stack for GPU AI Workloads
AI & Technology

Microsoft Open-Sources TauGrid: A Kubernetes-Native Stack for GPU AI Workloads

September 17, 2026
GSA Extends Anthropic’s Claude OneGov Offer for Federal Agencies – Unite.AI
AI & Technology

GSA Extends Anthropic’s Claude OneGov Offer for Federal Agencies – Unite.AI

September 17, 2026
Candy Crush Developers Are Planning A Strike For Next Week
AI & Technology

Candy Crush Developers Are Planning A Strike For Next Week

September 17, 2026
Next Post
Senua’s Saga: Hellblade II — A mighty warrior whose tale is too short | The DeanBeat

Senua’s Saga: Hellblade II — A mighty warrior whose tale is too short | The DeanBeat

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Imperial Petroleum Stock: Buy On Strong Prospects, Substantial Share Repurchases (IMPP)

Imperial Petroleum Stock: Buy On Strong Prospects, Substantial Share Repurchases (IMPP)

September 11, 2026
Are You Ready for the Next Stock Market Crash?

Are You Ready for the Next Stock Market Crash?

September 17, 2026
Anne Thompson recalls reporting near ground zero on 9/11

Anne Thompson recalls reporting near ground zero on 9/11

September 13, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!