3 ms·
This talks about continuous authentication, which isn’t about accessing a system, but rather flagging unusual behavior for followup inspection.
by dak1 8y ago
This talks about continuous authentication, which isn’t about accessing a system, but rather flagging unusual behavior for followup inspection.
- wahern 8y agoThere's nothing new about this, except for attaching "AI" to it. There's something to be said for the value in detecting drive-by or opportunistic attacks, or cleaning up after the fact. Though it was a thinly veiled advertisement for his company, Counterpane, Bruce Schneier made the case for this approach in a 2001 paper: https://www.schneier.com/academic/paperfiles/paper-msm.pdf https://www.schneier.com/academic/paperfiles/paper-msm.pdf But these pattern detection systems are fundamentally incapable of preventing targeted attacks. For a targeted attack any pattern recognizer (heuristic, bayesian, neural net, army of elite white hats, w'ever) simply provides a blueprint for reliably subverting the system. They could never replace a hard, cryptographically strong authentication factor providing distinct, provable security characteristics; certainly not in environments like DoD facilities which require such strong authentication.