📥 Content Hub
← назад
AI / Искусственный интеллект AFCEA International en 2026-10-01 04:33 8 min

Securing the Digital World: AI-Driven Defense of the Cyber Domain - AFCEA International

Кратко: Securing the Digital World: AI-Driven Defense of the Cyber Domain The future of cybersecurity rests on five foundational axioms: “Data is the new oil,” humans cannot operate at machine speed, cyber is inherently a “purple” discipline, zero-trust architecture is non-negotiable, and cybersecurity is a group effort. These principles guide our understanding of the evolving threat landscape and highlight opportunities to identify anomalous and/or malicious activity, find gaps in our security before malicious actors do and leverage AI to develop low-cost, secure operating systems for our partner nations.
🧭 Извлечение: ok · confidence 90% · диагностика
High confidence: full text extraction produced 9980 characters.

Securing the Digital World: AI-Driven Defense of the Cyber Domain

The future of cybersecurity rests on five foundational axioms: “Data is the new oil,” humans cannot operate at machine speed, cyber is inherently a “purple” discipline, zero-trust architecture is non-negotiable, and cybersecurity is a group effort. These principles guide our understanding of the evolving threat landscape and highlight opportunities to identify anomalous and/or malicious activity, find gaps in our security before malicious actors do and leverage AI to develop low-cost, secure operating systems for our partner nations.

The Five Axioms of Cybersecurity 

1. ‘Data is the new oil.’ It just needs to be refined.

“Data is the new oil,” coined by Clive Humby in 2006 at an Association of National Advertisers conference and later expanded by Dr. Steven Carter to “Data is the new oil, it just has to be refined,” still holds true, perhaps more so, 20 years later. The economics of technology have been transformed; the cost of storage, memory and compute power has steadily decreased while their capacity has grown exponentially.

This has made it feasible to collect vast amounts of data from every possible source and process it with increasing speed. In cybersecurity, tools like security information and event management and endpoint/extended detection and response are now standard for monitoring network events. We must collect logs and metrics from every device, application and network segment. Each data point, no matter how insignificant it may seem, contributes to a more complete operational picture.

However, raw data is not intelligence. This is where artificial intelligence (AI) becomes the refinery. AI can analyze petabytes of data in real time, identifying subtle patterns and anomalies that would be impossible for a human analyst to spot.

It can correlate events across disparate systems to distinguish between malicious attacks, unauthorized user activity and simple network inefficiencies. By providing AI with read-only application programming interface access to various services, it can act as an orchestrator, pulling in data from multiple streams to create a unified, high-fidelity view of the battlespace.

2. Humans can’t read, act and react at machine speed. 

Today’s digital domain is too vast and complex for human-driven defense. The sheer volume of data and the speed at which events unfold have surpassed human cognitive limits. We require AI-integrated tools, not just to automate tasks, but to replicate at machine speed, exceeding the ability of an experienced analyst or team.  

An AI can monitor the network’s configuration, detect an anomaly and implement a defensive countermeasure in milliseconds. While traditional algorithms are efficient for known threats, AI introduces the ability to cross-reference massive, unstructured datasets, providing a level of context that is crucial for identifying novel and sophisticated attacks. AI doesn’t just follow rules; it learns and adapts, making it a powerful force multiplier for security teams.

3. Purple is the color of cyber. 

For too long, cybersecurity has been separated into “red teams” (offense) and “blue teams” (defense). This creates an adversarial relationship where the ultimate goal—securing the enterprise—can be lost in the lack of communication and coordination between the two.

Malicious actors are already using AI to find and exploit vulnerabilities at an unprecedented speed. Automated penetration testing tools, powered by AI, should be continuously probing our own networks or a digital twin to identify weaknesses before an adversary does. AI should also be running over current network configurations to identify gaps in security because human teams are prone to burnout, forgetfulness, oversaturated work requirements and errors, which inevitably lead to security gaps.

Furthermore, traditional change management, with its deliberative boards, is too slow for the modern threat environment. A more agile approach involves using AI to validate changes in a digital twin of the live network. This allows for continuous patching and updating in a secure, virtualized environment that mirrors the production network, ensuring that security is maintained without disrupting operations. By using the AI-reviewed digital twin, management teams can maintain a human in the loop as the decision-makers for change implementations while reducing the administrative tasks and time necessary to come to a decision, as response times become increasingly more crucial.

4. Zero-trust architecture (ZTA) must be adhered to.  

The foundational principle of zero trust is “never trust, always verify.” In a ZTA environment, no user or device is trusted by default, regardless of its location. This architecture can be significantly enhanced by generative intelligence.

AI can monitor network traffic and user behavior, comparing it against established baselines and approved configurations. When it detects an irregularity, or a user accessing a file they’ve never touched before, a device communicating with an unknown server can automatically flag it for review or even block the action in real time. This moves ZTA from a static set of rules to a dynamic, adaptive security model.

5. Cybersecurity is a global team sport.  

The security of our own networks is intrinsically linked to the security of our allies and defense industry partners. This is not merely a theoretical concept but a stark reality of our interconnected world. A significant challenge, particularly for smaller nations, is the reliance on low-cost hardware from countries known to embed backdoors and other vulnerabilities in their products. As the role of the traditional software engineer evolves, AI-driven coding and recoding can empower allies to repurpose hardware from potentially untrustworthy sources, turning a vulnerability into a strength. 

The most prominent example of this challenge is the widespread adoption of technology from Huawei. The company’s equipment forms the backbone of digital infrastructure in more than 170 countries, including an estimated 70% of Africa’s 4G networks and a significant portion of networks in Latin America and even parts of Europe. This hardware was adopted for a simple reason: it was affordable and effective, allowing many developing nations to build out their first modern communication networks.

However, this widespread adoption comes with severe risks. Security analyses have raised major alarms; one 2019 study found that 55% of Huawei firmware images had at least one potential backdoor and that, on average, each device had more than 100 known vulnerabilities. The concern is not just technical. Huawei’s close ties to the Chinese government and the legal requirements of China’s 2017 National Intelligence Law, which compels Chinese companies to cooperate with state intelligence, create a credible threat of state-sponsored espionage and data interception.

The current proposed solution to this problem is a complete “rip and replace” of the suspect hardware, but for many nations, this is simply not a viable option. The financial cost of removing and replacing nationwide infrastructure for less developed countries can be astronomically large compared to their gross domestic product; for example, the U.S. “Rip and Replace” program for American telecommunications carriers amounted to nearly $5.6 billion and would cause massive disruptions and downtime, setting their digital development back by years.

This is where generative AI presents a transformative opportunity. Instead of a costly and disruptive physical replacement, AI-powered tools can perform a digital rip-and-replace. These tools can analyze the source code of the operating systems and software running on the installed hardware, identifying the malicious code, vulnerabilities and hidden backdoors that security experts have warned about.

If analyzing the code is not possible, AI can help write entirely new code for the operating system that can then be open-sourced and shared for low to no cost because the benefit would be increased cybersecurity and a reduction in espionage or intellectual theft for our partners and us. This would allow partner nations and developing countries to leverage the low-cost technology they already possess without inheriting the associated risks, dramatically lowering the cost of building and maintaining a secure digital infrastructure. Specifically, this would eliminate the need for nations to absorb the immense cost and downtime of physically rebuilding their networks.

However, the question may be raised: What about the hardware and BIOS? Here, the use of AI for writing code can go a step further. AI could be leveraged to visually inspect the hardware to identify anomalous components integrated into the motherboard to warn the owners of the equipment; plus, that same AI could be used to identify the make and model of components to build a secure BIOS for the hardware, so from start to finish the owners and operators will be assured that their low-cost network hardware is secure.

By providing our partners with these AI-powered tools and rebuilt operating systems, we foster a more resilient global security environment. We empower them to secure their own systems, which, in turn, reduces the number of vulnerable networks that could be used as testing or staging grounds for attacks against the United States or our allies. In a truly interconnected world, helping our allies secure their digital domain is a critical component of defending our own, creating a more equitable and secure digital future for all.

Maj. Michael Godwin, USA, became a 25A Signal officer as a captain in 2018 and transitioned to a 26A network security engineer in 2020. For the past five years, he has been serving in cyber units working with joint services and external partners across U.S. Africa Command to help secure the Department of War Information Network.

Читать оригинал ↗

Сделать контент из этого материала