Equipping Threat Hunters - Advanced Analytics and Artificial Intelligence Part 1
As cyber threats become more complex through AI-powered malicious software, zero-day vulnerabilities, and state-sponsored attacks, organizations face increasing difficulty in protecting their digital assets.

Threat Hunting: The Rise of the Integrated Approach
As cyber threats become increasingly complex through AI/ML-powered malicious software, zero-day vulnerabilities, and state-sponsored attacks, organizations face growing challenges in protecting their digital assets. The lack of cybersecurity expertise and the vast amount of data to analyze have led organizations to seek a balanced approach for threat detection. This approach combines the precision of rule-based detection, the adaptability of AI/ML models, and human critical thinking. This article aims to explain the role of each of these elements in threat detection and how their combination forms a robust defense against today's advanced cyber threats.
This is the eleventh article in our ongoing "The Rise of the Threat Hunter" blog series. To learn more about the series and find previous posts, please visit our series introduction or read last week's article on "The Future of Threat Hunting".
Rule-Based Threat Detection
Rule-based threat detection has long been an important tool in cybersecurity and one of the first methodologies used to identify and mitigate threats. Traditionally, this approach involves creating specific rules and signatures for known malicious software and threats, scanning new data against these predefined patterns. In recent years, rule-based detection has significantly evolved with systems such as OpenText's ArcSight ESM, providing advanced real-time event correlation engines that enable accurate threat identification and quick rule-based responses.
The strength of rule-based detection lies in its high interpretability and ready usability. The transparency provided by rules establishes clear connections between alerts and triggering events, simplifying investigations. These systems are particularly effective in detecting known threats and can be easily deployed with minimal configuration.
However, rule-based approaches have limitations, especially in adapting to new and unknown threats. Threshold-inclusive compliance rules can increase false positives when detecting data distribution anomalies due to organizational changes. Maintaining and updating these systems can be time-consuming and often requires manual intervention.
AI/ML-Based Threat Detection
Behavioral Threat Monitoring with AI/ML
Machine Learning (ML) and Artificial Intelligence (AI) are revolutionizing threat detection by employing advanced techniques to identify both known threats (e.g., brute force, identity theft) and unknown threats (e.g., exploiting zero-day vulnerabilities). These technologies are trained on unique datasets, making them adaptable to specific organizations. ML/AI-based systems use supervised models or unsupervised models with labeled datasets to learn normal behaviors and flag deviations as potential anomalies. Platforms like OpenText's ArcSight Intelligence utilize various models to analyze different behavioral patterns within an organization, enabling proactive threat detection.
Several factors should be considered when training AI models for threat detection:
- Transparency and Traceability: Predictions obtained from models should be supported by evidence or explanations to help threat hunters understand and trust the decisions, enabling them to take effective measures.
- Adaptability: As user and system behaviors evolve, models must adapt to new patterns without losing accuracy.
- Scalability: AI models should efficiently handle large and growing cybersecurity datasets.
- Relevance: Statistical anomalies may not always be security relevant. Understanding and differentiating these anomalies helps reduce false positives and ensures the model's outputs remain actionable.
A strong advantage of AI/ML in threat detection is its ability to identify unknown threats by detecting deviations from normal behavior patterns. This makes them more effective against complex attacks that traditional methods may miss. Additionally, these models can adapt to changing data without requiring constant human intervention, making their maintenance easier.
However, challenges such as interpreting complex model outputs arise if transparency is not upheld. Furthermore, limited access to comprehensive threat data complicates the validation of unsupervised models. These models also require sufficient baseline data to make accurate predictions, which can be a time-consuming process. Despite these challenges, AI/ML-based threat detection has proven to be a significant advancement in cybersecurity, offering cutting-edge solutions against emerging threats.
Threat Hunting with Generative AI
Large Language Models (LLMs) represent the latest developments in Generative AI. These are tools designed to produce human-like text and are widely used for tasks such as summarization and chatbot development. LLMs offer significant potential in cybersecurity, particularly as natural language interfaces between threat hunters and analytical systems.
Generating Threat Reports with LLMs
Rules and AI/ML models can accelerate threat hunting, but the sheer volume of alerts can overwhelm threat hunters. LLMs help alleviate this burden by generating reports that summarize the threat landscape and highlight important anomalies. These summaries assist security teams in quickly understanding critical issues, improving efficiency and focus.
LLM-Based Threat Hunting Assistants
LLMs can go beyond summary generation by enabling natural language interaction with data, facilitating pattern discovery, answering queries, and uncovering insights. This intuitive interaction with security data helps teams more effectively detect and respond to threats.
LLMs for Code Generation
The code generation capabilities of LLMs can be used for tasks such as automatic rule creation. This makes the process of defining rules from natural language descriptions more intuitive for threat hunters.
Human Insight in Threat Detection
Despite the existence of advanced threat detection tools, the role of threat hunters remains indispensable due to the critical human insight they provide. Automated tools can enhance the efficiency of threat hunters. However, human reasoning, critical thinking, and decision-making under pressure are irreplaceable in detecting complex attacks that automated systems may overlook. Furthermore, threat hunters play a crucial role in keeping automated systems relevant and effective by collaborating with data scientists to define rules or improve AI/ML models. Their deep understanding of evolving threats ensures detection systems remain accurate and sensitive in the face of new challenges.
Integrated Approach: A Robust Defense System
Integrating rules, AI/ML models, and Large Language Models (LLMs) can create a more comprehensive and effective threat detection system for threat hunters. Rules are particularly effective in identifying known threats and malicious software signatures, while AI/ML models excel at detecting unknown threats by capturing deviations in various behavioral dimensions. Layering rules over model outputs can result in a detection system that is less noisy and more accurate than direct rule application on raw data. Additionally, machine learning models can enhance their prediction power by incorporating rule violations as features. Finally, LLMs can serve as a user-friendly interface, presenting consolidated insights from both rules and models to threat hunters in an effective manner, facilitating more accurate and actionable threat analysis. Human threat hunters remain indispensable with their unique insights and decision-making capabilities, complementing automated tools to detect complex attacks. They help ensure that detection systems remain up-to-date and effective against evolving threats.
Learn More About OpenText Cybersecurity
Ready to empower your threat hunting team with products, services, and training to protect your most valuable and sensitive information? To proactively identify, prioritize, and investigate anomalies and malicious behaviors, explore our modern comprehensive security solution portfolio that offers 360-degree visibility across endpoints and network traffic for threat hunters and security analysts. View our cybersecurity portfolio.
Source: Equipping Threat Hunters: Advanced Analytics and AI, Part 1 - OpenText Blogs