Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • Laboratory thwarts insider threat with Darktrace AI

Security

Laboratory thwarts insider threat with Darktrace AI

A leading laboratory specialising in vitro diagnostics has successfully stopped an insider threat with the help of Darktrace's self-learning AI.

Image courtesy Darktrace

The company, which has laboratories, offices and distribution centres in over 100 countries worldwide and more than 3,000 employees, specialises in the research, development and manufacturing of innovative in vitro diagnostic tests for disease, conditions and infections. The organisation uses Darktrace's detect, respond and investigate capabilities to defend against in-progress attacks at the early-stages.

Advertisement
ODU RT 2

Powered by Self-Learning AI, Darktrace technology develops an understanding of normal operations for the company. From this understanding it can then autonomously interrupt in-progress attacks at every stage from the initial entry with sophisticated spearphishing emails to brute-forced remote desktop protocol (RDP), command-and-control, and lateral movement, all without business disruption.

In one instance, Darktrace's Self-Learning AI detected an internal device communicating with the Tor network via an intermediary web service. Tor is an open-source privacy network that enables anonymous web browsing by guiding data traffic through different servers, located all over the world. Whilst it is not wholly malicious, it can be associated with the browsing of non-business or even illegal content.

The device was connecting with a darknet forum relating to the pharmaceutical market. Given that no other device within the organisation had visited the Tor network in the past, Darktrace AI flagged this to the security team as out-of-the-ordinary. With the AI taking care of early detection and making micro-level decisions the security team were uplifted and able to make important decisions that required business context.

The internal security team later found that this was likely an insider looking to sell proprietary intellectual property or even medical supplies on the darknet.

"Malicious or compromised insiders can be difficult to identify because their privileged access and knowledge of company workings allows them to evade detection by traditional security tools," commented Toby Lewis, Global Head of Threat Analysis, Darktrace. "In order to protect intellectual property from insider threat, organizations need to augment security teams with AI-powered technology to stop malicious activity in real time at the moment of detection."

Advertisement
ODU RT 2

 

 

Advertisement
L3Harris L3Harris
Roke opens Gloucester office

Aerospace Defence Security

Roke opens Gloucester office

19 April 2024

Romsey headquartered technology company Roke, has today officially opened its new bespoke office space in Gloucester, as it focuses on further expansion, innovation and technological growth in the area and for the UK.

CCL Solutions appoints Seamus O’Reilly as Technical Director, Cyber Services

Security

CCL Solutions appoints Seamus O’Reilly as Technical Director, Cyber Services

18 April 2024

Digital forensics and cyber security specialist CCL Solutions Group has announced the appointment of Seamus O’Reilly as its new Technical Director, Cyber Services.

Met leads infiltration of fraud platform used by criminals worldwide

Security

Met leads infiltration of fraud platform used by criminals worldwide

18 April 2024

A website used by more than 2,000 criminals to defraud victims worldwide has been infiltrated in the Met’s latest joint operation to tackle large-scale online fraud.

Bridewell research reveals UK CNI ransomware risks

Aerospace Security

Bridewell research reveals UK CNI ransomware risks

17 April 2024

Three-in-ten UK-based critical national infrastructure (CNI) organisations (30%) that have fallen victim to a ransomware attack have risked legal repercussions by paying a ransom.

Advertisement
Marshall RT 2
Goldilock and CR14 to support CNI testing under NATO DIANA

Defence Security

Goldilock and CR14 to support CNI testing under NATO DIANA

17 April 2024

British cybersecurity startup Goldilock, has partnered with CR14, a cyber defence organisation established by the Estonian ministry of defence and the host of NATO’s operative Cyber Defence Centre of Excellence (CCDCOE), to conduct testing activities with the aim of increasing the resilience of critical national infrastructure (CNI).

ODU Connectors introduces MINI-SNAP Super Shorty

Aerospace Defence Security Space

ODU Connectors introduces MINI-SNAP Super Shorty

16 April 2024

ODU Connectors has introduced its MINI-SNAP Super Shorty, designed to provide a compact solution for large electrical engineering challenges.

Advertisement
ODU RT 2