THE CRITICAL ROLE OF OPEN SOURCE AND ARTIFICIAL INTELLIGENCE IN CYBERSECURITY


Parmaksız H.

1. Uluslararası WriteTec Yapay Zeka Çağında Sosyal Bilimler ve Sağlık Bilimleri Kongresi: (Ana Tema: Sosyal Bilimler ve Sağlık Bilimlerinde Yapay Zeka Uygulamaları), Antalya, Turkey, 25 - 27 October 2024, pp.100-101, (Summary Text)

  • Publication Type: Conference Paper / Summary Text
  • City: Antalya
  • Country: Turkey
  • Page Numbers: pp.100-101
  • Bilecik Şeyh Edebali University Affiliated: Yes

Abstract

AI has come a long way since its inception in the 1950s, developing uses in a multitude of fields: natural language processing, computer vision, autonomous systems, electric vehicles, and IoT. The integration of AI with cybersecurity increases the effectiveness of security operations. Security Operations Centers (SOCs) play a critical role in protecting businesses, and AI enhances the functionality of Security Information and Event Management (SIEM) systems by increasing their data processing capacity. In addition, the capacity of intrusion detection and prevention systems (IDS/IPS) is being increased to identify AI-enabled anomaly detection and zero-day attacks. The widespread use of open-source technologies in cybersecurity allows for increased cost-effective solutions and flexibility and customization in security solutions. SIEM systems centralize log management to detect attacks and enable early warning mechanisms. Endpoint detection and response (EDR) solutions analyze suspicious device behavior to detect malware and attacks. Threat intelligence systems provide up-to-date threat information that supports proactive protection measures. Vulnerability management technologies automate patch management processes, while network traffic analysis tools detect unusual network behaviors. AI-powered tools continuously gather information about new threats, increasing the speed and accuracy of vulnerability scans and facilitating penetration testing and vulnerability analysis. Security Orchestration, Automation, and Response (SOAR) technologies automate security operations, speeding incident response times and reducing human errors. Industry standards guide security teams in threat modeling and risk assessment, contributing to the development of open-source security technologies. Combining open-source SOC tools with AI technology enables businesses to better protect against cyber threats while maintaining cost-effectiveness, flexibility, and continuous innovation.