Sevii targets AI-Speed ​​attacks with preemptive autonomous defense

Fighting fire with fire is a known reaction. Combating AI attacks with AI defenses is a growing practice. But instant removal is new and welcome.

Sevii has expanded its Autonomous Protection and Recovery (ADR) platform with a new AI security module. As the speed and scope of AI-driven attacks increase, so does AI protection. Because companies are rarely aware of all the shadow AI in use within an organization, this protection must work at runtime, regardless of the source, with effective immediate and autonomous remediation.

That’s what new module provides. As with Sevii’s broader ADR platform, alerts are received from the entire customer protection detection stack. The new module receives these signals in real time and then analyzes them. While existing tools can detect attacks, they tend to report them to the SOC. Sevii’s new AI module “picks up” this reading and reacts instantly and autonomously with its own AI-driven machine speed.

It uses AI agents (it calls them “cyber warriors”) to undertake a seven-day retrospective search of context to determine whether an action detected is normal or unusual. This is used to confirm a real AI attack. If it’s real, cyber warriors look for the possibility that the same attack could happen elsewhere in the customer’s infrastructure. This identifies whether the attack is broader than initial detection and helps determine whether it requires immediate remediation.

“When we get the AIDR finding, we go into action to determine if it’s good or bad policy, or acting in the most equitable way,” explained Sevii CEO and co-founder Kurt Aubley. “We immediately gather all the data we need. We call it hunting. We grab all that data and analyze it so we can reverse engineer the attack and take whatever action we need.”

If remediation is required, it can be autonomous or triggered by a human defender in the loop. As a realist, the human-in-the-loop option is a marketing comfort: companies like to have that option, even if it’s counterproductive. In reality, any defense against an AI attack must be able to respond at the same machine speed as the attack itself. Requiring a human in the loop defeats this.

Advertising. Scroll to continue reading.

“Having a human in the loop may be required by today’s governance policy. But consider the damage and speed with which OpenAI rogue agents attacked Hugging Face,” Aubli commented. “Seventeen seven-minute acts. It’s mathematically impossible for a human to manage that.” Speed ​​and the remediation process are essential to the success of any defense against an AI-driven attack.

Sevii recovery can be immediate. As it gathers context for its next steps, it can detect a large volume of data leaving the customer. It performs an instant search for information. Is this a standard occurrence? Where does the data go? Is it going to known command and control C2 or infrastructure that is known to be bad? The knowledge that a destination might be bad may have arisen in the last 15 minutes, but Sevii already knows it.

If a customer sends data to an unsafe location, “We will absolutely immediately stop that activity and autonomously do an impact analysis to see what data is left and how quickly we stopped it,” Aubli said

A simple example of Sevii’s standard remediation process can be seen in the autonomous action it takes against a compromised laptop. “Let’s say an employee uses a laptop and uses the same ID and password to access different systems like SAP, Salesforce or ServiceNow,” Aubli explained. “Whatever the applications, we might get a detection that the laptop has been compromised and the user’s identity starts doing strange activity — they can log into systems they’ve never logged into before. So we’ll do our hunting and checking to confirm that the detection is a true positive.”

The next step is insulation. “We’re going to isolate the laptop and disable the account, we’re going to remove those sessions from that account and force the person to reset their password. So, first the identity part is stopped so the adversary can no longer get into those other systems. That stops the spread. We’re connecting securely to the laptop and we’re removing bad processes and logs and things of that nature,” he continued.

“Once that’s done, we remove the isolation. We do a final validation and monitor that system to make sure it’s not behaving weird anymore. If we’re happy, we release it back to the customer.”

This fully autonomous, AI-driven process typically takes between two and fifteen minutes. The stay is minimal. Since an AI attack usually takes between 30 seconds and 30 minutes, with an average of the same 15 minutes it will take Sevii to take down, this new AIDR module can truly be described as a successful attempt at fighting fire with fire.

Connected: UK government introduces Agentic AI defense plan alongside industry pledge

Connected: Fixed Claude flaw for Chrome allowing extensions to read Gmail, Calendar

Connected: Sevii launches Cyber ​​Swarm Defense to make Agentic AI’s security costs predictable

Connected: Can we trust AI? No – but eventually you have to

Leave a Reply

Your email address will not be published. Required fields are marked *