Fortinet introduces Self-Learning AI appliance
Fortinet® announced FortiAI, an appliance
that leverages self-learning Deep
Neural Networks (DNN) to speed threat remediation and handle time consuming, manual
security analyst tasks. FortiAI’s Virtual Security AnalystÔ is developed
by Fortinet’s
FortiGuard Labs – directly into an
organization’s network to deliver sub-second detection of advanced threats.
John Maddison, EVP of
products and CMO at Fortinet
“Fortinet has invested heavily in
FortiGuard Labs cloud-based AI-driven threat intelligence, allowing us to
detect more threats, more quickly and more accurately. FortiAI takes the
artificial intelligence knowledge from FortiGuard Labs and packages it
specifically for on-premises deployments. This gives customers the power of
FortiGuard Labs directly in their environment, with self-learning AI to
identify, classify and investigate sophisticated threats in sub-seconds.”
Organizations Face
an Uphill Battle
Security architects confront many challenges when it
comes to discovering and remediating threats, including:
- Cybercriminals are becoming more
sophisticated. While
traditional cyber threats continue, sophistication of advanced attacks – often enabled by
artificial intelligence, machine learning and open source communities – are
increasing. As a result, organizations and their defenses are challenged to
keep pace with threat evolution.
- The attack surface is expanding. Millions of new applications, growing cloud adoption and the increase in connected devices are creating billions of edges that security teams need to properly protect and manage. Organizations are challenged to keep pace with the threat volume resulting from many potential entry points.
- Security teams are
constrained due to the cyber skills shortage. There are not enough skilled professionals available in organizations
to properly triage, investigate and respond to the growing number of threats – potential
and actual – making it easier
for cybercriminals to outpace legacy security processes and tools.
Self-Learning AI Adapts Organizations’ Threat Protection
To address these challenges faced by security
professionals today, Fortinet is unveiling FortiAI Virtual Security AnalystÔ to accelerate threat remediation.
FortiAI Levels the Playing Field
Fortinet’s Deep Neural Networks (DNN) approach enables FortiAI to revolutionize
threat protection by:
- Automating
time-consuming manual investigations to identify and classify threats in real
time: Organizations using legacy security
processes combined with limited security staff find it difficult to perform
manual investigations for each threat alert. This creates additional risks including
a data breach or security incident due to slow response time. To solve this,
FortiAI automates investigations using DNN to identify the entire threat
movement and uncover patient zero and all subsequent infections in a sub-second.
- Transforming security processes for instant detection and remediation of attacks: FortiAI’s Virtual Security AnalystÔ significantly reduces the time organizations are exposed to threats by scientifically analyzing characteristics of threats and generating an accurate verdict to accelerate threat response.
- Delivering
tailored threat intelligence to significantly reduce false positives: False positives are a burden for security
analysts to investigate and it is time consuming to determine threats versus
non-threats. Through tailored threat intelligence, FortiAI learns new malware
features as it adapts to new attacks instantaneously and reduces false
positives.
On-premises Protection for Air Gapped Networks
FortiAI offers on-premises AI
suitable for organizations that have air gapped networks. Operational technology
environments, government agencies and some large enterprises must adhere to
strict compliance regulations and/or security policies that limit their
network’s connection to the internet. FortiAI with its self-learning AI model
does not require internet connectivity to learn and mature, enabling
organizations with closed environments or stringent security policies to stay
ahead of threats.
Fortinet’s AI-driven Technologies
Automate Threat Protection
Fortinet has a longstanding history of helping customers
strengthen their security posture by
leveraging artificial intelligence. Some of the existing Fortinet offerings and
services, complemented by the new FortiAI, that leverage various forms of AI,
such as least squares optimization and Bayesian probability metrics, include:
- FortiGuard Labs Threat Intelligence: FortiGuard
Labs uses proven
advanced AI and machine learning to gather and analyze over 100 billion security
events every day. This threat intelligence produced by FortiGuard Labs is
delivered to customers through its subscription services available for a range
of Fortinet’s products, including the flagship FortiGate NGFWs. As a result,
customers benefit from artificial intelligence deployed in global labs for
faster threat prevention.
- FortiSandbox: FortiSandbox
includes two machine learning models to its static and dynamic analysis of
zero-day threats, improving the detection of constantly evolving malware, such
as ransomware and cryptojacking. Through the use of a universal security
language to categorize malware, FortiSandbox also connects discussions between
network and security teams, leading to more integrated and improved security
operations.
- FortiEDR: Fortinet’s FortiEDR uses machine learning to automate the endpoint protection against advanced threats
with real time orchestrated incident response functionalities. Customers also
benefit from more control of network, user and
host activity within their environments.
- FortiInsight: FortiInsight uses machine learning analytics to
effectively monitor endpoints, data movements and user activities to detect
unusual, malicious behavior and policy violations attributed to insider risk.
- FortiWeb: To better protect web applications and APIs,
FortiWeb applies machine learning to tailor a unique
defense for each application. As a result, FortiWeb can quickly block threats
while minimizing the false positives that may interfere with end user
experience.
- FortiSIEM: FortiSIEM leverages machine learning to recognize patterns in typical user behavior like location, time
of day, devices used and specific servers accessed. FortiSIEM can then
automatically notify security operations teams when anomalous activities occur,
like concurrent logins from separate locations.
As cyber criminals
look to exploit the expanding digital attack surface with sophisticated attacks,
the breadth and depth of the Fortinet
Security Fabric’s AI-driven
technology provides customers with unparalleled threat prevention, detection
and response that can be instant and automated.