AI Security AI安全 6h ago Updated 2h ago 更新于 2小时前 41

The Future of AI-Driven Security Depends on Complete Data AI驱动安全的未来取决于完整的数据

Traditional SIEM architectures are fundamentally flawed for AI-driven security because they only capture 10-20% of generated telemetry, discarding critical context through pre-filtering and normalization Modern AI-powered attacks span multiple domains (network, cloud, identity, endpoints), requiring complete multi-source data to reconstruct attack chains and intent The most valuable enterprise data—source code, financial models, IP—is routinely excluded from security analysis due to privacy and SOC的核心问题在于架构缺陷而非人力不足,传统系统无法为AI提供完整的高保真数据 传统日志仅保留环境生成数据的10-20%,丢失了关键上下文和时间关系,无法重建攻击链 AI驱动的安全需要完整的多产品数据,包括安全遥测、基础设施、身份和端用户数据 企业最敏感的数据(源代码、商业文档)因隐私和合规顾虑被排除在安全分析之外,形成关键盲区 数据完整性和主权是AI安全的双重需求,未来竞争关键在于谁能为AI提供最完整的数据而非最复杂的模型

55
Hot 热度
62
Quality 质量
58
Impact 影响力

Analysis 深度分析

TL;DR

  • Traditional SIEM architectures are fundamentally flawed for AI-driven security because they only capture 10-20% of generated telemetry, discarding critical context through pre-filtering and normalization
  • Modern AI-powered attacks span multiple domains (network, cloud, identity, endpoints), requiring complete multi-source data to reconstruct attack chains and intent
  • The most valuable enterprise data—source code, financial models, IP—is routinely excluded from security analysis due to privacy and regulatory concerns, creating dangerous blind spots
  • Data completeness and data sovereignty are inseparable: organizations must run AI within their own environment to access "crown jewel" data without violating GDPR, CLOUD Act, DORA, or HIPAA
  • The competitive advantage in AI-driven security will belong to organizations that provide their models with the most complete, high-fidelity data while retaining full control over their data and infrastructure

Why It Matters

This article reframes the AI-in-security debate from model sophistication to data architecture, challenging the industry assumption that better algorithms alone will solve SOC challenges. For practitioners, it highlights that investing in data completeness and on-premises AI deployment may yield greater security returns than chasing the latest threat detection model. The convergence of data sovereignty requirements with AI capability needs is becoming a strategic differentiator for enterprises navigating increasing regulatory scrutiny.

Technical Details

  • Current SIEM systems receive only 10-20% of generated telemetry because security products pre-filter and normalize data before forwarding, stripping process-creation events of full context and timing relationships to adjacent events
  • AI-powered attacks require correlation across four or more distinct systems (DLP, CASB, identity, endpoint) to reconstruct attack chains—examples include insider exfiltration spanning document access, download, cloud upload, and external email
  • Complete data requirements include: security telemetry, infrastructure/operational data (network, OT sensors, IoT, SaaS, cloud), identity context (human and non-human accounts, API keys, tokens), end-user data (files, documents, content flows), and proprietary "crown jewel" data
  • Regulatory constraints (GDPR, US CLOUD Act, DORA, HIPAA) prevent cloud-dependent AI architectures from ingesting sensitive data, making on-premises or sovereign AI deployment a technical necessity rather than a preference
  • Pattern detection requires longitudinal correlation: a single anomalous event (e.g., 1 AM login) is ambiguous, but 50 correlated logins over six months combined with device telemetry and access patterns reveal true intent

Industry Insight

  • Organizations should prioritize data architecture modernization—implementing full-fidelity telemetry collection and on-premises AI deployment—over incremental SIEM upgrades or model procurement, as data completeness is the primary bottleneck for AI security effectiveness
  • The convergence of data sovereignty regulations and AI capability requirements will accelerate demand for sovereign/on-premises AI security platforms, creating a competitive moat for vendors that can deliver both completeness and control
  • CISOs should challenge the assumption that cloud-based AI security tools can adequately protect crown jewel data; the regulatory and operational risks of excluding sensitive data from analysis may outweigh the convenience of cloud deployment, making hybrid or fully sovereign architectures the strategic choice

TL;DR

  • SOC的核心问题在于架构缺陷而非人力不足,传统系统无法为AI提供完整的高保真数据
  • 传统日志仅保留环境生成数据的10-20%,丢失了关键上下文和时间关系,无法重建攻击链
  • AI驱动的安全需要完整的多产品数据,包括安全遥测、基础设施、身份和端用户数据
  • 企业最敏感的数据(源代码、商业文档)因隐私和合规顾虑被排除在安全分析之外,形成关键盲区
  • 数据完整性和主权是AI安全的双重需求,未来竞争关键在于谁能为AI提供最完整的数据而非最复杂的模型

为什么值得看

这篇文章揭示了AI安全落地的核心瓶颈——数据完整性而非模型复杂度,为安全从业者提供了重新思考SIEM架构和数据策略的关键视角。在AI降低攻击门槛的背景下,它强调了"完整数据+数据主权"是构建有效AI驱动安全运营的基础。

技术解析

  • 传统SIEM架构缺陷:安全产品对遥测数据进行预过滤和归一化,导致只有10-20%的环境数据到达SIEM,日志丢失了完整上下文和时间关系
  • 攻击链重建需求:现代AI攻击跨越多个系统(如DLP、CASB、邮件系统),需要完整的数据血缘和时间线才能识别意图,孤立异常无法揭示攻击序列
  • 数据完整性四要素:需要安全遥测、基础设施/运营数据(网络、OT、IoT、SaaS、云)、身份数据(人和非人账户)、端用户数据以及专有数据(crown jewels)
  • 数据主权架构:需要在组织内部运行AI而非依赖第三方云,以符合GDPR、CLOUD Act、DORA、HIPAA等法规要求

行业启示

  • 安全架构需要从"日志收集"转向"完整数据摄取",重新评估SIEM和数据管道设计,避免AI因数据缺失而失效
  • 数据主权将成为AI安全采购的关键决策因素,本地化部署和可控模型的需求将推动安全架构变革
  • 安全团队需要与业务部门协作,重新定义敏感数据的处理策略,在合规前提下扩大AI可见性,消除数据盲区

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 AI AI SOC SOC