HomeMalware & ThreatsAnthropic Shifts Claude Focus to Critical Infrastructure

Anthropic Shifts Claude Focus to Critical Infrastructure

Published on

spot_img

Artificial Intelligence & Machine Learning,
Critical Infrastructure Security,
Next-Generation Technologies & Secure Development

11 Industry Partners Will Pair Claude With Engineers to Tackle OT Vulnerabilities

Anthropic Shifts Claude Focus to Critical Infrastructure
Image: Shutterstock

In a significant push to address the vulnerabilities present in operational technology (OT) systems that are often challenging to update or take offline, Anthropics has unveiled a new initiative. By pairing artificial intelligence with human expertise, the company aims to enhance the security of these critical systems.

Through its recently launched Critical Infrastructure Defense Program, announced on Thursday, Anthropic will provide access to its advanced Claude AI models, on-site engineers, and dedicated threat research to a coalition of eleven companies. These companies serve as advisors to operators of essential systems such as power grids, water utilities, factories, and transportation networks.

The initiative acknowledges the complex nature of OT and Internet of Things (IoT) systems. However, its success hinges on operators’ ability to implement fixes in a timely manner, in tandem with AI’s capability to identify vulnerabilities without disrupting ongoing operations. Jen Sovada, public sector general manager at OT security firm Claroty, remarked on the difficulties faced in securing critical infrastructure environments. She emphasized the need to prioritize risk signals carefully, particularly when taking a system offline could lead to significant consequences.

Anthropic’s new program follows an earlier expansion of its Cyber Verification Program, designed to make AI models available to all critical infrastructure operators. The models will have fewer restrictions, allowing for both defensive and offensive applications in cybersecurity. John Gallagher, vice president of OT cyber hygiene provider Viakoo, elaborated on the unique challenges faced by OT and IoT systems in terms of patch management. He noted that many of these systems only receive updates during specific maintenance windows, while AI-driven threats can escalate quickly, often within days.

This new OT defense program will collaborate with a select group of trusted partners who will assist OT maintainers in identifying vulnerabilities and suggesting real-time fixes. The founding partners of this program include prominent firms such as Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. These partnerships have already begun implementing Claude for vulnerability assessments, sharing their findings with customers in the process.

According to Anthropic, the goal is to learn from this small cohort of providers to determine the most effective strategies for mitigating risks. While these leading companies represent only a fraction of the critical infrastructure landscape, this initiative is a vital step toward bridging the widening gap between AI-driven attacks and the necessary defenses to counter them.

Recent headlines have increasingly highlighted the repercussions of cyberattacks on critical infrastructure. For instance, a minor power plant in the United Kingdom was offline for four days this past August, and in July, over 30 community water systems in Minnesota were forced to revert to manual controls due to a coordinated cyberattack. Programmable logic controllers, which play a crucial role in automating industrial processes, have become a focal point in these attacks, particularly as they are reportedly being targeted by Iranian-affiliated hackers.

Despite this growing concern, many outdated legacy OT devices remain challenging to secure. These devices often operate on old software, use default credentials, and lack comprehensive security monitoring. However, AI holds promise in addressing these issues. Gallagher noted that AI excels in quickly analyzing binary firmware across various devices, which can help unearth unpatched open-source libraries prone to exploitation.

Though there are numerous commercial solutions aimed at enhancing threat detection and vulnerability management within critical infrastructures, they often struggle at the “last mile” of defense, according to Gallagher. He cautioned that simply accelerating the discovery of high-severity vulnerabilities does not necessarily protect utilities. If applying fixes remains cumbersome, the effectiveness of these solutions may diminish significantly.

Sovada emphasized that Anthropic’s approach is commendable in that it integrates experts familiar with the intricacies of physical operations in OT. AI, while powerful, cannot supplant the human expertise vital for navigating the operational landscapes of these systems. Identifying vulnerabilities is only one part of the equation; understanding how to manage them without disrupting essential services is another critical challenge.

Experts like Josh Corman, executive-in-residence for public safety and resilience at the Institute for Security and Technology, highlighted that security measures for IT could adversely affect fragile OT environments. Basic IT practices, such as asset discovery or port scanning, can inadvertently disrupt older systems. Corman noted the importance of tailored solutions for operators who often depend on aging equipment that may not be able to undergo regular patching.

He lamented that, even when patches are available, many organizations are limited in their ability to implement them frequently. Often using outdated and unsupported versions of essential products, these operators struggle against the challenges of maintaining operational continuity while also safeguarding their systems against evolving threats.

Overall, Anthropic’s initiative seeks to merge cutting-edge AI technology with human expertise to create robust solutions for securing critical infrastructure, a necessary evolution in an increasingly complex security landscape.

Source link

Latest articles

UK Allies Warn of Cyber Threat Posed by China’s Integrity Technology Group

On October 8, a significant alert was jointly issued by the United States, the...

Ransomware Consultant Claims He Would Decrypt Data but is Accused of Paying Ransoms Instead

Title: Allegations Surface Against MonsterCloud Regarding Ransom Payment Practices In an alarming development within the...

Core to Cloud Appoints David Brown Managing Director

Core to Cloud Strengthens Leadership with Appointment of David Brown as Managing Director UK cybersecurity...

More like this

UK Allies Warn of Cyber Threat Posed by China’s Integrity Technology Group

On October 8, a significant alert was jointly issued by the United States, the...

Ransomware Consultant Claims He Would Decrypt Data but is Accused of Paying Ransoms Instead

Title: Allegations Surface Against MonsterCloud Regarding Ransom Payment Practices In an alarming development within the...

Core to Cloud Appoints David Brown Managing Director

Core to Cloud Strengthens Leadership with Appointment of David Brown as Managing Director UK cybersecurity...