Many Hands Make Light Work

The amount of data generated worldwide continues to grow exponentially. Most of which is hacking tools and other bots or nefarious actors. Between 2023 and 2024, the number of fake Australian Government websites created to steal credentials reportedly doubled in the first quarter alone.
These Government Departments are holding Australia’s most valuable data resource including Tax File Numbers, Social Security, Veteran Affairs… and they’re protected by the best Australia has to offer, the Australian Signals Directorate and its “unique capabilities” in information retrieval, analysis and then most notably of late offensive cyber capabilities that are rumoured to be 5 orders of magnitude in places like this. 1 defensive technician, for every 5 offensive technician. The recent REDSPICE program announcement came with it a huge bursary. The government doing its due diligence where it can when it comes to the secret world of signals intelligence.
Though I digress, but for a reason. These capabilities aren’t available to individuals and then small to medium sized business many of whom don’t have formal cyber policies let alone the capabilities of an intel service.
Within cybersecurity firms, one critical role is that of a Threat Hunter. Threat Hunters are often part of a Security Operations Center (SOC) or a specialized team focused on defending a company’s intellectual property and digital assets. In some firms, entire SOCs are dedicated to these tasks. However, due to an undersupply of skilled professionals and the high demand for such expertise, many organizations are struggling to adequately staff these roles.
Why Crowd Computing?
Crowd computing is becoming increasingly important for several reasons, particularly for companies running AI applications. Setting up a dedicated “supercomputer” involves immense costs, significant physical space, and ongoing maintenance. Moreover, the computational demand for AI can fluctuate dramatically. For instance, a company may only require 20% of its computing power during off-peak hours, rendering much of its hardware temporarily idle.
A decentralized, crowd-sourced computing network can solve this problem. By leveraging shared computing resources, companies can dynamically scale their computing power according to real-time demand. This flexibility is not just about accessing more CPUs or GPUs; it’s also about integrating human expertise into the AI loop to verify and audit decisions made by AI systems. Crowdsourced computing enables AI systems to harness human intelligence to validate and improve their models, making them more robust and adaptive at scale.
Furthermore, crowd computing can generate significantly larger datasets for deep learning models, enhancing the training process and improving AI accuracy. The combination of machine and human intelligence creates a powerful synergy that drives continuous improvement in AI systems.
Humans in the Loop
The complexity and evolving nature of the infosec landscape make human involvement essential. Even with advanced AI systems, human threat hunters and analysts play a critical role. AI can leverage a peer-to-peer mesh of protection and information sharing, but human expertise remains crucial to adapt and respond quickly when an adversary penetrates the network’s defenses and enters its OODA (Observe, Orient, Decide, Act) loop. The presence of skilled human operators makes it more difficult for attackers to maintain their advantage.
System Design
A theoretical framework for a prototype technology to supplement the efforts of expensive threat hunters. It is of my humble opinion that future (now?) of information security will likely revolve around hybrid systems that combine AI and human intelligence. Here’s a blueprint for such a system:
1. Distributed Raw Information Communication: A decentralized network where raw data is continuously collected and shared.
2. Cohort of Models and Agents: At the “top of the pipe,” a collection of AI models and agents analyze the incoming data for patterns of anomalous activity, such as unusual network traffic or activity from specific geographical regions.
3. Human Analyst Triage: When the system identifies traffic or behaviors of interest, it funnels this information to human analysts for deeper investigation and context.
4. Reinforcement Learning: The system uses offline training mechanisms to reinforce learning, improve detection accuracy, and minimize false positives.
5. Custom Reports by LLMs: Large Language Models (LLMs) can generate tailored reports for different stakeholders. For example, network administrators receive prompts with detailed technical insights relevant to their roles, while CISOs get high-level summaries that provide a broader view of the threat landscape.
Why Crowd Computing?
Another reason crowd computing is important is the cost and difficulty for companies to set up their own “supercomputer”. Besides the immense cost and space required, an AI application’s fluctuating computing demand is the issue. Meaning that a company may only need 20% of its computing power at slow hours while the rest of its rigs are temporarily rendered obsolete.
This makes employing a crowd-sourced, decentralized computing network of human experts ideal for companies running AI applications. These shared computing resources can be leveraged by the application’s computing demand, and the AI can rely on more or less global computing resource providers, according to demand. Not to mention the availability of human experts that can verify and audit the decisions of the AI application.
Crowdsourced computing enables AI systems to leverage the benefits of human intelligence, which can help verify and validate their decisions and ultimately make them evolve at scale. Crowd computing can also produce much larger data sets for deep learning algorithms to use in the machine learning process.
Humans in the Loop
The complexity, nuances and evolutionary nature of the infosec landscape mean that the presence of human threat hunters and associates are still of paramount importance. Well tested Artificial Intelligence systems leveraging a peer-peer mesh of protection and information will make the job of the adversary more difficult and quicker to respond if an adversary does make it inside the OODA Loop of a member of the network.
Systems Design
- Distributed raw information communication.
- Cohort of models and agents performing “top of the pipe” analysis. If there is a recurring pattern of anomalous traffic originating from similar network address ranges, behavioural or geographical regions.
- Traffic of interest is funnelled to human analysts triaged by the system.
- Reinforcement Learning rewards the system through an offline training mechanism to improve accuracy and importantly, minimise false positives.
- Reports can be written by LLM’s for specific departments. For example a network administrator will have prompts for collecting the relevant contextual information for their configuration and AIOps, while a CISO will get a thousand meter look at the landscape. Different intelligence derived from the same data.
With advancements like this coming down the pipeline the ability of infosec teams to mitigate an ever more powerful and automated adversity is fighting fire with fire.
Looking Forward
With these advancements, infosec teams are better equipped to confront increasingly automated and sophisticated adversaries. Leveraging both AI and human intelligence in a crowd-computing model allows organizations to “fight fire with fire,” staying ahead of evolving threats in an ever-changing cybersecurity
Number of fake Australian Government fake news websites to steal credentials doubled in the first quarter reportedly.
One of the job roles within a Cyber company is a Threat Hunter. You will find Threat Hunters as part of a team, in specialised firms an entire SOC may be working to defend company’s IP and other assets.
Due to an under supply and over demand a sma
Why Crowd Computing?
Another reason crowd computing is important is the cost and difficulty for companies to set up their own “supercomputer”. Besides the immense cost and space required, an AI application’s fluctuating computing demand is the issue. Meaning that a company may only need 20% of its computing power at slow hours while the rest of its rigs are temporarily rendered obsolete.
This makes employing a crowd-sourced, decentralized computing network of human experts ideal for companies running AI applications. These shared computing resources can be leveraged by the application’s computing demand, and the AI can rely on more or less global computing resource providers, according to demand. Not to mention the availability of human experts that can verify and audit the decisions of the AI application.
Crowdsourced computing enables AI systems to leverage the benefits of human intelligence, which can help verify and validate their decisions and ultimately make them evolve at scale. Crowd computing can also produce much larger data sets for deep learning algorithms to use in the machine learning process.
Humans in the Loop
The complexity, nuances and evolutionary nature of the infosec landscape mean that the presence of human threat hunters and associates are still of paramount importance. Well tested Artificial Intelligence systems leveraging a peer-peer mesh of protection and information will make the job of the adversary more difficult and quicker to respond if an adversary does make it inside the OODA Loop of a member of the network.
Systems Design
- Distributed raw information communication.
- Cohort of models and agents performing “top of the pipe” analysis. If there is a recurring pattern of anomalous traffic originating from similar network address ranges, behavioural or geographical regions.
- Traffic of interest is funnelled to human analysts triaged by the system.
- Reinforcement Learning rewards the system through an offline training mechanism to improve accuracy and importantly, minimise false positives.
- Reports can be written by LLM’s for specific departments. For example a network administrator will have prompts for collecting the relevant contextual information for their configuration and AIOps, while a CISO will get a thousand meter look at the landscape. Different intelligence derived from the same data.
With advancements like this coming down the pipeline the ability of infosec teams to mitigate an ever more powerful and automated adversity is fighting fire with fire.