📺
YouTube · USENIX
9 YouTube-Aufrufe
Krupa Brahmkstri, Visa
Modern security tools claim to detect attacks, yet in practice they generate signals: alerts, anomalies, and observations. The actual act of detection is performed by human analysts who correlate fragmented evidence, form hypotheses, and reconstruct attack narratives across identities, systems, and time. This distinction exposes a fundamental architectural flaw in modern security operations. Most security infrastructures are designed around alert generation, while the critical work of investigative reasoning remains largely manual.
This talk introduces the concept of Inference-Driven Detection, a model that reframes attack detection as a reasoning problem rather than an anomaly-identification problem. Drawing on lessons from large-scale enterprise security environments, it explores why attacks such as credential abuse, privilege escalation, and lateral movement are often discovered through narrative reconstruction rather than isolated alerts. The talk argues that future security systems must move beyond alert-centric architectures and instead support human and AI-assisted investigative reasoning to identify and understand adversarial behavior.
View the full USENIX Security '26 program at https://www.usenix.org/conference/usenixsecurity26/technical-sessions
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
SOCIAL SHARE CARD GENERATOR