Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense

Sevii has expanded its ADR platform with AI agents designed to investigate, contain, and remediate AI-driven attacks within minutes.

Fighting fire with fire is a known response. Fighting AI attacks with AI defense is a growing practice. But instant remediation is new and welcome.

Sevii has extended its Autonomous Defense & Remediation (ADR) platform with a new AI security module. As the speed and scope of AI driven attacks increases, it requires an AI defense. Since companies are rarely aware of all the shadow AI used within the organization, this defense needs to operate at runtime irrespective of source, with effectively immediate and autonomous remediation.

This is what the new module provides. As with Sevii’s wider ADR platform, alerts are received from the customer’s entire security detection stack. The new module ingests these alerts in real-time and then analyzes them. While existing tools can detect attacks, they tend to report them to the SOC. Sevii’s new AI module ‘intercepts’ this reporting and responds instantly and autonomously with its own AI-driven machine speed.

It uses AI agents (it calls them ‘cyber warriors’) to undertake a seven-day retrospective context hunt to determine whether the detected action is normal or abnormal. This is used to confirm a genuine AI attack. If genuine, the cyber warriors look for the possibility of the same attack occurring elsewhere within the customer’s infrastructure. This identifies whether the attack is broader than the initial detection and helps to determine if it requires immediate remediation.

“When we get the AIDR detection, we start the action to determine whether it is good or bad from policy, or is it acting in the fairest way,” explained Sevii’s CEO and co-founder, Curt Aubley. “We immediately collect all the data we need. We call it a hunt. We grab all that data and analyze it to be able reverse engineer the attack and take any necessary action.”

If remediation is necessary, it may be autonomous or triggered by a human defender in the loop. Being realistic, the ‘human in the loop’ option is a marketing comforter: companies like to have that option even if it is counterproductive. In reality, any defense against an AI attack must be able to react with the same machine speed as the attack itself. Requiring a human in the loop defeats this.

Advertisement. Scroll to continue reading.

“Having a human in the loop may be required by today’s governance policy. But consider the damage and speed at which OpenAI rogue agents attacked Hugging Face,” commented Aubley. “Seventeen seven-minute actions. It’s mathematically impossible for a human to keep up with that.” The speed and process of remediation is essential to the success of any defense against an AI-driven attack.

Sevii’s remediation can be immediate. While it is gathering context for its next steps, it may detect a high volume of data leaving the customer. It performs an instant intelligence search. Is this a standard occurrence? Where is the data going? Is it going to a known command and control C2, or infrastructure that is known to be bad? Knowledge that a destination may be bad could have occurred within the last 15 minutes, but Sevii already knows it.

If the customer is sending data to a dangerous location, “We will absolutely immediately stop that activity and autonomously do an impact analysis as well to see what data left and how quickly we stopped it,” said Aubley

A simple example of Sevii’s standard remediation process can be seen in the autonomous action it takes against a compromised laptop. “Let’s say an employee is using a laptop and uses the same identity and password to access different systems such as SAP, Salesforce or ServiceNow,” explained Aubley. “Whatever the applications are, we may get a detection that the laptop has been compromised, and the user’s identity is starting to do weird activity – it may be logging in to systems it’s never logged into before. So, we’ll do our hunt and validation to confirm the detection is a true positive.”

The next step is isolation. “We will isolate the laptop and disable the account, remove those sessions from that account, and force the person to reset their password. So, first the identity portion is stopped, so the adversary can no longer log into these other systems. That stops the spread. We securely connect to the laptop and remove the bad processes and registries and things of that nature,” he continued. 

“Once done, we remove the isolation. We do a final validation, and we watch that system to make sure that it is not acting strangely anymore. If satisfied, we release it back to the customer.”

This complete AI-driven autonomous process typically takes between two and fifteen minutes. Downtime is minimal. Since an AI attack typically takes between 30 seconds and 30 minutes, with an average of the same 15 minutes that it will take Sevii to remediate, this new AIDR module can truly be described as a successful attempt at fighting fire with fire.

Related: UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge

Related: Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar

Related: Sevii Launches Cyber Swarm Defense to Make Agentic AI Security Costs Predictable

Related: Can We Trust AI? No – But Eventually We Must

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Social engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.

Naveen Bhateja has been appointed Chief People Officer at HackerOne.

The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.