•  
  •  
 
Communications of the Association for Information Systems

Author ORCID Identifier

Anik Mukherjee: 0000-0001-9130-5720

Indranil Bose: 0000-0002-5737-966X

Abstract

CyberCom, recognized for its cloud-based security solutions that emphasize antivirus protection, malware detection, and endpoint security, has developed several key products: CyberComSECURE, CyberComLENS, and CyberComSHIELD. These products are designed to defend against system vulnerabilities and enable rapid responses to cyber threats. Central to the product line is a machine learning (ML) model trained on vast amounts of data related to malware and past cyber incidents, offering reliable detection of known malware. However, external security researchers discovered vulnerabilities within this model that rendered it ineffective in detecting mutated malware files. These altered files exploited the system's reliance on historical data, exposing the critical limitation of artificial intelligence (AI)-based cybersecurity tools in addressing new and evolving threats. The case describes what led to this scenario and raises the question how CyberCom should handle the crisis and future-proof its products against similar attacks.

Share

COinS
 

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.