The post has been translated automatically. Original language: Russian
Kazakhstan's cybersecurity can be Kazakh
Every day, financial organizations fend off thousands of attempted network attacks.
The best global solutions are used for this purpose — Cisco, Palo Alto Networks, IBM, Fortinet and others. These systems have proven their effectiveness for decades and remain the foundation of modern security.
But one question has been nagging at me for a long time.
Why is the intelligent analysis of network traffic for Kazakhstani organizations almost always based on foreign technologies?
Is it possible to create your own system that will work locally, take into account the requirements of the domestic infrastructure and not transfer network data outside the organization?
This is how the AIKA project appeared.
What is AIKA?
AIKA is an intelligent network attack detection System (AI Intrusion Detection System).
It does not replace existing security features.
It becomes an additional layer of intelligent analysis, which helps to detect suspicious activity in almost real time.
The system is installed inside the client's infrastructure.
All calculations are performed locally.
Network traffic is not sent to external cloud services.
How the system was created
An open data set containing more than 2.5 million network events was used to train the model.
The model was trained to recognize various types of network attacks, including:
DoS;
DDoS;
Port Scan;
Brute Force;
Web Attacks;
Botnet activity;
as well as normal network traffic.
After several cycles of training and testing, it was possible to obtain a stable model for detecting network anomalies.
Today, AIKA is able to analyze network traffic and detect signs of suspicious activity in near real time.
How it looks in practice
Imagine an ordinary work night.
Someone is gradually starting to select passwords for the internal service.
Each individual request looks quite legitimate.
But AIKA does not analyze individual packets, but the behavior of the stream.
When the system sees a characteristic pattern of brute force passwords, it detects the anomaly, generates a warning, and transmits the information to an information security specialist.
Not after the incident.
During its development.
Why is this important to me?
I'm not trying to build "another antivirus."
And I'm not going to replace the existing corporate security tools.
My goal is to create an intelligent assistant for cybersecurity professionals.
A system that helps to detect threats faster, reduce the burden on analysts, and strengthen the organization's existing defenses.
What's next
AIKA is currently at the MVP stage.
A web-based monitoring interface, event logging, an AI model for detecting network anomalies, and a local operating mode are already in operation.
The next step is pilot testing in a real infrastructure.
Who are we looking for
We are looking for an organization that is ready to conduct a pilot project.
It can be:
bank;
telecom operator;
Government organization;
data center;
a large corporate network.
We do not suggest buying the product right away.
We suggest to see how it works in real conditions, to receive honest professional feedback and together to determine the directions of further development.
Why do I believe in this project?
I am convinced that Kazakhstan is capable of creating its own world-class engineering solutions.
Do not copy.
Not to catch up.
And to create technologies that you can be proud of.
If you are interested in seeing AIKA in operation or discussing the possibility of a pilot project, I will be glad to meet you.
AIKA Security
Artificial Intelligence Knowledge Assistant
Made in Kazakhstan.
Казахстанская кибербезопасность может быть казахстанской
Каждый день финансовые организации отражают тысячи попыток сетевых атак.
Для этого используются лучшие мировые решения — Cisco, Palo Alto Networks, IBM, Fortinet и другие. Эти системы десятилетиями доказывали свою эффективность и остаются основой современной защиты.
Но меня давно не покидал один вопрос.
Почему интеллектуальный анализ сетевого трафика для казахстанских организаций почти всегда строится на зарубежных технологиях?
Можно ли создать собственную систему, которая будет работать локально, учитывать требования отечественной инфраструктуры и не передавать сетевые данные за пределы организации?
Так появился проект AIKA.
Что такое AIKA
AIKA — это интеллектуальная система обнаружения сетевых атак (AI Intrusion Detection System).
Она не заменяет существующие средства защиты.
Она становится дополнительным уровнем интеллектуального анализа, который помогает обнаруживать подозрительную активность практически в реальном времени.
Система устанавливается внутри инфраструктуры клиента.
Все вычисления выполняются локально.
Сетевой трафик не отправляется во внешние облачные сервисы.
Как создавалась система
Для обучения модели использован открытый набор данных, содержащий более 2,5 миллионов сетевых событий.
Модель обучалась распознавать различные типы сетевых атак, включая:
DoS;
DDoS;
Port Scan;
Brute Force;
Web Attacks;
Botnet-активность;
а также нормальный сетевой трафик.
После нескольких циклов обучения и тестирования удалось получить устойчивую модель обнаружения сетевых аномалий.
Сегодня AIKA способна анализировать сетевой поток и выявлять признаки подозрительной активности в режиме, близком к реальному времени.
Как это выглядит на практике
Представьте обычную рабочую ночь.
Кто-то начинает постепенно подбирать пароли к внутреннему сервису.
Каждый отдельный запрос выглядит вполне легитимным.
Но AIKA анализирует не отдельные пакеты, а поведение потока.
Когда система видит характерный шаблон перебора паролей, она фиксирует аномалию, формирует предупреждение и передает информацию специалисту по информационной безопасности.
Не после инцидента.
Во время его развития.
Почему для меня это важно
Я не пытаюсь построить «ещё один антивирус».
И не собираюсь заменить существующие корпоративные средства защиты.
Моя цель — создать интеллектуального помощника для специалистов по кибербезопасности.
Систему, которая помогает быстрее замечать угрозы, снижать нагрузку на аналитиков и усиливать существующую защиту организации.
Что дальше
Сейчас AIKA находится на стадии MVP.
Уже работает веб-интерфейс мониторинга, журналирование событий, AI-модель обнаружения сетевых аномалий и локальный режим работы.
Следующий шаг — пилотное тестирование в реальной инфраструктуре.
Кого мы ищем
Мы ищем организацию, которая готова провести пилотный проект.
Это может быть:
банк;
телеком-оператор;
государственная организация;
дата-центр;
крупная корпоративная сеть.
Мы не предлагаем сразу покупать продукт.
Мы предлагаем посмотреть, как он работает в реальных условиях, получить честную профессиональную обратную связь и вместе определить направления дальнейшего развития.
Почему я верю в этот проект
Я убеждён, что Казахстан способен создавать собственные инженерные решения мирового уровня.
Не копировать.
Не догонять.
А создавать технологии, которыми можно будет гордиться.
Если вам интересно увидеть AIKA в работе или обсудить возможность пилотного проекта — буду рад знакомству.
AIKA Security
Artificial Intelligence Knowledge Assistant
Made in Kazakhstan.