---
title: Cybersecurity Firm Analyzes AI-Based Threat Detection
url: https://www.dataloco.com/en/cybersecurity-firm-analyzes-ai-based-threat-detection
published: 2026-10-10T18:20:35+00:00
language: en
section: Security
source: https://www.dailysecu.com/news/articleView.html?idxno=208800
organizations: dti.ai
publisher: Dataloco
---

# Cybersecurity Firm Analyzes AI-Based Threat Detection

Recently, a cybersecurity firm analyzed the process of attacks on the financial sector, revealing that AI technology can detect abnormal behaviors prior to personal information leaks. The firm, which specializes in AI cybersecurity, stated that its AI-based threat detection solution, DTI.ai, can identify repetitive customer information queries and abnormal service access.

The analysis focused on five stages of attacks targeting the financial sector, which include entry into query services, collection of customer numbers, linked service queries, mass information extraction, and incident awareness and response. The firm explained that its AI-based anomaly detection technology can be applied in four of these stages, from initial service access to mass information extraction.

Specifically, random login attempts are compared with normal behavior patterns for users, while repetitive customer number entries and linked service queries analyze the communication patterns received by servers. During the mass information extraction stage, abnormal outbound traffic is identified as a detection target.

The firm emphasized the importance of early detection, particularly noting that repetitive customer number entries and abnormal linked queries can indicate potential personal information leaks before they occur. However, the analysis compared the publicly disclosed attack stages with the firm’s detection model capabilities, without providing empirical results from actual breaches in financial company systems.

DTI.ai learns normal communication behaviors across users, servers, and network assets, detecting activities that deviate from established patterns. It does not rely solely on predefined rules or signatures of known attack types but analyzes abnormal access and communication changes.

The firm has applied around 20 threat detection models across various areas, including web, network, VPN, and DNS. It also reported success in applying its technology to military intelligent cyber threat analysis systems, which identified modified or circumvention attacks previously undetected by existing security systems. An example highlighted abnormal DNS traffic attempting to incorporate internal servers into a proxy botnet by communicating with external malicious IP addresses.

The representative from the firm stated that analyzing recent financial sector attacks using AI models trained on normal behaviors could have allowed for detection during the repetitive query stage before personal information leakage occurred. He noted that it is essential not only to detect unknown threats but also to minimize false positives and over-detections in real operational environments.
